ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1552.001×

15 examples

TechniqueUsed byProcedure example
T1552.001
Credentials In Files
GroupIndrik Spider

Indrik Spider has searched files to obtain and exfiltrate credentials.

T1552.001
Credentials In Files
GroupAPT3

APT3 has a tool that can locate credentials in files on the file system such as those from Firefox or Chrome.

T1552.001
Credentials In Files
GroupKimsuky

Kimsuky has used tools that are capable of obtaining credentials from saved mail.

T1552.001
Credentials In Files
GroupMuddyWater

MuddyWater has run a tool that steals passwords saved in victim email.

T1552.001
Credentials In Files
GroupLeafminer

Leafminer used several tools for retrieving login and password information, including LaZagne.

T1552.001
Credentials In Files
GroupTeamTNT

TeamTNT has searched for unsecured AWS credentials and Docker API credentials.

T1552.001
Credentials In Files
GroupScattered Spider

Scattered Spider Spider searches for credential storage documentation on a compromised host.

T1552.001
Credentials In Files
GroupOilRig

OilRig has used credential dumping tools such as LaZagne to steal credentials to accounts logged into the compromised system and to Outlook Web Access.

T1552.001
Credentials In Files
GroupTA505

TA505 has used malware to gather credentials from FTP clients and Outlook.

T1552.001
Credentials In Files
GroupRedCurl

RedCurl used LaZagne to obtain passwords in files.

T1552.001
Credentials In Files
GroupEmber Bear

Ember Bear has dumped configuration settings in accessed IP cameras including plaintext credentials.

T1552.001
Credentials In Files
GroupFox Kitten

Fox Kitten has accessed files to gain valid credentials.

T1552.001
Credentials In Files
GroupAPT33

APT33 has used a variety of publicly available tools like LaZagne to gather credentials.

T1552.001
Credentials In Files
GroupFIN13

FIN13 has obtained administrative credentials by browsing through local files on a compromised machine.

T1552.001
Credentials In Files
GroupShinyHunters

ShinyHunters has gathered PII from database infrastructure.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.