ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Group: G0064×

31 examples

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
GroupAPT33

APT33 has used a variety of publicly available tools like LaZagne, Mimikatz, and ProcDump to dump credentials.

T1003.004
LSA Secrets
GroupAPT33

APT33 has used a variety of publicly available tools like LaZagne to gather credentials.

T1003.005
Cached Domain Credentials
GroupAPT33

APT33 has used a variety of publicly available tools like LaZagne to gather credentials.

T1027.013
Encrypted/Encoded File
GroupAPT33

APT33 has used base64 to encode payloads.

T1040
Network Sniffing
GroupAPT33

APT33 has used SniffPass to collect credentials by sniffing network traffic.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
GroupAPT33

APT33 has used FTP to exfiltrate files (separately from the C2 channel).

T1053.005
Scheduled Task
GroupAPT33

APT33 has created a scheduled task to execute a .vbe file multiple times a day.

T1059.001
PowerShell
GroupAPT33

APT33 has utilized PowerShell to download files from the C2 server and run various scripts.

T1059.005
Visual Basic
GroupAPT33

APT33 has used VBScript to initiate the delivery of payloads.

T1068
Exploitation for Privilege Escalation
GroupAPT33

APT33 has used a publicly available exploit for CVE-2017-0213 to escalate privileges on a local system.

T1071.001
Web Protocols
GroupAPT33

APT33 has used HTTP for command and control.

T1078
Valid Accounts
GroupAPT33

APT33 has used valid accounts for initial access and privilege escalation.

T1078.004
Cloud Accounts
GroupAPT33

APT33 has used compromised Office 365 accounts in tandem with Ruler in an attempt to gain control of endpoints.

T1105
Ingress Tool Transfer
GroupAPT33

APT33 has downloaded additional files and programs from its C2 server.

T1110.003
Password Spraying
GroupAPT33

APT33 has used password spraying to gain access to target systems.

T1132.001
Standard Encoding
GroupAPT33

APT33 has used base64 to encode command and control traffic.

T1203
Exploitation for Client Execution
GroupAPT33

APT33 has attempted to exploit a known vulnerability in WinRAR (CVE-2018-20250), and attempted to gain remote code execution via a security bypass vulnerability (CVE-2017-11774).

T1204.001
Malicious Link
GroupAPT33

APT33 has lured users to click links to malicious HTML applications delivered via spearphishing emails.

T1204.002
Malicious File
GroupAPT33

APT33 has used malicious e-mail attachments to lure victims into executing malware.

T1546.003
Windows Management Instrumentation Event Subscription
GroupAPT33

APT33 has attempted to use WMI event subscriptions to establish persistence on compromised hosts.

T1547.001
Registry Run Keys / Startup Folder
GroupAPT33

APT33 has deployed a tool known as DarkComet to the Startup folder of a victim, and used Registry run keys to gain persistence.

T1552.001
Credentials In Files
GroupAPT33

APT33 has used a variety of publicly available tools like LaZagne to gather credentials.

T1552.006
Group Policy Preferences
GroupAPT33

APT33 has used a variety of publicly available tools like Gpppassword to gather credentials.

T1555
Credentials from Password Stores
GroupAPT33

APT33 has used a variety of publicly available tools like LaZagne to gather credentials.

T1555.003
Credentials from Web Browsers
GroupAPT33

APT33 has used a variety of publicly available tools like LaZagne to gather credentials.

T1560.001
Archive via Utility
GroupAPT33

APT33 has used WinRAR to compress data prior to exfil.

T1566.001
Spearphishing Attachment
GroupAPT33

APT33 has sent spearphishing e-mails with archive attachments.

T1566.002
Spearphishing Link
GroupAPT33

APT33 has sent spearphishing emails containing links to .hta files.

T1571
Non-Standard Port
GroupAPT33

APT33 has used HTTP over TCP ports 808 and 880 for command and control.

T1573.001
Symmetric Cryptography
GroupAPT33

APT33 has used AES for encryption of command and control traffic.

T1588.002
Tool
GroupAPT33

APT33 has obtained and leveraged publicly-available tools for early intrusion activities.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.