ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0194×

28 examples

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
ToolPowerSploit

PowerSploit contains a collection of Exfiltration modules that can harvest credentials using Mimikatz.

T1005
Data from Local System
ToolPowerSploit

PowerSploit contains a collection of Exfiltration modules that can access data from local files, volumes, and processes.

T1012
Query Registry
ToolPowerSploit

PowerSploit contains a collection of Privesc-PowerUp modules that can query Registry keys for potential opportunities.

T1027.005
Indicator Removal from Tools
ToolPowerSploit

PowerSploit's Find-AVSignature AntivirusBypass module can be used to locate single byte anti-virus signatures.

T1027.010
Command Obfuscation
ToolPowerSploit

PowerSploit contains a collection of ScriptModification modules that compress and encode scripts and payloads.

T1047
Windows Management Instrumentation
ToolPowerSploit

PowerSploit's Invoke-WmiCommand CodeExecution module uses WMI to execute and retrieve the output from a PowerShell payload.

T1053.005
Scheduled Task
ToolPowerSploit

PowerSploit's New-UserPersistenceOption Persistence argument can be used to establish via a Scheduled Task/Job.

T1055.001
Dynamic-link Library Injection
ToolPowerSploit

PowerSploit contains a collection of CodeExecution modules that inject code (DLL, shellcode) into a process.

T1056.001
Keylogging
ToolPowerSploit

PowerSploit's Get-Keystrokes Exfiltration module can log keystrokes.

T1057
Process Discovery
ToolPowerSploit

PowerSploit's Get-ProcessTokenPrivilege Privesc-PowerUp module can enumerate privileges for a given process.

T1059.001
PowerShell
ToolPowerSploit

PowerSploit modules are written in and executed via PowerShell.

T1087.001
Local Account
ToolPowerSploit

PowerSploit's Get-ProcessTokenGroup Privesc-PowerUp module can enumerate all SIDs associated with its current token.

T1113
Screen Capture
ToolPowerSploit

PowerSploit's Get-TimedScreenshot Exfiltration module can take screenshots at regular intervals.

T1123
Audio Capture
ToolPowerSploit

PowerSploit's Get-MicrophoneAudio Exfiltration module can record system microphone audio.

T1134
Access Token Manipulation
ToolPowerSploit

PowerSploit's Invoke-TokenManipulation Exfiltration module can be used to manipulate tokens.

T1482
Domain Trust Discovery
ToolPowerSploit

PowerSploit has modules such as Get-NetDomainTrust and Get-NetForestTrust to enumerate domain and forest trusts.

T1543.003
Windows Service
ToolPowerSploit

PowerSploit contains a collection of Privesc-PowerUp modules that can discover and replace/modify service binaries, paths, and configs.

T1547.001
Registry Run Keys / Startup Folder
ToolPowerSploit

PowerSploit's New-UserPersistenceOption Persistence argument can be used to establish via the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key.

T1547.005
Security Support Provider
ToolPowerSploit

PowerSploit's Install-SSP Persistence module can be used to establish by installing a SSP DLL.

T1552.002
Credentials in Registry
ToolPowerSploit

PowerSploit has several modules that search the Windows Registry for stored credentials: Get-UnattendedInstallFile, Get-Webconfig, Get-ApplicationHost, Get-SiteListPassword, Get-CachedGPPPassword, and Get-RegistryAutoLogon.

T1552.006
Group Policy Preferences
ToolPowerSploit

PowerSploit contains a collection of Exfiltration modules that can harvest credentials from Group Policy Preferences.

T1555.004
Windows Credential Manager
ToolPowerSploit

PowerSploit contains a collection of Exfiltration modules that can harvest credentials from Windows vault credential objects.

T1558.003
Kerberoasting
ToolPowerSploit

PowerSploit's Invoke-Kerberoast module can request service tickets and return crackable ticket hashes.

T1574.001
DLL
ToolPowerSploit

PowerSploit contains a collection of Privesc-PowerUp modules that can discover and exploit DLL hijacking opportunities in services and processes.

T1574.007
Path Interception by PATH Environment Variable
ToolPowerSploit

PowerSploit contains a collection of Privesc-PowerUp modules that can discover and exploit path interception opportunities in the PATH environment variable.

T1574.008
Path Interception by Search Order Hijacking
ToolPowerSploit

PowerSploit contains a collection of Privesc-PowerUp modules that can discover and exploit search order hijacking vulnerabilities.

T1574.009
Path Interception by Unquoted Path
ToolPowerSploit

PowerSploit contains a collection of Privesc-PowerUp modules that can discover and exploit unquoted path vulnerabilities.

T1620
Reflective Code Loading
ToolPowerSploit

PowerSploit reflectively loads a Windows PE file into a process.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.