ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0677×

24 examples

TechniqueUsed byProcedure example
T1003.004
LSA Secrets
ToolAADInternals

AADInternals can dump secrets from the Local Security Authority.

T1048
Exfiltration Over Alternative Protocol
ToolAADInternals

AADInternals can directly download cloud user data such as OneDrive files.

T1059.001
PowerShell
ToolAADInternals

AADInternals is written and executed via PowerShell.

T1069.003
Cloud Groups
ToolAADInternals

AADInternals can enumerate Azure AD groups.

T1087.004
Cloud Account
ToolAADInternals

AADInternals can enumerate Azure AD users.

T1098.005
Device Registration
ToolAADInternals

AADInternals can register a device to Azure AD.

T1112
Modify Registry
ToolAADInternals

AADInternals can modify registry keys as part of setting a new pass-through authentication agent.

T1136.003
Cloud Account
ToolAADInternals

AADInternals can create new Azure AD users.

T1484.002
Trust Modification
ToolAADInternals

AADInternals can create a backdoor by converting a domain to a federated domain which will be able to authenticate any user across the tenant. AADInternals can also modify DesktopSSO information.

T1526
Cloud Service Discovery
ToolAADInternals

AADInternals can enumerate information about a variety of cloud services, such as Office 365 and Sharepoint instances or OpenID Configurations.

T1528
Steal Application Access Token
ToolAADInternals

AADInternals can steal users’ access tokens via phishing emails containing malicious links.

T1530
Data from Cloud Storage
ToolAADInternals

AADInternals can collect files from a user’s OneDrive.

T1552.001
Credentials In Files
ToolAADInternals

AADInternals can gather unsecured credentials for Azure AD services, such as Azure AD Connect, from a local machine.

T1552.004
Private Keys
ToolAADInternals

AADInternals can gather encryption keys from Azure AD services such as ADSync and Active Directory Federated Services servers.

T1556.006
Multi-Factor Authentication
ToolAADInternals

The AADInternals `Set-AADIntUserMFA` command can be used to disable MFA for a specified user.

T1556.007
Hybrid Identity
ToolAADInternals

AADInternals can inject a malicious DLL (`PTASpy`) into the `AzureADConnectAuthenticationAgentService` to backdoor Azure AD Pass-Through Authentication.

T1558.002
Silver Ticket
ToolAADInternals

AADInternals can be used to forge Kerberos tickets using the password hash of the AZUREADSSOACC account.

T1566.002
Spearphishing Link
ToolAADInternals

AADInternals can send "consent phishing" emails containing malicious links designed to steal users’ access tokens.

T1589.002
Email Addresses
ToolAADInternals

AADInternals can check for the existence of user email addresses using public Microsoft APIs.

T1590.001
Domain Properties
ToolAADInternals

AADInternals can gather information about a tenant’s domains using public Microsoft APIs.

T1598.003
Spearphishing Link
ToolAADInternals

AADInternals can send phishing emails containing malicious links designed to collect users’ credentials.

T1606.002
SAML Tokens
ToolAADInternals

AADInternals can be used to create SAML tokens using the AD Federated Services token signing certificate.

T1649
Steal or Forge Authentication Certificates
ToolAADInternals

AADInternals can create and export various authentication certificates, including those associated with Azure AD joined/registered devices.

T1651
Cloud Administration Command
ToolAADInternals

AADInternals can execute commands on Azure virtual machines using the VM agent.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.