Real-world descriptions of how a group, tool or campaign used a technique.
32 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.001 LSASS Memory |
ToolPoshC2 | PoshC2 contains an implementation of Mimikatz to gather credentials from memory. |
| T1007 System Service Discovery |
ToolPoshC2 | PoshC2 can enumerate service and service permission information. |
| T1016 System Network Configuration Discovery |
ToolPoshC2 | PoshC2 can enumerate network adapter information. |
| T1040 Network Sniffing |
ToolPoshC2 | PoshC2 contains a module for taking packet captures on compromised hosts. |
| T1046 Network Service Discovery |
ToolPoshC2 | PoshC2 can perform port scans from an infected host. |
| T1047 Windows Management Instrumentation |
ToolPoshC2 | PoshC2 has a number of modules that use WMI to execute tasks. |
| T1049 System Network Connections Discovery |
ToolPoshC2 | PoshC2 contains an implementation of netstat to enumerate TCP and UDP connections. |
| T1055 Process Injection |
ToolPoshC2 | PoshC2 contains multiple modules for injecting into processes, such as |
| T1056.001 Keylogging |
ToolPoshC2 | PoshC2 has modules for keystroke logging and capturing credentials from spoofed Outlook authentication messages. |
| T1068 Exploitation for Privilege Escalation |
ToolPoshC2 | PoshC2 contains modules for local privilege escalation exploits such as CVE-2016-9192 and CVE-2016-0099. |
| T1069.001 Local Groups |
ToolPoshC2 | PoshC2 contains modules, such as |
| T1071.001 Web Protocols |
ToolPoshC2 | PoshC2 can use protocols like HTTP/HTTPS for command and control traffic. |
| T1082 System Information Discovery |
ToolPoshC2 | PoshC2 contains modules, such as |
| T1083 File and Directory Discovery |
ToolPoshC2 | PoshC2 can enumerate files on the local file system and includes a module for enumerating recently accessed files. |
| T1087.001 Local Account |
ToolPoshC2 | PoshC2 can enumerate local and domain user account information. |
| T1087.002 Domain Account |
ToolPoshC2 | PoshC2 can enumerate local and domain user account information. |
| T1090 Proxy |
ToolPoshC2 | PoshC2 contains modules that allow for use of proxies in command and control. |
| T1110 Brute Force |
ToolPoshC2 | PoshC2 has modules for brute forcing local administrator and AD user accounts. |
| T1119 Automated Collection |
ToolPoshC2 | PoshC2 contains a module for recursively parsing through files and directories to gather valid credit card numbers. |
| T1134 Access Token Manipulation |
ToolPoshC2 | PoshC2 can use Invoke-TokenManipulation for manipulating tokens. |
| T1134.002 Create Process with Token |
ToolPoshC2 | PoshC2 can use Invoke-RunAs to make tokens. |
| T1201 Password Policy Discovery |
ToolPoshC2 | PoshC2 can use |
| T1210 Exploitation of Remote Services |
ToolPoshC2 | PoshC2 contains a module for exploiting SMB via EternalBlue. |
| T1482 Domain Trust Discovery |
ToolPoshC2 | PoshC2 has modules for enumerating domain trusts. |
| T1546.003 Windows Management Instrumentation Event Subscription |
ToolPoshC2 | PoshC2 has the ability to persist on a system using WMI events. |
| T1548.002 Bypass User Account Control |
ToolPoshC2 | PoshC2 can utilize multiple methods to bypass UAC. |
| T1550.002 Pass the Hash |
ToolPoshC2 | PoshC2 has a number of modules that leverage pass the hash for lateral movement. |
| T1552.001 Credentials In Files |
ToolPoshC2 | PoshC2 contains modules for searching for passwords in local and remote files. |
| T1555 Credentials from Password Stores |
ToolPoshC2 | PoshC2 can decrypt passwords stored in the RDCMan configuration file. |
| T1557.001 Name Resolution Poisoning and SMB Relay |
ToolPoshC2 | PoshC2 can use Inveigh to conduct name service poisoning for credential theft and associated relay attacks. |
| T1560.001 Archive via Utility |
ToolPoshC2 | PoshC2 contains a module for compressing data using ZIP. |
| T1569.002 Service Execution |
ToolPoshC2 | PoshC2 contains an implementation of PsExec for remote execution. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.