Real-world descriptions of how a group, tool or campaign used a technique.
25 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.001 LSASS Memory |
CampaignHomeLand Justice | During HomeLand Justice, threat actors dumped LSASS memory on compromised hosts. |
| T1021.001 Remote Desktop Protocol |
CampaignHomeLand Justice | During HomeLand Justice, threat actors primarily used RDP for lateral movement in the victim environment. |
| T1021.002 SMB/Windows Admin Shares |
CampaignHomeLand Justice | During HomeLand Justice, threat actors used SMB for lateral movement. |
| T1036.005 Match Legitimate Resource Name or Location |
CampaignHomeLand Justice | During HomeLand Justice, threat actors renamed ROADSWEEP to GoXML.exe and ZeroCleare to cl.exe. |
| T1041 Exfiltration Over C2 Channel |
CampaignHomeLand Justice | During HomeLand Justice, threat actors used HTTP to transfer data from compromised Exchange servers. |
| T1046 Network Service Discovery |
CampaignHomeLand Justice | During HomeLand Justice, threat actors executed the Advanced Port Scanner tool on compromised systems. |
| T1047 Windows Management Instrumentation |
CampaignHomeLand Justice | During HomeLand Justice, threat actors used WMI to modify Windows Defender settings. |
| T1059.001 PowerShell |
CampaignHomeLand Justice | During HomeLand Justice, threat actors used PowerShell cmdlets New-MailboxSearch and Get-Recipient for discovery. |
| T1059.003 Windows Command Shell |
CampaignHomeLand Justice | During HomeLand Justice, threat actors used Windows batch files for persistence and execution. |
| T1078 Valid Accounts |
CampaignHomeLand Justice | During HomeLand Justice, threat actors used a compromised Exchange account to search mailboxes and create new Exchange accounts. |
| T1078.001 Default Accounts |
CampaignHomeLand Justice | During HomeLand Justice, threat actors used the built-in administrator account to move laterally using RDP and Impacket. |
| T1087.003 Email Account |
CampaignHomeLand Justice | During HomeLand Justice, threat actors used compromised Exchange accounts to search mailboxes for administrator accounts. |
| T1098.002 Additional Email Delegate Permissions |
CampaignHomeLand Justice | During HomeLand Justice, threat actors added the `ApplicationImpersonation` management role to accounts under their control to impersonate users and take ownership of targeted mailboxes. |
| T1105 Ingress Tool Transfer |
CampaignHomeLand Justice | During HomeLand Justice, threat actors used web shells to download files to compromised infrastructure. |
| T1114.002 Remote Email Collection |
CampaignHomeLand Justice | During HomeLand Justice, threat actors made multiple HTTP POST requests to the Exchange servers of the victim organization to transfer data. |
| T1134.001 Token Impersonation/Theft |
CampaignHomeLand Justice | During HomeLand Justice, threat actors used custom tooling to acquire tokens using `ImpersonateLoggedOnUser/SetThreadToken`. |
| T1190 Exploit Public-Facing Application |
CampaignHomeLand Justice | For HomeLand Justice, threat actors exploited CVE-2019-0604 in Microsoft SharePoint for initial access. |
| T1486 Data Encrypted for Impact |
CampaignHomeLand Justice | During HomeLand Justice, threat actors used ROADSWEEP ransomware to encrypt files on targeted systems. |
| T1505.003 Web Shell |
CampaignHomeLand Justice | For HomeLand Justice, threat actors used .aspx webshells named pickers.aspx, error4.aspx, and ClientBin.aspx, to maintain persistence. |
| T1561.002 Disk Structure Wipe |
CampaignHomeLand Justice | During HomeLand Justice, threat actors used a version of ZeroCleare to wipe disk drives on targeted hosts. |
| T1570 Lateral Tool Transfer |
CampaignHomeLand Justice | During HomeLand Justice, threat actors initiated a process named Mellona.exe to spread the ROADSWEEP file encryptor and a persistence script to a list of internal machines. |
| T1588.002 Tool |
CampaignHomeLand Justice | During HomeLand Justice, threat actors used tools including Advanced Port Scanner, Mimikatz, and Impacket. |
| T1588.003 Code Signing Certificates |
CampaignHomeLand Justice | During HomeLand Justice, threat actors used tools with legitimate code signing certificates. |
| T1685 Disable or Modify Tools |
CampaignHomeLand Justice | During HomeLand Justice, threat actors modified and disabled components of endpoint detection and response (EDR) solutions including Microsoft Defender Antivirus. |
| T1685.001 Disable or Modify Windows Event Log |
CampaignHomeLand Justice | During HomeLand Justice, threat actors deleted Windows events and application logs. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.