Ackerman, G., et al. (2018, December 21). OVERRULED: Containing a Potentially Destructive Adversary. Retrieved January 17, 2019.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.001 LSASS Memory |
GroupAPT33 | APT33 has used a variety of publicly available tools like LaZagne, Mimikatz, and ProcDump to dump credentials. |
| T1003.002 Security Account Manager |
MalwarePOWERTON | POWERTON has the ability to dump password hashes. |
| T1003.004 LSA Secrets |
GroupAPT33 | APT33 has used a variety of publicly available tools like LaZagne to gather credentials. |
| T1003.005 Cached Domain Credentials |
GroupAPT33 | APT33 has used a variety of publicly available tools like LaZagne to gather credentials. |
| T1027.013 Encrypted/Encoded File |
GroupAPT33 | APT33 has used base64 to encode payloads. |
| T1059.001 PowerShell |
MalwarePOWERTON | POWERTON is written in PowerShell. |
| T1068 Exploitation for Privilege Escalation |
GroupAPT33 | APT33 has used a publicly available exploit for CVE-2017-0213 to escalate privileges on a local system. |
| T1071.001 Web Protocols |
MalwarePOWERTON | POWERTON has used HTTP/HTTPS for C2 traffic. |
| T1078 Valid Accounts |
GroupAPT33 | APT33 has used valid accounts for initial access and privilege escalation. |
| T1110.003 Password Spraying |
GroupAPT33 | APT33 has used password spraying to gain access to target systems. |
| T1132.001 Standard Encoding |
GroupAPT33 | APT33 has used base64 to encode command and control traffic. |
| T1546.003 Windows Management Instrumentation Event Subscription |
MalwarePOWERTON | POWERTON can use WMI for persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwarePOWERTON | POWERTON can install a Registry Run key for persistence. |
| T1552.001 Credentials In Files |
GroupAPT33 | APT33 has used a variety of publicly available tools like LaZagne to gather credentials. |
| T1552.006 Group Policy Preferences |
GroupAPT33 | APT33 has used a variety of publicly available tools like Gpppassword to gather credentials. |
| T1555 Credentials from Password Stores |
GroupAPT33 | APT33 has used a variety of publicly available tools like LaZagne to gather credentials. |
| T1555.003 Credentials from Web Browsers |
GroupAPT33 | APT33 has used a variety of publicly available tools like LaZagne to gather credentials. |
| T1573.001 Symmetric Cryptography |
GroupAPT33 | APT33 has used AES for encryption of command and control traffic. |
| T1573.001 Symmetric Cryptography |
MalwarePOWERTON | POWERTON has used AES for encrypting C2 traffic. |
| T1588.002 Tool |
GroupAPT33 | APT33 has obtained and leveraged publicly-available tools for early intrusion activities. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.