ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1069.001×

21 examples

TechniqueUsed byProcedure example
T1069.001
Local Groups
MalwarePOWRUNER

POWRUNER may collect local group information by running net localgroup administrators or a series of other commands on a victim.

T1069.001
Local Groups
MalwareEmissary

Emissary has the capability to execute the command net localgroup administrators.

T1069.001
Local Groups
MalwareGomir

Gomir checks the effective group ID of its process when initially executed to determine if it is in group 0, denoting superuser privileges in Linux environments.

T1069.001
Local Groups
MalwareFlawedAmmyy

FlawedAmmyy enumerates the privilege level of the victim during the initial infection.

T1069.001
Local Groups
MalwareKazuar

Kazuar gathers information about local groups and members.

T1069.001
Local Groups
MalwareFlagpro

Flagpro has been used to execute the net localgroup administrators command on a targeted system.

T1069.001
Local Groups
MalwareExbyte

Exbyte checks whether the process is running with privileged local access during execution.

T1069.001
Local Groups
MalwareEpic

Epic gathers information on local group names.

T1069.001
Local Groups
MalwareCaterpillar WebShell

Caterpillar WebShell can obtain a list of local groups of users from a system.

T1069.001
Local Groups
MalwareSys10

Sys10 collects the group name of the logged-in user and sends it to the C2.

T1069.001
Local Groups
MalwareCobalt Strike

Cobalt Strike can use net localgroup to list local groups on a system.

T1069.001
Local Groups
MalwareKwampirs

Kwampirs collects a list of users belonging to the local users and administrators groups with the commands net localgroup administrators and net localgroup users.

T1069.001
Local Groups
MalwareJPIN

JPIN can obtain the permissions of the victim user.

T1069.001
Local Groups
MalwareLunarWeb

LunarWeb can discover local group memberships.

T1069.001
Local Groups
MalwareQakBot

QakBot can use net localgroup to enable discovery of local groups.

T1069.001
Local Groups
MalwareHelminth

Helminth has checked the local administrators group.

T1069.001
Local Groups
MalwareOSInfo

OSInfo has enumerated the local administrators group.

T1069.001
Local Groups
ToolNet

Commands such as net group and net localgroup can be used in Net to gather information about and manipulate groups.

T1069.001
Local Groups
ToolBloodHound

BloodHound can collect information about local groups and members.

T1069.001
Local Groups
ToolSILENTTRINITY

SILENTTRINITY can obtain a list of local groups and members.

T1069.001
Local Groups
ToolPoshC2

PoshC2 contains modules, such as Get-LocAdm for enumerating permission groups.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.