Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1001.003 Protocol or Service Impersonation |
MalwareNinja | Ninja has the ability to mimic legitimate services with customized HTTP URL paths and headers to hide malicious traffic. |
| T1001.003 Protocol or Service Impersonation |
MalwareBankshot | Bankshot generates a false TLS handshake using a public certificate to disguise C2 network communications. |
| T1001.003 Protocol or Service Impersonation |
MalwareTONESHELL | TONESHELL used FakeTLS headers in network packets to impersonate various versions of TLS protocols to blend in with legitimate network traffic. TONESHELL variants have utilized FakeTLS headers with the bytes `0x17 0x03 0x03` to represent TLSv1.2 and `0x17 0x03 0x04` for TLSv1.3. |
| T1001.003 Protocol or Service Impersonation |
MalwareBOOKWORM | BOOKWORM has modified HTTP POST requests to resemble legitimate communications. |
| T1001.003 Protocol or Service Impersonation |
MalwarePUBLOAD | PUBLOAD has modified HTTP POST requests to resemble legitimate communications. PUBLOAD used FakeTLS headers in network packets to impersonate various versions of TLS protocols to blend in with legitimate network traffic. PUBLOAD has utilized FakeTLS headers with the bytes 17 03 03. |
| T1001.003 Protocol or Service Impersonation |
MalwareInvisiMole | InvisiMole can mimic HTTP protocol with custom HTTP “verbs” HIDE, ZVVP, and NOP. |
| T1001.003 Protocol or Service Impersonation |
MalwareOkrum | Okrum leverages the HTTP protocol for C2 communication, while hiding the actual messages in the Cookie and Set-Cookie headers of the HTTP requests. |
| T1001.003 Protocol or Service Impersonation |
MalwareKeyBoy | KeyBoy uses custom SSL libraries to impersonate SSL in C2 traffic. |
| T1001.003 Protocol or Service Impersonation |
MalwareTAINTEDSCRIBE | TAINTEDSCRIBE has used FakeTLS for session authentication. |
| T1001.003 Protocol or Service Impersonation |
MalwareUroburos | Uroburos can use custom communication methodologies that ride over common protocols including TCP, UDP, HTTP, SMTP, and DNS in order to blend with normal network traffic. |
| T1001.003 Protocol or Service Impersonation |
MalwareBADCALL | BADCALL uses a FakeTLS method during C2. |
| T1001.003 Protocol or Service Impersonation |
MalwareCobalt Strike | Cobalt Strike can leverage the HTTP protocol for C2 communication, while hiding the actual data in either an HTTP header, URI parameter, the transaction body, or appending it to the URI. Cobalt Strike has also added Host: ocsp.verisign.com to HTTP headers to mimic Online Certificate Status Protocol (OCSP) traffic. |
| T1001.003 Protocol or Service Impersonation |
MalwareSUNBURST | SUNBURST masqueraded its network traffic as the Orion Improvement Program (OIP) protocol. |
| T1001.003 Protocol or Service Impersonation |
MalwareFakeM | FakeM C2 traffic attempts to evade detection by resembling data generated by legitimate messenger applications, such as MSN and Yahoo! messengers. Additionally, some variants of FakeM use modified SSL code for communications back to C2 servers, making SSL decryption ineffective. |
| T1001.003 Protocol or Service Impersonation |
MalwareFRAMESTING | FRAMESTING uses a cookie named `DSID` to mimic the name of a cookie used by Ivanti Connect Secure appliances for maintaining VPN sessions. |
| T1001.003 Protocol or Service Impersonation |
MalwareHARDRAIN | HARDRAIN uses FakeTLS to communicate with its C2 server. |
| T1001.003 Protocol or Service Impersonation |
MalwareStarProxy | StarProxy has utilized TLS record headers in network packets to impersonate various versions of TLS protocols to blend in with legitimate network traffic. StarProxy used FakeTLS to communicate with its C2 server. |
| T1001.003 Protocol or Service Impersonation |
MalwareFALLCHILL | FALLCHILL uses fake Transport Layer Security (TLS) to communicate with its C2 server. |
| T1003 OS Credential Dumping |
GroupEmber Bear | Ember Bear gathers credential material from target systems, such as SSH keys, to facilitate access to victim environments. |
| T1003 OS Credential Dumping |
GroupAPT39 | APT39 has used different versions of Mimikatz to obtain credentials. |
| T1003 OS Credential Dumping |
MalwareCarbanak | Carbanak obtains Windows logon password details. |
| T1003 OS Credential Dumping |
MalwareMgBot | MgBot includes modules for dumping and capturing credentials from process memory. |
| T1003 OS Credential Dumping |
MalwareRevenge RAT | Revenge RAT has a plugin for credential harvesting. |
| T1003 OS Credential Dumping |
MalwarePinchDuke | PinchDuke steals credentials from compromised hosts. PinchDuke's credential stealing functionality is believed to be based on the source code of the Pinch credential stealing malware (also known as LdPinch). Credentials targeted by PinchDuke include ones associated many sources such as WinInet Credential Cache, and Lightweight Directory Access Protocol (LDAP). |
| T1003 OS Credential Dumping |
GroupPoseidon Group | Poseidon Group conducts credential dumping on victims, with a focus on obtaining credentials belonging to domain and database servers. |
| T1003 OS Credential Dumping |
MalwareOnionDuke | OnionDuke steals credentials from its victims. |
| T1003 OS Credential Dumping |
GroupMustang Panda | Mustang Panda utilized “Hdump” to dump credentials from memory. |
| T1003 OS Credential Dumping |
GroupTonto Team | Tonto Team has used a variety of credential dumping tools. |
| T1003 OS Credential Dumping |
GroupAPT32 | APT32 used GetPassword_x64 to harvest credentials. |
| T1003 OS Credential Dumping |
MalwareHOMEFRY | HOMEFRY can perform credential dumping. |
| T1003 OS Credential Dumping |
GroupSuckfly | Suckfly used a signed credential-dumping tool to obtain victim account credentials. |
| T1003 OS Credential Dumping |
GroupBlackByte | BlackByte used tools such as Cobalt Strike and Mimikatz to dump credentials from victim systems. |
| T1003 OS Credential Dumping |
MalwareTrojan.Karagany | Trojan.Karagany can dump passwords and save them into |
| T1003 OS Credential Dumping |
GroupAPT28 | APT28 regularly deploys both publicly available (ex: Mimikatz) and custom password retrieval tools on victims. |
| T1003 OS Credential Dumping |
GroupSowbug | Sowbug has used credential dumping tools. |
| T1003 OS Credential Dumping |
GroupStorm-0501 | Storm-0501 has used the SecretsDump module within Impacket can perform credential dumping to obtain account and password information. |
| T1003 OS Credential Dumping |
GroupAxiom | Axiom has been known to dump credentials. |
| T1003 OS Credential Dumping |
GroupLeviathan | Leviathan has used publicly available tools to dump password hashes, including HOMEFRY. |
| T1003.001 LSASS Memory |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors used Mimikatz to dump LSASS memory. |
| T1003.001 LSASS Memory |
CampaignTriton Safety Instrumented System Attack | In the Triton Safety Instrumented System Attack, TEMP.Veles used Mimikatz. |
| T1003.001 LSASS Memory |
CampaignCutting Edge | During Cutting Edge, threat actors used Task Manager to dump LSASS memory from Windows devices to disk. |
| T1003.001 LSASS Memory |
CampaignOperation Digital Eye | During Operation Digital Eye, threat actors targeted memory from the LSASS process to extract credentials. |
| T1003.001 LSASS Memory |
CampaignHomeLand Justice | During HomeLand Justice, threat actors dumped LSASS memory on compromised hosts. |
| T1003.001 LSASS Memory |
CampaignC0032 | During the C0032 campaign, TEMP.Veles used Mimikatz and a custom tool, SecHack, to harvest credentials. |
| T1003.001 LSASS Memory |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries attempted to dump credentials utilizing LSASS. |
| T1003.001 LSASS Memory |
Campaign2016 Ukraine Electric Power Attack | During the 2016 Ukraine Electric Power Attack, Sandworm Team used Mimikatz to capture and use legitimate credentials. |
| T1003.001 LSASS Memory |
CampaignOperation Wocao | During Operation Wocao, threat actors used ProcDump to dump credentials from memory. |
| T1003.001 LSASS Memory |
GroupIndrik Spider | Indrik Spider used Cobalt Strike to carry out credential dumping using ProcDump. |
| T1003.001 LSASS Memory |
GroupGALLIUM | GALLIUM used a modified version of Mimikatz along with a PowerShell-based Mimikatz to dump credentials on the victim machines. |
| T1003.001 LSASS Memory |
GroupAPT3 | APT3 has used a tool to dump credentials by injecting itself into lsass.exe and triggering with the argument "dig." |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.