ATT&CKReferencesFireEye APT33 Guardrail

FireEye APT33 Guardrail

Ackerman, G., et al. (2018, December 21). OVERRULED: Containing a Potentially Destructive Adversary. Retrieved January 17, 2019.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples20

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
GroupAPT33

APT33 has used a variety of publicly available tools like LaZagne, Mimikatz, and ProcDump to dump credentials.

T1003.002
Security Account Manager
MalwarePOWERTON

POWERTON has the ability to dump password hashes.

T1003.004
LSA Secrets
GroupAPT33

APT33 has used a variety of publicly available tools like LaZagne to gather credentials.

T1003.005
Cached Domain Credentials
GroupAPT33

APT33 has used a variety of publicly available tools like LaZagne to gather credentials.

T1027.013
Encrypted/Encoded File
GroupAPT33

APT33 has used base64 to encode payloads.

T1059.001
PowerShell
MalwarePOWERTON

POWERTON is written in PowerShell.

T1068
Exploitation for Privilege Escalation
GroupAPT33

APT33 has used a publicly available exploit for CVE-2017-0213 to escalate privileges on a local system.

T1071.001
Web Protocols
MalwarePOWERTON

POWERTON has used HTTP/HTTPS for C2 traffic.

T1078
Valid Accounts
GroupAPT33

APT33 has used valid accounts for initial access and privilege escalation.

T1110.003
Password Spraying
GroupAPT33

APT33 has used password spraying to gain access to target systems.

T1132.001
Standard Encoding
GroupAPT33

APT33 has used base64 to encode command and control traffic.

T1546.003
Windows Management Instrumentation Event Subscription
MalwarePOWERTON

POWERTON can use WMI for persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwarePOWERTON

POWERTON can install a Registry Run key for persistence.

T1552.001
Credentials In Files
GroupAPT33

APT33 has used a variety of publicly available tools like LaZagne to gather credentials.

T1552.006
Group Policy Preferences
GroupAPT33

APT33 has used a variety of publicly available tools like Gpppassword to gather credentials.

T1555
Credentials from Password Stores
GroupAPT33

APT33 has used a variety of publicly available tools like LaZagne to gather credentials.

T1555.003
Credentials from Web Browsers
GroupAPT33

APT33 has used a variety of publicly available tools like LaZagne to gather credentials.

T1573.001
Symmetric Cryptography
GroupAPT33

APT33 has used AES for encryption of command and control traffic.

T1573.001
Symmetric Cryptography
MalwarePOWERTON

POWERTON has used AES for encrypting C2 traffic.

T1588.002
Tool
GroupAPT33

APT33 has obtained and leveraged publicly-available tools for early intrusion activities.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.