Real-world descriptions of how a group, tool or campaign used a technique.
20 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.002 Security Account Manager |
ToolCrackMapExec | CrackMapExec can dump usernames and hashed passwords from the SAM. |
| T1003.003 NTDS |
ToolCrackMapExec | CrackMapExec can dump hashed passwords associated with Active Directory using Windows' Directory Replication Services API (DRSUAPI), or Volume Shadow Copy. |
| T1003.004 LSA Secrets |
ToolCrackMapExec | CrackMapExec can dump hashed passwords from LSA secrets for the targeted system. |
| T1016 System Network Configuration Discovery |
ToolCrackMapExec | CrackMapExec can collect DNS information from the targeted system. |
| T1018 Remote System Discovery |
ToolCrackMapExec | CrackMapExec can discover active IP addresses, along with the machine name, within a targeted network. |
| T1047 Windows Management Instrumentation |
ToolCrackMapExec | CrackMapExec can execute remote commands using Windows Management Instrumentation. |
| T1049 System Network Connections Discovery |
ToolCrackMapExec | CrackMapExec can discover active sessions for a targeted system. |
| T1053.002 At |
ToolCrackMapExec | CrackMapExec can set a scheduled task on the target system to execute commands remotely using at. |
| T1059.001 PowerShell |
ToolCrackMapExec | CrackMapExec can execute PowerShell commands via WMI. |
| T1069.002 Domain Groups |
ToolCrackMapExec | CrackMapExec can gather the user accounts within domain groups. |
| T1083 File and Directory Discovery |
ToolCrackMapExec | CrackMapExec can discover specified filetypes and log files on a targeted system. |
| T1087.002 Domain Account |
ToolCrackMapExec | CrackMapExec can enumerate the domain user accounts on a targeted system. |
| T1110 Brute Force |
ToolCrackMapExec | CrackMapExec can brute force supplied user credentials across a network range. |
| T1110.001 Password Guessing |
ToolCrackMapExec | CrackMapExec can brute force passwords for a specified user on a single target system or across an entire network. |
| T1110.003 Password Spraying |
ToolCrackMapExec | CrackMapExec can brute force credential authentication by using a supplied list of usernames and a single password. |
| T1112 Modify Registry |
ToolCrackMapExec | CrackMapExec can create a registry key using wdigest. |
| T1135 Network Share Discovery |
ToolCrackMapExec | CrackMapExec can enumerate the shared folders and associated permissions for a targeted network. |
| T1201 Password Policy Discovery |
ToolCrackMapExec | CrackMapExec can discover the password policies applied to the target system. |
| T1550.002 Pass the Hash |
ToolCrackMapExec | CrackMapExec can pass the hash to authenticate via SMB. |
| T1680 Local Storage Discovery |
ToolCrackMapExec | CrackMapExec can enumerate the system drives and associated system name. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.