ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1074.001
Local Data Staging
MalwareHelminth

Helminth creates folders to store output from batch scripts prior to sending the information to its C2 server.

T1074.001
Local Data Staging
MalwareDtrack

Dtrack can save collected data to disk, different file formats, and network shares.

T1074.001
Local Data Staging
MalwareSLOWPULSE

SLOWPULSE can write logged ACE credentials to `/home/perl/PAUS.pm` in append mode, using the format string `%s:%s\n`.

T1074.001
Local Data Staging
MalwareADVSTORESHELL

ADVSTORESHELL stores output from command execution in a .dat file in the %TEMP% directory.

T1074.001
Local Data Staging
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer has created a staging file in `/tmp` for collected data.

T1074.001
Local Data Staging
MalwareDuqu

Modules can be pushed to and executed by Duqu that copy data to a staging area, compress it, and XOR encrypt it.

T1074.002
Remote Data Staging
Malwareccf32

ccf32 has copied files to a remote machine infected with Chinoxy or another backdoor.

T1078
Valid Accounts
MalwareLinux Rabbit

Linux Rabbit acquires valid SSH accounts through brute force.

T1078
Valid Accounts
MalwareSeaDuke

Some SeaDuke samples have a module to extract email from Microsoft Exchange servers using compromised credentials.

T1078
Valid Accounts
MalwareLP-Notes

LP-Notes has used stolen Windows credentials to log in as the users.

T1078
Valid Accounts
MalwareKinsing

Kinsing has used valid SSH credentials to access remote hosts.

T1078
Valid Accounts
MalwareIndustroyer

Industroyer can use supplied user credentials to execute processes and stop services.

T1078
Valid Accounts
MalwareDtrack

Dtrack used hard-coded credentials to gain access to a network share.

T1078
Valid Accounts
MalwareDuqu

Adversaries can instruct Duqu to spread laterally by copying itself to shares it has enumerated and for which it has obtained legitimate credentials (via keylogging or other means). The remote host is then infected by using the compromised credentials to schedule a task on remote machines that executes the malware.

T1078.001
Default Accounts
MalwareStuxnet

Stuxnet infected WinCC machines via a hardcoded database server password.

T1078.001
Default Accounts
MalwareHyperStack

HyperStack can use default credentials to connect to IPC$ shares on remote machines.

T1078.002
Domain Accounts
MalwareStuxnet

Stuxnet attempts to access network resources with a domain account’s credentials.

T1078.002
Domain Accounts
MalwareShamoon

If Shamoon cannot access shares using current privileges, it attempts access using hard coded, domain-specific credentials gathered earlier in the intrusion.

T1078.002
Domain Accounts
MalwareRyuk

Ryuk can use stolen domain admin accounts to move laterally within a victim domain.

T1078.002
Domain Accounts
MalwareCobalt Strike

Cobalt Strike can use known credentials to run commands and spawn processes as a domain user account.

T1078.002
Domain Accounts
MalwareCreepySnail

CreepySnail can use stolen credentials to authenticate on target networks.

T1078.003
Local Accounts
MalwareEmotet

Emotet can brute force a local admin password, then use it to facilitate lateral movement.

T1078.003
Local Accounts
MalwareUmbreon

Umbreon creates valid local users to provide access to the system.

T1078.003
Local Accounts
MalwareNotPetya

NotPetya can use valid credentials with PsExec or wmic to spread itself to remote systems.

T1078.003
Local Accounts
MalwareLockBit 3.0

LockBit 3.0 can use a compromised local account for lateral movement.

T1078.003
Local Accounts
MalwareCobalt Strike

Cobalt Strike can use known credentials to run commands and spawn processes as a local user account.

T1078.004
Cloud Accounts
MalwareShai-Hulud

Shai-Hulud has leveraged compromised accounts to log into cloud services to access cloud hosted repositories.

T1078.004
Cloud Accounts
ToolPacu

Pacu leverages valid cloud accounts to perform most of its operations.

T1078.004
Cloud Accounts
ToolROADTools

ROADTools leverages valid cloud credentials to perform enumeration operations using the internal Azure AD Graph API.

T1078.004
Cloud Accounts
ToolTruffleHog

TruffleHog has used stolen credentials to log into cloud services to access cloud hosted repositories and other cloud storage solutions to discover sensitive data to include API Keys, tokens and credentials.

T1078.004
Cloud Accounts
ToolPeirates

Peirates can use stolen service account tokens to perform its operations.

T1078.004
Cloud Accounts
MalwareMini Shai-Hulud

Mini Shai-Hulud has used compromised accounts for Docker Hub and GitHub to publish malicious software packages.

T1080
Taint Shared Content
MalwareStuxnet

Stuxnet infects remote servers via network shares and by infecting WinCC database views with malicious code.

T1080
Taint Shared Content
MalwareUrsnif

Ursnif has copied itself to and infected files in network drives for propagation.

T1080
Taint Shared Content
MalwareMiner-C

Miner-C copies itself into the public folder of Network Attached Storage (NAS) devices and infects new victims who open the file.

T1080
Taint Shared Content
MalwareInvisiMole

InvisiMole can replace legitimate software or documents in the compromised network with their trojanized versions, in an attempt to propagate itself within the network.

T1080
Taint Shared Content
MalwareConti

Conti can spread itself by infecting other remote machines via network shared drives.

T1080
Taint Shared Content
MalwareRamsay

Ramsay can spread itself by infecting other portable executable files on networks shared drives.

T1080
Taint Shared Content
MalwareH1N1

H1N1 has functionality to copy itself to network shares.

T1082
System Information Discovery
MalwareTrickBot

TrickBot gathers the OS version, machine name, CPU type, amount of RAM available, and UEFI/BIOS firmware information from the victim’s machine.

T1082
System Information Discovery
MalwarePowerDuke

PowerDuke has commands to get information about the victim's name, build, version, serial number, and memory usage.

T1082
System Information Discovery
MalwareBLINDINGCAN

BLINDINGCAN has collected from a victim machine the system name, processor information, and OS version.

T1082
System Information Discovery
MalwareNinja

Ninja can obtain the computer name and information on the OS from targeted hosts.

T1082
System Information Discovery
MalwarePikabot

Pikabot performs a variety of system checks and gathers system information, including commands such as whoami.

T1082
System Information Discovery
MalwareRCSession

RCSession can gather system information from a compromised host.

T1082
System Information Discovery
MalwareSpark

Spark can collect the hostname, keyboard layout, and language from the system.

T1082
System Information Discovery
MalwareSynAck

SynAck gathers computer names, OS version info, and also checks installed keyboard layouts to estimate if it has been launched from a certain list of countries.

T1082
System Information Discovery
MalwareBumblebee

Bumblebee can enumerate the OS version and domain on a targeted system.

T1082
System Information Discovery
MalwareMURKYTOP

MURKYTOP has the capability to retrieve information about the OS.

T1082
System Information Discovery
MalwareGRIFFON

GRIFFON has used a reconnaissance module that can be used to retrieve information about a victim's computer, including the resolution of the workstation .

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.