ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1069.002×

13 examples

TechniqueUsed byProcedure example
T1069.002
Domain Groups
GroupVolt Typhoon

Volt Typhoon has run `net group` in compromised environments to discover domain groups.

T1069.002
Domain Groups
GroupDragonfly

Dragonfly has used batch scripts to enumerate administrators and users in the domain.

T1069.002
Domain Groups
GroupFIN7

FIN7 has used the command `net group "domain admins" /domain` to enumerate domain groups.

T1069.002
Domain Groups
GroupMustang Panda

Mustang Panda has leveraged AdFind to enumerate domain groups.

T1069.002
Domain Groups
GroupScattered Spider

Scattered Spider has enumerated Active Directory security groups including through the use of ADExplorer, ADRecon.ps1, and Get-ADUser.

T1069.002
Domain Groups
GroupOilRig

OilRig has used net group /domain, net group “domain admins” /domain, and net group “Exchange Trusted Subsystem” /domain to find domain group permission settings.

T1069.002
Domain Groups
GroupKe3chang

Ke3chang performs discovery of permission groups net group /domain.

T1069.002
Domain Groups
GroupTurla

Turla has used net group "Domain Admins" /domain to identify domain administrators.

T1069.002
Domain Groups
GroupMedusa Group

Medusa Group has utilized the `net group` command to query domain groups within the victim environment.

T1069.002
Domain Groups
GroupToddyCat

ToddyCat has executed `net group "domain admins" /dom` for discovery on compromised machines.

T1069.002
Domain Groups
GroupINC Ransom

INC Ransom has enumerated domain groups on targeted hosts.

T1069.002
Domain Groups
GroupLAPSUS$

LAPSUS$ has used the AD Explorer tool to enumerate groups on a victim's network.

T1069.002
Domain Groups
GroupInception

Inception has used specific malware modules to gather domain membership.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.