ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Group: G1021×

19 examples

TechniqueUsed byProcedure example
T1021.002
SMB/Windows Admin Shares
GroupCinnamon Tempest

Cinnamon Tempest has used SMBexec for lateral movement.

T1047
Windows Management Instrumentation
GroupCinnamon Tempest

Cinnamon Tempest has used Impacket for lateral movement via WMI.

T1059.001
PowerShell
GroupCinnamon Tempest

Cinnamon Tempest has used PowerShell to communicate with C2, download files, and execute reconnaissance commands.

T1059.003
Windows Command Shell
GroupCinnamon Tempest

Cinnamon Tempest has executed ransomware using batch scripts deployed via GPO.

T1059.006
Python
GroupCinnamon Tempest

Cinnamon Tempest has used a customized version of the Impacket wmiexec.py module to create renamed output files.

T1078
Valid Accounts
GroupCinnamon Tempest

Cinnamon Tempest has used compromised user accounts to deploy payloads and create system services.

T1078.002
Domain Accounts
GroupCinnamon Tempest

Cinnamon Tempest has obtained highly privileged credentials such as domain administrator in order to deploy malware.

T1080
Taint Shared Content
GroupCinnamon Tempest

Cinnamon Tempest has deployed ransomware from a batch file in a network share.

T1090
Proxy
GroupCinnamon Tempest

Cinnamon Tempest has used a customized version of the Iox port-forwarding and proxy tool.

T1105
Ingress Tool Transfer
GroupCinnamon Tempest

Cinnamon Tempest has downloaded files, including Cobalt Strike, to compromised hosts.

T1140
Deobfuscate/Decode Files or Information
GroupCinnamon Tempest

Cinnamon Tempest has used weaponized DLLs to load and decrypt payloads.

T1190
Exploit Public-Facing Application
GroupCinnamon Tempest

Cinnamon Tempest has exploited multiple unpatched vulnerabilities for initial access including vulnerabilities in Microsoft Exchange, Manage Engine AdSelfService Plus, Confluence, and Log4j.

T1484.001
Group Policy Modification
GroupCinnamon Tempest

Cinnamon Tempest has used Group Policy to deploy batch scripts for ransomware deployment.

T1543.003
Windows Service
GroupCinnamon Tempest

Cinnamon Tempest has created system services to establish persistence for deployed tooling.

T1567.002
Exfiltration to Cloud Storage
GroupCinnamon Tempest

Cinnamon Tempest has uploaded captured keystroke logs to the Alibaba Cloud Object Storage Service, Aliyun OSS.

T1572
Protocol Tunneling
GroupCinnamon Tempest

Cinnamon Tempest has used the Iox and NPS proxy and tunneling tools in combination create multiple connections through a single tunnel.

T1574.001
DLL
GroupCinnamon Tempest

Cinnamon Tempest has used search order hijacking to launch Cobalt Strike Beacons. Cinnamon Tempest has also abused legitimate executables to side-load weaponized DLLs.

T1588.002
Tool
GroupCinnamon Tempest

Cinnamon Tempest has used open-source tools including customized versions of the Iox proxy tool, NPS tunneling tool, Meterpreter, and a keylogger that uploads data to Alibaba cloud storage.

T1657
Financial Theft
GroupCinnamon Tempest

Cinnamon Tempest has maintained leak sites for exfiltrated data in attempt to extort victims into paying a ransom.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.