Real-world descriptions of how a group, tool or campaign used a technique.
21 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1049 System Network Connections Discovery |
ToolPacu | Once inside a Virtual Private Cloud, Pacu can attempt to identify DirectConnect, VPN, or VPC Peering. |
| T1059.009 Cloud API |
ToolPacu | Pacu leverages the AWS CLI for its operations. |
| T1069.003 Cloud Groups |
ToolPacu | Pacu can enumerate IAM permissions. |
| T1078.004 Cloud Accounts |
ToolPacu | Pacu leverages valid cloud accounts to perform most of its operations. |
| T1087.004 Cloud Account |
ToolPacu | Pacu can enumerate IAM users, roles, and groups. |
| T1098.001 Additional Cloud Credentials |
ToolPacu | Pacu can generate SSH and API keys for AWS infrastructure and additional API keys for other IAM users. |
| T1119 Automated Collection |
ToolPacu | Pacu can automatically collect data, such as CloudFormation templates, EC2 user data, AWS Inspector reports, and IAM credential reports. |
| T1518.001 Security Software Discovery |
ToolPacu | Pacu can enumerate AWS security services, including WAF rules and GuardDuty detectors. |
| T1526 Cloud Service Discovery |
ToolPacu | Pacu can enumerate AWS services, such as CloudTrail and CloudWatch. |
| T1530 Data from Cloud Storage |
ToolPacu | Pacu can enumerate and download files stored in AWS storage services, such as S3 buckets. |
| T1546 Event Triggered Execution |
ToolPacu | Pacu can set up S3 bucket notifications to trigger a malicious Lambda function when a CloudFormation template is uploaded to the bucket. It can also create Lambda functions that trigger upon the creation of users, roles, and groups. |
| T1552 Unsecured Credentials |
ToolPacu | Pacu can search for sensitive data: for example, in Code Build environment variables, EC2 user data, and Cloud Formation templates. |
| T1555.006 Cloud Secrets Management Stores |
ToolPacu | Pacu can retrieve secrets from the AWS Secrets Manager via the enum_secrets module. |
| T1578.001 Create Snapshot |
ToolPacu | Pacu can create snapshots of EBS volumes and RDS instances. |
| T1580 Cloud Infrastructure Discovery |
ToolPacu | Pacu can enumerate AWS infrastructure, such as EC2 instances. |
| T1619 Cloud Storage Object Discovery |
ToolPacu | Pacu can enumerate AWS storage services, such as S3 buckets and Elastic Block Store volumes. |
| T1648 Serverless Execution |
ToolPacu | Pacu can create malicious Lambda functions. |
| T1651 Cloud Administration Command |
ToolPacu | Pacu can run commands on EC2 instances using AWS Systems Manager Run Command. |
| T1654 Log Enumeration |
ToolPacu | Pacu can collect CloudTrail event histories and CloudWatch logs. |
| T1685.002 Disable or Modify Cloud Log |
ToolPacu | Pacu can disable or otherwise restrict various AWS logging services, such as AWS CloudTrail and VPC flow logs. |
| T1686.001 Cloud Firewall |
ToolPacu | Pacu can allowlist IP addresses in AWS GuardDuty. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.