ATT&CKReferencesNCSC Joint Report Public Tools

NCSC Joint Report Public Tools

The Australian Cyber Security Centre (ACSC), the Canadian Centre for Cyber Security (CCCS), the New Zealand National Cyber Security Centre (NZ NCSC), CERT New Zealand, the UK National Cyber Security Centre (UK NCSC) and the US National Cybersecurity and Communications Integration Center (NCCIC). (2018, October 11). Joint report on publicly available hacking tools. Retrieved March 11, 2019.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software2

Campaigns0

None recorded.

Procedure examples18

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
ToolMimikatz

Mimikatz performs credential dumping to obtain account and password information useful in gaining access to additional systems and enterprise network resources. It contains functionality to acquire information about credentials in many ways, including from the LSASS Memory.

T1003.001
LSASS Memory
MalwareNotPetya

NotPetya contains a modified version of Mimikatz to help gather credentials that are later used for lateral movement.

T1003.002
Security Account Manager
ToolMimikatz

Mimikatz performs credential dumping to obtain account and password information useful in gaining access to additional systems and enterprise network resources. It contains functionality to acquire information about credentials in many ways, including from the SAM table.

T1003.004
LSA Secrets
ToolMimikatz

Mimikatz performs credential dumping to obtain account and password information useful in gaining access to additional systems and enterprise network resources. It contains functionality to acquire information about credentials in many ways, including from the LSA.

T1003.006
DCSync
ToolMimikatz

Mimikatz performs credential dumping to obtain account and password information useful in gaining access to additional systems and enterprise network resources. It contains functionality to acquire information about credentials in many ways, including from DCSync/NetSync.

T1005
Data from Local System
MalwareChina Chopper

China Chopper's server component can upload local files.

T1014
Rootkit
ToolHTRAN

HTRAN can install a rootkit to hide network connections from the host OS.

T1055
Process Injection
ToolHTRAN

HTRAN can inject into into running processes.

T1059.001
PowerShell
ToolEmpire

Empire leverages PowerShell for the majority of its client-side agent tasks. Empire also contains the ability to conduct PowerShell remoting with the Invoke-PSRemoting module.

T1059.003
Windows Command Shell
MalwareChina Chopper

China Chopper's server component is capable of opening a command terminal.

T1070.006
Timestomp
MalwareChina Chopper

China Chopper's server component can change the timestamp of files.

T1090
Proxy
ToolHTRAN

HTRAN can proxy TCP socket connections to obfuscate command and control infrastructure.

T1105
Ingress Tool Transfer
MalwareChina Chopper

China Chopper's server component can download remote files.

T1550.002
Pass the Hash
ToolMimikatz

Mimikatz's SEKURLSA::Pth module can impersonate a user, with only a password hash, to execute arbitrary commands.

T1550.003
Pass the Ticket
ToolMimikatz

Mimikatz’s LSADUMP::DCSync and KERBEROS::PTT modules implement the three steps required to extract the krbtgt account hash and create/use Kerberos tickets.

T1555
Credentials from Password Stores
ToolMimikatz

Mimikatz performs credential dumping to obtain account and password information useful in gaining access to additional systems and enterprise network resources. It contains functionality to acquire information about credentials in many ways, including from the credential vault and DPAPI.

T1555.003
Credentials from Web Browsers
ToolMimikatz

Mimikatz performs credential dumping to obtain account and password information useful in gaining access to additional systems and enterprise network resources. It contains functionality to acquire information about credentials in many ways, including from DPAPI.

T1588.002
Tool
GroupAPT19

APT19 has obtained and used publicly-available tools like Empire.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.