ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1069.002×

23 examples

TechniqueUsed byProcedure example
T1069.002
Domain Groups
MalwareGRIFFON

GRIFFON has used a reconnaissance module that can be used to retrieve Windows domain membership information.

T1069.002
Domain Groups
MalwarePOWRUNER

POWRUNER may collect domain group information by running net group /domain or a series of other commands on a victim.

T1069.002
Domain Groups
MalwareBADHATCH

BADHATCH can use `net.exe group "domain admins" /domain` to identify Domain Administrators.

T1069.002
Domain Groups
MalwareGootloader

Gootloader can determine if a targeted system is part of an Active Directory domain by expanding the %USERDNSDOMAIN% environment variable.

T1069.002
Domain Groups
MalwareWellMess

WellMess can identify domain group membership for the current user.

T1069.002
Domain Groups
MalwareBlackCat

BlackCat can determine if a user on a compromised host has domain admin privileges.

T1069.002
Domain Groups
MalwareLatrodectus

Latrodectus can identify domain groups through `cmd.exe /c net group "Domain Admins" /domain`.

T1069.002
Domain Groups
MalwareCobalt Strike

Cobalt Strike can identify targets by querying account groups on a domain contoller.

T1069.002
Domain Groups
MalwareREvil

REvil can identify the domain membership of a compromised host.

T1069.002
Domain Groups
MalwareKwampirs

Kwampirs collects a list of domain groups with the command net localgroup /domain.

T1069.002
Domain Groups
MalwareLAMEHUG

LAMEHUG can use dsquery to gather domain group information.

T1069.002
Domain Groups
MalwareEgregor

Egregor can conduct Active Directory reconnaissance using tools such as Sharphound or AdFind.

T1069.002
Domain Groups
MalwareQilin

Qilin can run PowerShell cmdlets to discover domain groups.

T1069.002
Domain Groups
MalwareSoreFang

SoreFang can enumerate domain groups by executing net.exe group /domain.

T1069.002
Domain Groups
MalwareHelminth

Helminth has checked for the domain admin group and Exchange Trusted Subsystem groups using the commands net group Exchange Trusted Subsystem /domain and net group domain admins /domain.

T1069.002
Domain Groups
MalwareOSInfo

OSInfo specifically looks for Domain Admins and power users within the domain.

T1069.002
Domain Groups
ToolNet

Commands such as net group /domain can be used in Net to gather information about and manipulate groups.

T1069.002
Domain Groups
ToolBloodHound

BloodHound can collect information about domain groups and members.

T1069.002
Domain Groups
ToolSILENTTRINITY

SILENTTRINITY can use `System.DirectoryServices` namespace to retrieve domain group information.

T1069.002
Domain Groups
Tooldsquery

dsquery can be used to gather information on permission groups within a domain.

T1069.002
Domain Groups
ToolBrute Ratel C4

Brute Ratel C4 can use `net group` for discovery on targeted domains.

T1069.002
Domain Groups
ToolCrackMapExec

CrackMapExec can gather the user accounts within domain groups.

T1069.002
Domain Groups
ToolAdFind

AdFind can enumerate domain groups.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.