Real-world descriptions of how a group, tool or campaign used a technique.
12 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1210 Exploitation of Remote Services |
GroupDragonfly | Dragonfly has exploited a Windows Netlogon vulnerability (CVE-2020-1472) to obtain access to Windows Active Directory servers. |
| T1210 Exploitation of Remote Services |
GroupmenuPass | menuPass has used tools to exploit the ZeroLogon vulnerability (CVE-2020-1472). |
| T1210 Exploitation of Remote Services |
GroupMuddyWater | MuddyWater has exploited the Microsoft Netlogon vulnerability (CVE-2020-1472). |
| T1210 Exploitation of Remote Services |
GroupFIN7 | FIN7 has exploited ZeroLogon (CVE-2020-1472) against vulnerable domain controllers. |
| T1210 Exploitation of Remote Services |
GroupEmber Bear | Ember Bear has used exploits for vulnerabilities such as MS17-010, also known as `Eternal Blue`, during operations. |
| T1210 Exploitation of Remote Services |
GroupAPT28 | APT28 exploited a Windows SMB Remote Code Execution Vulnerability to conduct lateral movement. |
| T1210 Exploitation of Remote Services |
GroupFox Kitten | Fox Kitten has exploited known vulnerabilities in remote services including RDP. |
| T1210 Exploitation of Remote Services |
GroupTonto Team | Tonto Team has used EternalBlue exploits for lateral movement. |
| T1210 Exploitation of Remote Services |
GroupEarth Lusca | Earth Lusca has used Mimikatz to exploit a domain controller via the ZeroLogon exploit (CVE-2020-1472). |
| T1210 Exploitation of Remote Services |
GroupWizard Spider | Wizard Spider has exploited or attempted to exploit Zerologon (CVE-2020-1472) and EternalBlue (MS17-010) vulnerabilities. |
| T1210 Exploitation of Remote Services |
GroupThreat Group-3390 | Threat Group-3390 has exploited MS17-010 to move laterally to other systems on the network. |
| T1210 Exploitation of Remote Services |
GroupShinyHunters | ShinyHunters has exploited vulnerabilities in remote services for lateral movement. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.