ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Group: G0006×

23 examples

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
GroupAPT1

APT1 has been known to use credential dumping using Mimikatz.

T1005
Data from Local System
GroupAPT1

APT1 has collected files from a local victim.

T1007
System Service Discovery
GroupAPT1

APT1 used the commands net start and tasklist to get a listing of the services on the system.

T1016
System Network Configuration Discovery
GroupAPT1

APT1 used the ipconfig /all command to gather network configuration information.

T1021.001
Remote Desktop Protocol
GroupAPT1

The APT1 group is known to have used RDP during operations.

T1036.005
Match Legitimate Resource Name or Location
GroupAPT1

The file name AcroRD32.exe, a legitimate process name for Adobe's Acrobat Reader, was used by APT1 as a name for malware.

T1049
System Network Connections Discovery
GroupAPT1

APT1 used the net use command to get a listing on network connections.

T1057
Process Discovery
GroupAPT1

APT1 gathered a list of running processes on the system using tasklist /v.

T1059.003
Windows Command Shell
GroupAPT1

APT1 has used the Windows command shell to execute commands, and batch scripting to automate execution.

T1087.001
Local Account
GroupAPT1

APT1 used the commands net localgroup,net user, and net group to find accounts on the system.

T1114.001
Local Email Collection
GroupAPT1

APT1 uses two utilities, GETMAIL and MAPIGET, to steal email. GETMAIL extracts emails from archived Outlook .pst files.

T1114.002
Remote Email Collection
GroupAPT1

APT1 uses two utilities, GETMAIL and MAPIGET, to steal email. MAPIGET steals email still on Exchange servers that has not yet been archived.

T1119
Automated Collection
GroupAPT1

APT1 used a batch script to perform a series of discovery techniques and saves it to a text file.

T1135
Network Share Discovery
GroupAPT1

APT1 listed connected network shares.

T1550.002
Pass the Hash
GroupAPT1

The APT1 group is known to have used pass the hash.

T1560.001
Archive via Utility
GroupAPT1

APT1 has used RAR to compress files before moving them outside of the victim network.

T1566.001
Spearphishing Attachment
GroupAPT1

APT1 has sent spearphishing emails containing malicious attachments.

T1566.002
Spearphishing Link
GroupAPT1

APT1 has sent spearphishing emails containing hyperlinks to malicious files.

T1583.001
Domains
GroupAPT1

APT1 has registered hundreds of domains for use in operations.

T1584.001
Domains
GroupAPT1

APT1 hijacked FQDNs associated with legitimate websites hosted by hop points.

T1585.002
Email Accounts
GroupAPT1

APT1 has created email accounts for later use in social engineering, phishing, and when registering domains.

T1588.001
Malware
GroupAPT1

APT1 used publicly available malware for privilege escalation.

T1588.002
Tool
GroupAPT1

APT1 has used various open-source tools for privilege escalation purposes.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.