ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0363×

73 examples

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
ToolEmpire

Empire contains an implementation of Mimikatz to gather credentials from memory.

T1016
System Network Configuration Discovery
ToolEmpire

Empire can acquire network configuration information like DNS servers, public IP, and network proxies used by a host.

T1020
Automated Exfiltration
ToolEmpire

Empire has the ability to automatically send collected data back to the threat actors' C2.

T1021.003
Distributed Component Object Model
ToolEmpire

Empire can utilize Invoke-DCOM to leverage remote COM execution for lateral movement.

T1021.004
SSH
ToolEmpire

Empire contains modules for executing commands over SSH as well as in-memory VNC agent injection.

T1027.010
Command Obfuscation
ToolEmpire

Empire has the ability to obfuscate commands using Invoke-Obfuscation.

T1033
System Owner/User Discovery
ToolEmpire

Empire can enumerate the username on targeted hosts.

T1040
Network Sniffing
ToolEmpire

Empire can be used to conduct packet captures on target hosts.

T1041
Exfiltration Over C2 Channel
ToolEmpire

Empire can send data gathered from a target through the command and control channel.

T1046
Network Service Discovery
ToolEmpire

Empire can perform port scans from an infected host.

T1047
Windows Management Instrumentation
ToolEmpire

Empire can use WMI to deliver a payload to a remote host.

T1049
System Network Connections Discovery
ToolEmpire

Empire can enumerate the current network connections of a host.

T1053.005
Scheduled Task
ToolEmpire

Empire has modules to interact with the Windows task scheduler.

T1055
Process Injection
ToolEmpire

Empire contains multiple modules for injecting into processes, such as Invoke-PSInject.

T1056.001
Keylogging
ToolEmpire

Empire includes keylogging capabilities for Windows, Linux, and macOS systems.

T1056.004
Credential API Hooking
ToolEmpire

Empire contains some modules that leverage API hooking to carry out tasks, such as netripper.

T1057
Process Discovery
ToolEmpire

Empire can find information about processes running on local and remote systems.

T1059
Command and Scripting Interpreter
ToolEmpire

Empire uses a command-line interface to interact with systems.

T1059.001
PowerShell
ToolEmpire

Empire leverages PowerShell for the majority of its client-side agent tasks. Empire also contains the ability to conduct PowerShell remoting with the Invoke-PSRemoting module.

T1059.003
Windows Command Shell
ToolEmpire

Empire has modules for executing scripts.

T1068
Exploitation for Privilege Escalation
ToolEmpire

Empire can exploit vulnerabilities such as MS16-032 and MS16-135.

T1070.006
Timestomp
ToolEmpire

Empire can timestomp any files or payloads placed on a target machine to help them blend in.

T1071.001
Web Protocols
ToolEmpire

Empire can conduct command and control over protocols like HTTP and HTTPS.

T1082
System Information Discovery
ToolEmpire

Empire can enumerate host system information like OS, architecture, domain name, applied patches, and more.

T1083
File and Directory Discovery
ToolEmpire

Empire includes various modules for finding files of interest on hosts and network shares.

T1087.001
Local Account
ToolEmpire

Empire can acquire local and domain user account information.

T1087.002
Domain Account
ToolEmpire

Empire can acquire local and domain user account information.

T1102.002
Bidirectional Communication
ToolEmpire

Empire can use Dropbox and GitHub for C2.

T1105
Ingress Tool Transfer
ToolEmpire

Empire can upload and download to and from a victim machine.

T1106
Native API
ToolEmpire

Empire contains a variety of enumeration modules that have an option to use API calls to carry out tasks.

T1113
Screen Capture
ToolEmpire

Empire is capable of capturing screenshots on Windows and macOS systems.

T1114.001
Local Email Collection
ToolEmpire

Empire has the ability to collect emails on a target system.

T1115
Clipboard Data
ToolEmpire

Empire can harvest clipboard data on both Windows and macOS systems.

T1119
Automated Collection
ToolEmpire

Empire can automatically gather the username, domain name, machine name, and other information from a compromised system.

T1125
Video Capture
ToolEmpire

Empire can capture webcam data on Windows and macOS systems.

T1127.001
MSBuild
ToolEmpire

Empire can use built-in modules to abuse trusted utilities like MSBuild.exe.

T1134
Access Token Manipulation
ToolEmpire

Empire can use PowerSploit's Invoke-TokenManipulation to manipulate access tokens.

T1134.002
Create Process with Token
ToolEmpire

Empire can use Invoke-RunAs to make tokens.

T1134.005
SID-History Injection
ToolEmpire

Empire can add a SID-History to a user if on a domain controller.

T1135
Network Share Discovery
ToolEmpire

Empire can find shared drives on the local system.

T1136.001
Local Account
ToolEmpire

Empire has a module for creating a local user if permissions allow.

T1136.002
Domain Account
ToolEmpire

Empire has a module for creating a new domain user if permissions allow.

T1210
Exploitation of Remote Services
ToolEmpire

Empire has a limited number of built-in modules for exploiting remote SMB, JBoss, and Jenkins servers.

T1217
Browser Information Discovery
ToolEmpire

Empire has the ability to gather browser data such as bookmarks and visited sites.

T1482
Domain Trust Discovery
ToolEmpire

Empire has modules for enumerating domain trusts.

T1484.001
Group Policy Modification
ToolEmpire

Empire can use New-GPOImmediateTask to modify a GPO that will install and execute a malicious Scheduled Task/Job.

T1518.001
Security Software Discovery
ToolEmpire

Empire can enumerate antivirus software on the target.

T1543.003
Windows Service
ToolEmpire

Empire can utilize built-in modules to modify service binaries and restore them to their original state.

T1546.008
Accessibility Features
ToolEmpire

Empire can leverage WMI debugging to remotely replace binaries like sethc.exe, Utilman.exe, and Magnify.exe with cmd.exe.

T1547.001
Registry Run Keys / Startup Folder
ToolEmpire

Empire can modify the registry run keys HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run and HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run for persistence.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.