ATT&CKReferencesSecureworks IRON RITUAL Profile

Secureworks IRON RITUAL Profile

Secureworks CTU. (n.d.). IRON RITUAL. Retrieved February 24, 2022.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples4

TechniqueUsed byProcedure example
T1087.002
Domain Account
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used PowerShell to discover domain accounts by exectuing `Get-ADUser` and `Get-ADGroupMember`.

T1484.002
Trust Modification
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 changed domain federation trust settings using Azure AD administrative permissions to configure the domain to accept authorization tokens signed by their own SAML signing certificate.

T1550
Use Alternate Authentication Material
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used forged SAML tokens that allowed the actors to impersonate users and bypass MFA, enabling APT29 to access enterprise cloud applications and services.

T1606.002
SAML Tokens
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 created tokens using compromised SAML signing certificates.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.