Real-world descriptions of how a group, tool or campaign used a technique.
11 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1550.002 Pass the Hash |
GroupGALLIUM | GALLIUM used dumped hashes to authenticate to other machines via pass the hash. |
| T1550.002 Pass the Hash |
GroupKimsuky | Kimsuky has used pass the hash for authentication to remote access software used in C2. |
| T1550.002 Pass the Hash |
GroupAPT41 | APT41 uses tools such as Mimikatz to enable lateral movement via captured password hashes. |
| T1550.002 Pass the Hash |
GroupAPT32 | APT32 has used pass the hash for lateral movement. |
| T1550.002 Pass the Hash |
GroupAquatic Panda | Aquatic Panda used a registry edit to enable a Windows feature called |
| T1550.002 Pass the Hash |
GroupAPT1 | The APT1 group is known to have used pass the hash. |
| T1550.002 Pass the Hash |
GroupChimera | Chimera has dumped password hashes for use in pass the hash authentication attacks. |
| T1550.002 Pass the Hash |
GroupEmber Bear | Ember Bear has used pass-the-hash techniques for lateral movement in victim environments. |
| T1550.002 Pass the Hash |
GroupAPT28 | APT28 has used pass the hash for lateral movement. |
| T1550.002 Pass the Hash |
GroupWizard Spider | Wizard Spider has used the `Invoke-SMBExec` PowerShell cmdlet to execute the pass-the-hash technique and utilized stolen password hashes to move laterally. |
| T1550.002 Pass the Hash |
GroupFIN13 | FIN13 has used the PowerShell utility `Invoke-SMBExec` to execute the pass the hash method for lateral movement within an compromised environment. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.