Secureworks CTU. (n.d.). IRON RITUAL. Retrieved February 24, 2022.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1087.002 Domain Account |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used PowerShell to discover domain accounts by exectuing `Get-ADUser` and `Get-ADGroupMember`. |
| T1484.002 Trust Modification |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 changed domain federation trust settings using Azure AD administrative permissions to configure the domain to accept authorization tokens signed by their own SAML signing certificate. |
| T1550 Use Alternate Authentication Material |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used forged SAML tokens that allowed the actors to impersonate users and bypass MFA, enabling APT29 to access enterprise cloud applications and services. |
| T1606.002 SAML Tokens |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 created tokens using compromised SAML signing certificates. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.