The Australian Cyber Security Centre (ACSC), the Canadian Centre for Cyber Security (CCCS), the New Zealand National Cyber Security Centre (NZ NCSC), CERT New Zealand, the UK National Cyber Security Centre (UK NCSC) and the US National Cybersecurity and Communications Integration Center (NCCIC). (2018, October 11). Joint report on publicly available hacking tools. Retrieved March 11, 2019.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.001 LSASS Memory |
ToolMimikatz | Mimikatz performs credential dumping to obtain account and password information useful in gaining access to additional systems and enterprise network resources. It contains functionality to acquire information about credentials in many ways, including from the LSASS Memory. |
| T1003.001 LSASS Memory |
MalwareNotPetya | NotPetya contains a modified version of Mimikatz to help gather credentials that are later used for lateral movement. |
| T1003.002 Security Account Manager |
ToolMimikatz | Mimikatz performs credential dumping to obtain account and password information useful in gaining access to additional systems and enterprise network resources. It contains functionality to acquire information about credentials in many ways, including from the SAM table. |
| T1003.004 LSA Secrets |
ToolMimikatz | Mimikatz performs credential dumping to obtain account and password information useful in gaining access to additional systems and enterprise network resources. It contains functionality to acquire information about credentials in many ways, including from the LSA. |
| T1003.006 DCSync |
ToolMimikatz | Mimikatz performs credential dumping to obtain account and password information useful in gaining access to additional systems and enterprise network resources. It contains functionality to acquire information about credentials in many ways, including from DCSync/NetSync. |
| T1005 Data from Local System |
MalwareChina Chopper | China Chopper's server component can upload local files. |
| T1014 Rootkit |
ToolHTRAN | HTRAN can install a rootkit to hide network connections from the host OS. |
| T1055 Process Injection |
ToolHTRAN | HTRAN can inject into into running processes. |
| T1059.001 PowerShell |
ToolEmpire | Empire leverages PowerShell for the majority of its client-side agent tasks. Empire also contains the ability to conduct PowerShell remoting with the |
| T1059.003 Windows Command Shell |
MalwareChina Chopper | China Chopper's server component is capable of opening a command terminal. |
| T1070.006 Timestomp |
MalwareChina Chopper | China Chopper's server component can change the timestamp of files. |
| T1090 Proxy |
ToolHTRAN | HTRAN can proxy TCP socket connections to obfuscate command and control infrastructure. |
| T1105 Ingress Tool Transfer |
MalwareChina Chopper | China Chopper's server component can download remote files. |
| T1550.002 Pass the Hash |
ToolMimikatz | Mimikatz's |
| T1550.003 Pass the Ticket |
ToolMimikatz | Mimikatz’s |
| T1555 Credentials from Password Stores |
ToolMimikatz | Mimikatz performs credential dumping to obtain account and password information useful in gaining access to additional systems and enterprise network resources. It contains functionality to acquire information about credentials in many ways, including from the credential vault and DPAPI. |
| T1555.003 Credentials from Web Browsers |
ToolMimikatz | Mimikatz performs credential dumping to obtain account and password information useful in gaining access to additional systems and enterprise network resources. It contains functionality to acquire information about credentials in many ways, including from DPAPI. |
| T1588.002 Tool |
GroupAPT19 | APT19 has obtained and used publicly-available tools like Empire. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.