ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1001.003
Protocol or Service Impersonation
MalwareNinja

Ninja has the ability to mimic legitimate services with customized HTTP URL paths and headers to hide malicious traffic.

T1001.003
Protocol or Service Impersonation
MalwareBankshot

Bankshot generates a false TLS handshake using a public certificate to disguise C2 network communications.

T1001.003
Protocol or Service Impersonation
MalwareTONESHELL

TONESHELL used FakeTLS headers in network packets to impersonate various versions of TLS protocols to blend in with legitimate network traffic. TONESHELL variants have utilized FakeTLS headers with the bytes `0x17 0x03 0x03` to represent TLSv1.2 and `0x17 0x03 0x04` for TLSv1.3.

T1001.003
Protocol or Service Impersonation
MalwareBOOKWORM

BOOKWORM has modified HTTP POST requests to resemble legitimate communications.

T1001.003
Protocol or Service Impersonation
MalwarePUBLOAD

PUBLOAD has modified HTTP POST requests to resemble legitimate communications. PUBLOAD used FakeTLS headers in network packets to impersonate various versions of TLS protocols to blend in with legitimate network traffic. PUBLOAD has utilized FakeTLS headers with the bytes 17 03 03.

T1001.003
Protocol or Service Impersonation
MalwareInvisiMole

InvisiMole can mimic HTTP protocol with custom HTTP “verbs” HIDE, ZVVP, and NOP.

T1001.003
Protocol or Service Impersonation
MalwareOkrum

Okrum leverages the HTTP protocol for C2 communication, while hiding the actual messages in the Cookie and Set-Cookie headers of the HTTP requests.

T1001.003
Protocol or Service Impersonation
MalwareKeyBoy

KeyBoy uses custom SSL libraries to impersonate SSL in C2 traffic.

T1001.003
Protocol or Service Impersonation
MalwareTAINTEDSCRIBE

TAINTEDSCRIBE has used FakeTLS for session authentication.

T1001.003
Protocol or Service Impersonation
MalwareUroburos

Uroburos can use custom communication methodologies that ride over common protocols including TCP, UDP, HTTP, SMTP, and DNS in order to blend with normal network traffic.

T1001.003
Protocol or Service Impersonation
MalwareBADCALL

BADCALL uses a FakeTLS method during C2.

T1001.003
Protocol or Service Impersonation
MalwareCobalt Strike

Cobalt Strike can leverage the HTTP protocol for C2 communication, while hiding the actual data in either an HTTP header, URI parameter, the transaction body, or appending it to the URI. Cobalt Strike has also added Host: ocsp.verisign.com to HTTP headers to mimic Online Certificate Status Protocol (OCSP) traffic.

T1001.003
Protocol or Service Impersonation
MalwareSUNBURST

SUNBURST masqueraded its network traffic as the Orion Improvement Program (OIP) protocol.

T1001.003
Protocol or Service Impersonation
MalwareFakeM

FakeM C2 traffic attempts to evade detection by resembling data generated by legitimate messenger applications, such as MSN and Yahoo! messengers. Additionally, some variants of FakeM use modified SSL code for communications back to C2 servers, making SSL decryption ineffective.

T1001.003
Protocol or Service Impersonation
MalwareFRAMESTING

FRAMESTING uses a cookie named `DSID` to mimic the name of a cookie used by Ivanti Connect Secure appliances for maintaining VPN sessions.

T1001.003
Protocol or Service Impersonation
MalwareHARDRAIN

HARDRAIN uses FakeTLS to communicate with its C2 server.

T1001.003
Protocol or Service Impersonation
MalwareStarProxy

StarProxy has utilized TLS record headers in network packets to impersonate various versions of TLS protocols to blend in with legitimate network traffic. StarProxy used FakeTLS to communicate with its C2 server.

T1001.003
Protocol or Service Impersonation
MalwareFALLCHILL

FALLCHILL uses fake Transport Layer Security (TLS) to communicate with its C2 server.

T1003
OS Credential Dumping
GroupEmber Bear

Ember Bear gathers credential material from target systems, such as SSH keys, to facilitate access to victim environments.

T1003
OS Credential Dumping
GroupAPT39

APT39 has used different versions of Mimikatz to obtain credentials.

T1003
OS Credential Dumping
MalwareCarbanak

Carbanak obtains Windows logon password details.

T1003
OS Credential Dumping
MalwareMgBot

MgBot includes modules for dumping and capturing credentials from process memory.

T1003
OS Credential Dumping
MalwareRevenge RAT

Revenge RAT has a plugin for credential harvesting.

T1003
OS Credential Dumping
MalwarePinchDuke

PinchDuke steals credentials from compromised hosts. PinchDuke's credential stealing functionality is believed to be based on the source code of the Pinch credential stealing malware (also known as LdPinch). Credentials targeted by PinchDuke include ones associated many sources such as WinInet Credential Cache, and Lightweight Directory Access Protocol (LDAP).

T1003
OS Credential Dumping
GroupPoseidon Group

Poseidon Group conducts credential dumping on victims, with a focus on obtaining credentials belonging to domain and database servers.

T1003
OS Credential Dumping
MalwareOnionDuke

OnionDuke steals credentials from its victims.

T1003
OS Credential Dumping
GroupMustang Panda

Mustang Panda utilized “Hdump” to dump credentials from memory.

T1003
OS Credential Dumping
GroupTonto Team

Tonto Team has used a variety of credential dumping tools.

T1003
OS Credential Dumping
GroupAPT32

APT32 used GetPassword_x64 to harvest credentials.

T1003
OS Credential Dumping
MalwareHOMEFRY

HOMEFRY can perform credential dumping.

T1003
OS Credential Dumping
GroupSuckfly

Suckfly used a signed credential-dumping tool to obtain victim account credentials.

T1003
OS Credential Dumping
GroupBlackByte

BlackByte used tools such as Cobalt Strike and Mimikatz to dump credentials from victim systems.

T1003
OS Credential Dumping
MalwareTrojan.Karagany

Trojan.Karagany can dump passwords and save them into \ProgramData\Mail\MailAg\pwds.txt.

T1003
OS Credential Dumping
GroupAPT28

APT28 regularly deploys both publicly available (ex: Mimikatz) and custom password retrieval tools on victims.

T1003
OS Credential Dumping
GroupSowbug

Sowbug has used credential dumping tools.

T1003
OS Credential Dumping
GroupStorm-0501

Storm-0501 has used the SecretsDump module within Impacket can perform credential dumping to obtain account and password information.

T1003
OS Credential Dumping
GroupAxiom

Axiom has been known to dump credentials.

T1003
OS Credential Dumping
GroupLeviathan

Leviathan has used publicly available tools to dump password hashes, including HOMEFRY.

T1003.001
LSASS Memory
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors used Mimikatz to dump LSASS memory.

T1003.001
LSASS Memory
CampaignTriton Safety Instrumented System Attack

In the Triton Safety Instrumented System Attack, TEMP.Veles used Mimikatz.

T1003.001
LSASS Memory
CampaignCutting Edge

During Cutting Edge, threat actors used Task Manager to dump LSASS memory from Windows devices to disk.

T1003.001
LSASS Memory
CampaignOperation Digital Eye

During Operation Digital Eye, threat actors targeted memory from the LSASS process to extract credentials.

T1003.001
LSASS Memory
CampaignHomeLand Justice

During HomeLand Justice, threat actors dumped LSASS memory on compromised hosts.

T1003.001
LSASS Memory
CampaignC0032

During the C0032 campaign, TEMP.Veles used Mimikatz and a custom tool, SecHack, to harvest credentials.

T1003.001
LSASS Memory
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries attempted to dump credentials utilizing LSASS.

T1003.001
LSASS Memory
Campaign2016 Ukraine Electric Power Attack

During the 2016 Ukraine Electric Power Attack, Sandworm Team used Mimikatz to capture and use legitimate credentials.

T1003.001
LSASS Memory
CampaignOperation Wocao

During Operation Wocao, threat actors used ProcDump to dump credentials from memory.

T1003.001
LSASS Memory
GroupIndrik Spider

Indrik Spider used Cobalt Strike to carry out credential dumping using ProcDump.

T1003.001
LSASS Memory
GroupGALLIUM

GALLIUM used a modified version of Mimikatz along with a PowerShell-based Mimikatz to dump credentials on the victim machines.

T1003.001
LSASS Memory
GroupAPT3

APT3 has used a tool to dump credentials by injecting itself into lsass.exe and triggering with the argument "dig."

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.