Real-world descriptions of how a group, tool or campaign used a technique.
70 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1001 Data Obfuscation |
CampaignOperation Wocao | During Operation Wocao, threat actors encrypted IP addresses used for "Agent" proxy hops with RC4. |
| T1003.001 LSASS Memory |
CampaignOperation Wocao | During Operation Wocao, threat actors used ProcDump to dump credentials from memory. |
| T1003.006 DCSync |
CampaignOperation Wocao | During Operation Wocao, threat actors used Mimikatz's DCSync to dump credentials from the memory of the targeted system. |
| T1005 Data from Local System |
CampaignOperation Wocao | During Operation Wocao, threat actors exfiltrated files and directories of interest from the targeted system. |
| T1007 System Service Discovery |
CampaignOperation Wocao | During Operation Wocao, threat actors used the `tasklist` command to search for one of its backdoors. |
| T1012 Query Registry |
CampaignOperation Wocao | During Operation Wocao, the threat actors executed `/c cd /d c:\windows\temp\ & reg query HKEY_CURRENT_USER\Software\<username>\PuTTY\Sessions\` to detect recent PuTTY sessions, likely to further lateral movement. |
| T1016 System Network Configuration Discovery |
CampaignOperation Wocao | During Operation Wocao, threat actors discovered the local network configuration with `ipconfig`. |
| T1016.001 Internet Connection Discovery |
CampaignOperation Wocao | During Operation Wocao, threat actors used a Visual Basic script that checked for internet connectivity. |
| T1018 Remote System Discovery |
CampaignOperation Wocao | During Operation Wocao, threat actors used `nbtscan` and `ping` to discover remote systems, as well as `dsquery subnet` on a domain controller to retrieve all subnets in the Active Directory. |
| T1021.002 SMB/Windows Admin Shares |
CampaignOperation Wocao | During Operation Wocao, threat actors used Impacket's smbexec.py as well as accessing the C$ and IPC$ shares to move laterally. |
| T1027.005 Indicator Removal from Tools |
CampaignOperation Wocao | During Operation Wocao, threat actors edited variable names within the Impacket suite to avoid automated detection. |
| T1027.010 Command Obfuscation |
CampaignOperation Wocao | During Operation Wocao, threat actors executed PowerShell commands which were encoded or compressed using Base64, zlib, and XOR. |
| T1033 System Owner/User Discovery |
CampaignOperation Wocao | During Operation Wocao, threat actors enumerated sessions and users on a remote host, and identified privileged users logged into a targeted system. |
| T1036.005 Match Legitimate Resource Name or Location |
CampaignOperation Wocao | During Operation Wocao, the threat actors renamed some tools and executables to appear as legitimate programs. |
| T1041 Exfiltration Over C2 Channel |
CampaignOperation Wocao | During Operation Wocao, threat actors used the XServer backdoor to exfiltrate data. |
| T1046 Network Service Discovery |
CampaignOperation Wocao | During Operation Wocao, threat actors scanned for open ports and used nbtscan to find NETBIOS nameservers. |
| T1047 Windows Management Instrumentation |
CampaignOperation Wocao | During Operation Wocao, threat actors has used WMI to execute commands. |
| T1049 System Network Connections Discovery |
CampaignOperation Wocao | During Operation Wocao, threat actors collected a list of open connections on the infected system using `netstat` and checks whether it has an internet connection. |
| T1053.005 Scheduled Task |
CampaignOperation Wocao | During Operation Wocao, threat actors used scheduled tasks to execute malicious PowerShell code on remote systems. |
| T1055 Process Injection |
CampaignOperation Wocao | During Operation Wocao, threat actors injected code into a selected process, which in turn launches a command as a child process of the original. |
| T1056.001 Keylogging |
CampaignOperation Wocao | During Operation Wocao, threat actors obtained the password for the victim's password manager via a custom keylogger. |
| T1057 Process Discovery |
CampaignOperation Wocao | During Operation Wocao, the threat actors used `tasklist` to collect a list of running processes on an infected system. |
| T1059.001 PowerShell |
CampaignOperation Wocao | During Operation Wocao, threat actors used PowerShell on compromised systems. |
| T1059.003 Windows Command Shell |
CampaignOperation Wocao | During Operation Wocao, threat actors spawned a new `cmd.exe` process to execute commands. |
| T1059.005 Visual Basic |
CampaignOperation Wocao | During Operation Wocao, threat actors used VBScript to conduct reconnaissance on targeted systems. |
| T1059.006 Python |
CampaignOperation Wocao | During Operation Wocao, threat actors' backdoors were written in Python and compiled with py2exe. |
| T1069.001 Local Groups |
CampaignOperation Wocao | During Operation Wocao, threat actors used the command `net localgroup administrators` to list all administrators part of a local group. |
| T1070.004 File Deletion |
CampaignOperation Wocao | During Operation Wocao, the threat actors consistently removed traces of their activity by first overwriting a file using `/c cd /d c:\windows\temp\ & copy \\<IP ADDRESS>\c$\windows\system32\devmgr.dll \\<IP ADDRESS>\c$\windows\temp\LMAKSW.ps1 /y` and then deleting the overwritten file using `/c cd /d c:\windows\temp\ & del \\<IP ADDRESS>\c$\windows\temp\LMAKSW.ps1`. |
| T1071.001 Web Protocols |
CampaignOperation Wocao | During Operation Wocao, threat actors’ XServer tool communicated using HTTP and HTTPS. |
| T1074.001 Local Data Staging |
CampaignOperation Wocao | During Operation Wocao, threat actors staged archived files in a temporary directory prior to exfiltration. |
| T1078 Valid Accounts |
CampaignOperation Wocao | During Operation Wocao, threat actors used valid VPN credentials to gain initial access. |
| T1078.002 Domain Accounts |
CampaignOperation Wocao | During Operation Wocao, threat actors used domain credentials, including domain admin, for lateral movement and privilege escalation. |
| T1078.003 Local Accounts |
CampaignOperation Wocao | During Operation Wocao, threat actors used local account credentials found during the intrusion for lateral movement and privilege escalation. |
| T1082 System Information Discovery |
CampaignOperation Wocao | During Operation Wocao, threat actors discovered the OS versions of systems connected to a targeted network. |
| T1083 File and Directory Discovery |
CampaignOperation Wocao | During Operation Wocao, threat actors gathered a recursive directory listing to find files and directories of interest. |
| T1087.002 Domain Account |
CampaignOperation Wocao | During Operation Wocao, threat actors used the `net` command to retrieve information about domain accounts. |
| T1090 Proxy |
CampaignOperation Wocao | During Operation Wocao, threat actors used a custom proxy tool called "Agent" which has support for multiple hops. |
| T1090.001 Internal Proxy |
CampaignOperation Wocao | During Operation Wocao, threat actors proxied traffic through multiple infected systems. |
| T1090.003 Multi-hop Proxy |
CampaignOperation Wocao | During Operation Wocao, threat actors executed commands through the installed web shell via Tor exit nodes. |
| T1095 Non-Application Layer Protocol |
CampaignOperation Wocao | During Operation Wocao, threat actors used a custom protocol for command and control. |
| T1105 Ingress Tool Transfer |
CampaignOperation Wocao | During Operation Wocao, threat actors downloaded additional files to the infected system. |
| T1106 Native API |
CampaignOperation Wocao | During Operation Wocao, threat actors used the `CreateProcessA` and `ShellExecute` API functions to launch commands after being injected into a selected process. |
| T1111 Multi-Factor Authentication Interception |
CampaignOperation Wocao | During Operation Wocao, threat actors used a custom collection method to intercept two-factor authentication soft tokens. |
| T1112 Modify Registry |
CampaignOperation Wocao | During Operation Wocao, the threat actors enabled Wdigest by changing the `HKLM\SYSTEM\\ControlSet001\\Control\\SecurityProviders\\WDigest` registry value from 0 (disabled) to 1 (enabled). |
| T1115 Clipboard Data |
CampaignOperation Wocao | During Operation Wocao, threat actors collected clipboard data in plaintext. |
| T1119 Automated Collection |
CampaignOperation Wocao | During Operation Wocao, threat actors used a script to collect information about the infected system. |
| T1120 Peripheral Device Discovery |
CampaignOperation Wocao | During Operation Wocao, threat actors discovered removable disks attached to a system. |
| T1124 System Time Discovery |
CampaignOperation Wocao | During Operation Wocao, threat actors used the `time` command to retrieve the current time of a compromised system. |
| T1133 External Remote Services |
CampaignOperation Wocao | During Operation Wocao, threat actors used stolen credentials to connect to the victim's network via VPN. |
| T1135 Network Share Discovery |
CampaignOperation Wocao | During Operation Wocao, threat actors discovered network disks mounted to the system using netstat. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.