ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Campaign: C0014×

70 examples

TechniqueUsed byProcedure example
T1001
Data Obfuscation
CampaignOperation Wocao

During Operation Wocao, threat actors encrypted IP addresses used for "Agent" proxy hops with RC4.

T1003.001
LSASS Memory
CampaignOperation Wocao

During Operation Wocao, threat actors used ProcDump to dump credentials from memory.

T1003.006
DCSync
CampaignOperation Wocao

During Operation Wocao, threat actors used Mimikatz's DCSync to dump credentials from the memory of the targeted system.

T1005
Data from Local System
CampaignOperation Wocao

During Operation Wocao, threat actors exfiltrated files and directories of interest from the targeted system.

T1007
System Service Discovery
CampaignOperation Wocao

During Operation Wocao, threat actors used the `tasklist` command to search for one of its backdoors.

T1012
Query Registry
CampaignOperation Wocao

During Operation Wocao, the threat actors executed `/c cd /d c:\windows\temp\ & reg query HKEY_CURRENT_USER\Software\<username>\PuTTY\Sessions\` to detect recent PuTTY sessions, likely to further lateral movement.

T1016
System Network Configuration Discovery
CampaignOperation Wocao

During Operation Wocao, threat actors discovered the local network configuration with `ipconfig`.

T1016.001
Internet Connection Discovery
CampaignOperation Wocao

During Operation Wocao, threat actors used a Visual Basic script that checked for internet connectivity.

T1018
Remote System Discovery
CampaignOperation Wocao

During Operation Wocao, threat actors used `nbtscan` and `ping` to discover remote systems, as well as `dsquery subnet` on a domain controller to retrieve all subnets in the Active Directory.

T1021.002
SMB/Windows Admin Shares
CampaignOperation Wocao

During Operation Wocao, threat actors used Impacket's smbexec.py as well as accessing the C$ and IPC$ shares to move laterally.

T1027.005
Indicator Removal from Tools
CampaignOperation Wocao

During Operation Wocao, threat actors edited variable names within the Impacket suite to avoid automated detection.

T1027.010
Command Obfuscation
CampaignOperation Wocao

During Operation Wocao, threat actors executed PowerShell commands which were encoded or compressed using Base64, zlib, and XOR.

T1033
System Owner/User Discovery
CampaignOperation Wocao

During Operation Wocao, threat actors enumerated sessions and users on a remote host, and identified privileged users logged into a targeted system.

T1036.005
Match Legitimate Resource Name or Location
CampaignOperation Wocao

During Operation Wocao, the threat actors renamed some tools and executables to appear as legitimate programs.

T1041
Exfiltration Over C2 Channel
CampaignOperation Wocao

During Operation Wocao, threat actors used the XServer backdoor to exfiltrate data.

T1046
Network Service Discovery
CampaignOperation Wocao

During Operation Wocao, threat actors scanned for open ports and used nbtscan to find NETBIOS nameservers.

T1047
Windows Management Instrumentation
CampaignOperation Wocao

During Operation Wocao, threat actors has used WMI to execute commands.

T1049
System Network Connections Discovery
CampaignOperation Wocao

During Operation Wocao, threat actors collected a list of open connections on the infected system using `netstat` and checks whether it has an internet connection.

T1053.005
Scheduled Task
CampaignOperation Wocao

During Operation Wocao, threat actors used scheduled tasks to execute malicious PowerShell code on remote systems.

T1055
Process Injection
CampaignOperation Wocao

During Operation Wocao, threat actors injected code into a selected process, which in turn launches a command as a child process of the original.

T1056.001
Keylogging
CampaignOperation Wocao

During Operation Wocao, threat actors obtained the password for the victim's password manager via a custom keylogger.

T1057
Process Discovery
CampaignOperation Wocao

During Operation Wocao, the threat actors used `tasklist` to collect a list of running processes on an infected system.

T1059.001
PowerShell
CampaignOperation Wocao

During Operation Wocao, threat actors used PowerShell on compromised systems.

T1059.003
Windows Command Shell
CampaignOperation Wocao

During Operation Wocao, threat actors spawned a new `cmd.exe` process to execute commands.

T1059.005
Visual Basic
CampaignOperation Wocao

During Operation Wocao, threat actors used VBScript to conduct reconnaissance on targeted systems.

T1059.006
Python
CampaignOperation Wocao

During Operation Wocao, threat actors' backdoors were written in Python and compiled with py2exe.

T1069.001
Local Groups
CampaignOperation Wocao

During Operation Wocao, threat actors used the command `net localgroup administrators` to list all administrators part of a local group.

T1070.004
File Deletion
CampaignOperation Wocao

During Operation Wocao, the threat actors consistently removed traces of their activity by first overwriting a file using `/c cd /d c:\windows\temp\ & copy \\<IP ADDRESS>\c$\windows\system32\devmgr.dll \\<IP ADDRESS>\c$\windows\temp\LMAKSW.ps1 /y` and then deleting the overwritten file using `/c cd /d c:\windows\temp\ & del \\<IP ADDRESS>\c$\windows\temp\LMAKSW.ps1`.

T1071.001
Web Protocols
CampaignOperation Wocao

During Operation Wocao, threat actors’ XServer tool communicated using HTTP and HTTPS.

T1074.001
Local Data Staging
CampaignOperation Wocao

During Operation Wocao, threat actors staged archived files in a temporary directory prior to exfiltration.

T1078
Valid Accounts
CampaignOperation Wocao

During Operation Wocao, threat actors used valid VPN credentials to gain initial access.

T1078.002
Domain Accounts
CampaignOperation Wocao

During Operation Wocao, threat actors used domain credentials, including domain admin, for lateral movement and privilege escalation.

T1078.003
Local Accounts
CampaignOperation Wocao

During Operation Wocao, threat actors used local account credentials found during the intrusion for lateral movement and privilege escalation.

T1082
System Information Discovery
CampaignOperation Wocao

During Operation Wocao, threat actors discovered the OS versions of systems connected to a targeted network.

T1083
File and Directory Discovery
CampaignOperation Wocao

During Operation Wocao, threat actors gathered a recursive directory listing to find files and directories of interest.

T1087.002
Domain Account
CampaignOperation Wocao

During Operation Wocao, threat actors used the `net` command to retrieve information about domain accounts.

T1090
Proxy
CampaignOperation Wocao

During Operation Wocao, threat actors used a custom proxy tool called "Agent" which has support for multiple hops.

T1090.001
Internal Proxy
CampaignOperation Wocao

During Operation Wocao, threat actors proxied traffic through multiple infected systems.

T1090.003
Multi-hop Proxy
CampaignOperation Wocao

During Operation Wocao, threat actors executed commands through the installed web shell via Tor exit nodes.

T1095
Non-Application Layer Protocol
CampaignOperation Wocao

During Operation Wocao, threat actors used a custom protocol for command and control.

T1105
Ingress Tool Transfer
CampaignOperation Wocao

During Operation Wocao, threat actors downloaded additional files to the infected system.

T1106
Native API
CampaignOperation Wocao

During Operation Wocao, threat actors used the `CreateProcessA` and `ShellExecute` API functions to launch commands after being injected into a selected process.

T1111
Multi-Factor Authentication Interception
CampaignOperation Wocao

During Operation Wocao, threat actors used a custom collection method to intercept two-factor authentication soft tokens.

T1112
Modify Registry
CampaignOperation Wocao

During Operation Wocao, the threat actors enabled Wdigest by changing the `HKLM\SYSTEM\\ControlSet001\\Control\\SecurityProviders\\WDigest` registry value from 0 (disabled) to 1 (enabled).

T1115
Clipboard Data
CampaignOperation Wocao

During Operation Wocao, threat actors collected clipboard data in plaintext.

T1119
Automated Collection
CampaignOperation Wocao

During Operation Wocao, threat actors used a script to collect information about the infected system.

T1120
Peripheral Device Discovery
CampaignOperation Wocao

During Operation Wocao, threat actors discovered removable disks attached to a system.

T1124
System Time Discovery
CampaignOperation Wocao

During Operation Wocao, threat actors used the `time` command to retrieve the current time of a compromised system.

T1133
External Remote Services
CampaignOperation Wocao

During Operation Wocao, threat actors used stolen credentials to connect to the victim's network via VPN.

T1135
Network Share Discovery
CampaignOperation Wocao

During Operation Wocao, threat actors discovered network disks mounted to the system using netstat.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.