ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Campaign: C0012×

33 examples

TechniqueUsed byProcedure example
T1003.002
Security Account Manager
CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors leveraged a custom tool to dump OS credentials and used following commands: `reg save HKLM\\SYSTEM system.hiv`, `reg save HKLM\\SAM sam.hiv`, and `reg save HKLM\\SECURITY security.hiv`, to dump SAM, SYSTEM and SECURITY hives.

T1005
Data from Local System
CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors collected data, files, and other information from compromised networks.

T1007
System Service Discovery
CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors used the `net start` command as part of their initial reconnaissance.

T1016
System Network Configuration Discovery
CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors used `ipconfig`, `nbtstat`, `tracert`, `route print`, and `cat /etc/hosts` commands.

T1018
Remote System Discovery
CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors used the `net view` and `ping` commands as part of their advanced reconnaissance.

T1027.010
Command Obfuscation
CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors executed an encoded VBScript file.

T1027.011
Fileless Storage
CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors stroed payloads in Windows CLFS (Common Log File System) transactional logs.

T1033
System Owner/User Discovery
CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors used the `query user` and `whoami` commands as part of their advanced reconnaissance.

T1036.005
Match Legitimate Resource Name or Location
CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors renamed a malicious executable to `rundll32.exe` to allow it to blend in with other Windows system files.

T1049
System Network Connections Discovery
CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors used the `net session`, `net use`, and `netstat` commands as part of their advanced reconnaissance.

T1053.005
Scheduled Task
CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors used scheduled tasks to execute batch scripts for lateral movement with the following command: `SCHTASKS /Create /S <IP Address> /U <Username> /p <Password> /SC ONCE /TN test /TR <Path to a Batch File> /ST <Time> /RU SYSTEM.`

T1057
Process Discovery
CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors used the `tasklist` command as part of their advanced reconnaissance.

T1059.003
Windows Command Shell
CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors used batch scripts to perform reconnaissance.

T1059.005
Visual Basic
CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors executed an encoded VBScript file using `wscript` and wrote the decoded output to a text file.

T1069.001
Local Groups
CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors used the `net group` command as part of their advanced reconnaissance.

T1071.001
Web Protocols
CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors enabled HTTP and HTTPS listeners.

T1078.002
Domain Accounts
CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors used compromised domain administrator credentials as part of their lateral movement.

T1082
System Information Discovery
CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors used the `systeminfo` command to gather details about a compromised system.

T1083
File and Directory Discovery
CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors used `dir c:\\` to search for files.

T1087.001
Local Account
CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors used the `net user` command to gather account information.

T1087.002
Domain Account
CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors used the `dsquery` and `dsget` commands to get domain environment information and to query users in administrative groups.

T1120
Peripheral Device Discovery
CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors used the `fsutil fsinfo drives` command as part of their advanced reconnaissance.

T1124
System Time Discovery
CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors used the `net time` command as part of their advanced reconnaissance.

T1133
External Remote Services
CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors enabled WinRM over HTTP/HTTPS as a backup persistence mechanism using the following command: `cscript //nologo "C:\Windows\System32\winrm.vbs" set winrm/config/service@{EnableCompatibilityHttpsListener="true"}`.

T1135
Network Share Discovery
CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors used the `net share` command as part of their advanced reconnaissance.

T1190
Exploit Public-Facing Application
CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors exploited multiple vulnerabilities in externally facing servers.

T1201
Password Policy Discovery
CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors used the `net accounts` command as part of their advanced reconnaissance.

T1505.003
Web Shell
CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors generated a web shell within a vulnerable Enterprise Resource Planning Web Application Server as a persistence mechanism.

T1543.003
Windows Service
CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors modified the `IKEEXT` and `PrintNotify` Windows services for persistence.

T1547.006
Kernel Modules and Extensions
CampaignOperation CuckooBees

During Operation CuckooBees, attackers used a signed kernel rootkit to establish additional persistence.

T1560.001
Archive via Utility
CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors used the Makecab utility to compress and a version of WinRAR to create password-protected archives of stolen data prior to exfiltration.

T1574.001
DLL
CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors used the legitimate Windows services `IKEEXT` and `PrintNotify` to side-load malicious DLLs.

T1588.002
Tool
CampaignOperation CuckooBees

For Operation CuckooBees, the threat actors obtained publicly-available JSP code that was used to deploy a webshell onto a compromised server.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.