ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1555.004
Windows Credential Manager
ToolMimikatz

Mimikatz contains functionality to acquire credentials from the Windows Credential Manager.

T1555.004
Windows Credential Manager
ToolLaZagne

LaZagne can obtain credentials from Vault files.

T1555.005
Password Managers
CampaignOperation Wocao

During Operation Wocao, threat actors accessed and collected credentials from password managers.

T1555.005
Password Managers
GroupIndrik Spider

Indrik Spider has accessed and exported passwords from password managers.

T1555.005
Password Managers
GroupScattered Spider

Scattered Spider has searched for credentials in password vaults and Privileged Access Management (PAM) solutions including HashiCorp Vault.

T1555.005
Password Managers
GroupUNC3886

UNC3886 has targeted KeyPass password database files for credential access.

T1555.005
Password Managers
GroupStorm-0501

Storm-0501 has stolen credentials contained in the password manager Keepass by utilizing Find-KeePassConfig.ps1.

T1555.005
Password Managers
GroupFox Kitten

Fox Kitten has used scripts to access credential information from the KeePass database.

T1555.005
Password Managers
GroupLAPSUS$

LAPSUS$ has accessed local password managers and databases to obtain further credentials from a compromised network.

T1555.005
Password Managers
GroupThreat Group-3390

Threat Group-3390 obtained a KeePass database from a compromised host.

T1555.005
Password Managers
MalwareTrickBot

TrickBot can steal passwords from the KeePass open source password manager.

T1555.005
Password Managers
MalwareInvisibleFerret

InvisibleFerret has utilized the command `ssh_zcp` to exfiltrate data from browser extensions and password managers via Telegram and FTP.

T1555.005
Password Managers
MalwareMarkiRAT

MarkiRAT can gather information from the Keepass password manager.

T1555.005
Password Managers
MalwareProton

Proton gathers credentials in files for 1password.

T1555.005
Password Managers
MalwareMini Shai-Hulud

Mini Shai-Hulud has gathered credentials stored in password managers to include password vaults.

T1555.006
Cloud Secrets Management Stores
GroupHAFNIUM

HAFNIUM has moved laterally from on-premises environments to steal passwords from Azure key vaults.

T1555.006
Cloud Secrets Management Stores
GroupStorm-0501

Storm-0501 has utilized Azure Key Vault to store the encryption key using the operation `Microsoft.KeyVault/Vaults/write`.

T1555.006
Cloud Secrets Management Stores
MalwareShai-Hulud

Shai-Hulud has gathered secrets from AWS Secrets and GCP Secret Manager. Shai-Hulud has also gathered data from Azure Key Vault.

T1555.006
Cloud Secrets Management Stores
ToolPacu

Pacu can retrieve secrets from the AWS Secrets Manager via the enum_secrets module.

T1555.006
Cloud Secrets Management Stores
ToolTruffleHog

TruffleHog can obtain secrets from AWS Secrets and GCP Secret Manager. TruffleHog has also gathered passwords, secrets and API keys from source repositories, .env files, and git history.

T1555.006
Cloud Secrets Management Stores
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer can enumerate multiple filesystem paths to extract credentials for AWS, GCP, and Azure including Identity Access Management (IAM) credentials.

T1555.006
Cloud Secrets Management Stores
MalwareMini Shai-Hulud

Mini Shai-Hulud has captured credentials stored in cloud secret stores.

T1555.006
Cloud Secrets Management Stores
MalwareCanisterWorm

CanisterWorm has gathered credentials from Amazon Web Services (AWS), Google Cloud Platform (GCP), and Microsoft Azure.

T1555.006
Cloud Secrets Management Stores
GroupTeamPCP

TeamPCP has used malware to exfiltrate cloud secrets from targeted environments including AWS, GCP, and Azure.

T1556
Modify Authentication Process
CampaignArcaneDoor

ArcaneDoor included modification of the AAA process to bypass authentication mechanisms.

T1556
Modify Authentication Process
GroupFIN13

FIN13 has replaced legitimate KeePass binaries with trojanized versions to collect passwords from numerous applications.

T1556
Modify Authentication Process
MalwareKessel

Kessel has trojanized the <sode>ssh_login</code> and user-auth_pubkey functions to steal plaintext credentials.

T1556
Modify Authentication Process
MalwareEbury

Ebury can intercept private keys using a trojanized ssh-add function.

T1556
Modify Authentication Process
MalwareDRYHOOK

DRYHOOK has intercepted and logged user credentials by modifying the Perl module in Ivanti Connect Secure VPN edge-devices located within `/home/perl/DSAuth.pm`.

T1556
Modify Authentication Process
ToolSILENTTRINITY

SILENTTRINITY can create a backdoor in KeePass using a malicious config file and in TortoiseSVN using a registry hook.

T1556.001
Domain Controller Authentication
GroupChimera

Chimera's malware has altered the NTLM authentication program on domain controllers to allow Chimera to login without a valid credential.

T1556.001
Domain Controller Authentication
MalwareSkeleton Key

Skeleton Key is used to patch an enterprise domain controller authentication process with a backdoor password. It allows adversaries to bypass the standard authentication system to use a defined password for all accounts authenticating to that domain controller.

T1556.002
Password Filter DLL
GroupStrider

Strider has registered its persistence module on domain controllers as a Windows LSA (Local System Authority) password filter to acquire credentials any time a domain, local user, or administrator logs in or changes a password.

T1556.002
Password Filter DLL
GroupOilRig

OilRig has registered a password filter DLL in order to drop malware.

T1556.002
Password Filter DLL
GroupMirrorFace

MirrorFace has used a tool named MRSAStealer as a password filter to collect credentials on password changes.

T1556.002
Password Filter DLL
MalwareRemsec

Remsec harvests plain-text credentials as a password filter registered on domain controllers.

T1556.003
Pluggable Authentication Modules
MalwareSkidmap

Skidmap has the ability to replace the pam_unix.so file on an infected machine with its own malicious version that accepts a specific backdoor password for all users.

T1556.003
Pluggable Authentication Modules
MalwareEbury

Ebury can deactivate PAM modules to tamper with the sshd configuration.

T1556.004
Network Device Authentication
MalwareSYNful Knock

SYNful Knock has the capability to add its own custom backdoor password when it modifies the operating system of the affected network device.

T1556.004
Network Device Authentication
MalwareDRYHOOK

DRYHOOK has patched victim appliances authentication routines to capture credentials in plaintext as users log in.

T1556.004
Network Device Authentication
MalwareSLOWPULSE

SLOWPULSE can modify LDAP and two factor authentication flows by inspecting login credentials and forcing successful authentication if the provided password matches a chosen backdoor password.

T1556.006
Multi-Factor Authentication
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries modified two-factor settings within the FortiGate solution to `unset`.

T1556.006
Multi-Factor Authentication
GroupScattered Spider

After compromising user accounts, Scattered Spider registers their own MFA tokens.

T1556.006
Multi-Factor Authentication
MalwareSLOWPULSE

SLOWPULSE can insert malicious logic to bypass RADIUS and ACE two factor authentication (2FA) flows if a designated attacker-supplied password is provided.

T1556.006
Multi-Factor Authentication
ToolAADInternals

The AADInternals `Set-AADIntUserMFA` command can be used to disable MFA for a specified user.

T1556.007
Hybrid Identity
GroupAPT29

APT29 has edited the `Microsoft.IdentityServer.Servicehost.exe.config` file to load a malicious DLL into the AD FS process, thereby enabling persistent access to any service federated with AD FS for a user with a specified User Principal Name.

T1556.007
Hybrid Identity
ToolAADInternals

AADInternals can inject a malicious DLL (`PTASpy`) into the `AzureADConnectAuthenticationAgentService` to backdoor Azure AD Pass-Through Authentication.

T1556.009
Conditional Access Policies
GroupScattered Spider

Scattered Spider has added additional trusted locations to Azure AD conditional access policies.

T1556.009
Conditional Access Policies
GroupStorm-0501

Storm-0501 has registered their own MFA method, and leveraged a victim hybrid joined server to circumvent Conditional Access Policies.

T1557
Adversary-in-the-Middle
CampaignArcaneDoor

ArcaneDoor included interception of HTTP traffic to victim devices to identify and parse command and control information sent to the device.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.