ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1135×

16 examples

TechniqueUsed byProcedure example
T1135
Network Share Discovery
GroupAPT38

APT38 has enumerated network shares on a compromised host.

T1135
Network Share Discovery
GroupBlackByte

BlackByte enumerated network shares on victim devices.

T1135
Network Share Discovery
GroupAPT41

APT41 used the net share command as part of network reconnaissance.

T1135
Network Share Discovery
GroupDragonfly

Dragonfly has identified and browsed file servers in the victim network, sometimes , viewing files pertaining to ICS or Supervisory Control and Data Acquisition (SCADA) systems.

T1135
Network Share Discovery
GroupAPT32

APT32 used the net view command to show all shares available, including the administrative shares such as C$ and ADMIN$.

T1135
Network Share Discovery
GroupAPT39

APT39 has used the post exploitation tool CrackMapExec to enumerate network shares.

T1135
Network Share Discovery
GroupTropic Trooper

Tropic Trooper used netview to scan target systems for shared resources.

T1135
Network Share Discovery
GroupAPT1

APT1 listed connected network shares.

T1135
Network Share Discovery
GroupDarkVishnya

DarkVishnya scanned the network for public shared folders.

T1135
Network Share Discovery
GroupChimera

Chimera has used net share and net view to identify network shares of interest.

T1135
Network Share Discovery
GroupMedusa Group

Medusa Group has identified network shares using `cmd.exe /c net share`.

T1135
Network Share Discovery
GroupTonto Team

Tonto Team has used tools such as NBTscan to enumerate network shares.

T1135
Network Share Discovery
GroupINC Ransom

INC Ransom has used Internet Explorer to view folders on other systems.

T1135
Network Share Discovery
GroupSowbug

Sowbug listed remote shared drives that were accessible from a victim.

T1135
Network Share Discovery
GroupWizard Spider

Wizard Spider has used the “net view” command to locate mapped network shares.

T1135
Network Share Discovery
GroupFIN13

FIN13 has executed net view commands for enumeration of open shares on compromised machines.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.