Real-world descriptions of how a group, tool or campaign used a technique.
23 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1069.002 Domain Groups |
MalwareGRIFFON | GRIFFON has used a reconnaissance module that can be used to retrieve Windows domain membership information. |
| T1069.002 Domain Groups |
MalwarePOWRUNER | POWRUNER may collect domain group information by running |
| T1069.002 Domain Groups |
MalwareBADHATCH | BADHATCH can use `net.exe group "domain admins" /domain` to identify Domain Administrators. |
| T1069.002 Domain Groups |
MalwareGootloader | Gootloader can determine if a targeted system is part of an Active Directory domain by expanding the %USERDNSDOMAIN% environment variable. |
| T1069.002 Domain Groups |
MalwareWellMess | WellMess can identify domain group membership for the current user. |
| T1069.002 Domain Groups |
MalwareBlackCat | BlackCat can determine if a user on a compromised host has domain admin privileges. |
| T1069.002 Domain Groups |
MalwareLatrodectus | Latrodectus can identify domain groups through `cmd.exe /c net group "Domain Admins" /domain`. |
| T1069.002 Domain Groups |
MalwareCobalt Strike | Cobalt Strike can identify targets by querying account groups on a domain contoller. |
| T1069.002 Domain Groups |
MalwareREvil | REvil can identify the domain membership of a compromised host. |
| T1069.002 Domain Groups |
MalwareKwampirs | Kwampirs collects a list of domain groups with the command |
| T1069.002 Domain Groups |
MalwareLAMEHUG | |
| T1069.002 Domain Groups |
MalwareEgregor | Egregor can conduct Active Directory reconnaissance using tools such as Sharphound or AdFind. |
| T1069.002 Domain Groups |
MalwareQilin | Qilin can run PowerShell cmdlets to discover domain groups. |
| T1069.002 Domain Groups |
MalwareSoreFang | SoreFang can enumerate domain groups by executing |
| T1069.002 Domain Groups |
MalwareHelminth | Helminth has checked for the domain admin group and Exchange Trusted Subsystem groups using the commands |
| T1069.002 Domain Groups |
MalwareOSInfo | OSInfo specifically looks for Domain Admins and power users within the domain. |
| T1069.002 Domain Groups |
ToolNet | Commands such as |
| T1069.002 Domain Groups |
ToolBloodHound | BloodHound can collect information about domain groups and members. |
| T1069.002 Domain Groups |
ToolSILENTTRINITY | SILENTTRINITY can use `System.DirectoryServices` namespace to retrieve domain group information. |
| T1069.002 Domain Groups |
Tooldsquery | dsquery can be used to gather information on permission groups within a domain. |
| T1069.002 Domain Groups |
ToolBrute Ratel C4 | Brute Ratel C4 can use `net group` for discovery on targeted domains. |
| T1069.002 Domain Groups |
ToolCrackMapExec | CrackMapExec can gather the user accounts within domain groups. |
| T1069.002 Domain Groups |
ToolAdFind | AdFind can enumerate domain groups. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.