ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1557
Adversary-in-the-Middle
GroupKimsuky

Kimsuky has used modified versions of PHProxy to examine web traffic between the victim and the accessed website.

T1557
Adversary-in-the-Middle
GroupMustang Panda

Mustang Panda leveraged a captive portal hijack that redirected the victim to a webpage that prompted the victim to download a malicious payload.

T1557
Adversary-in-the-Middle
GroupSea Turtle

Sea Turtle modified DNS records at service providers to redirect traffic from legitimate resources to Sea Turtle-controlled servers to enable adversary-in-the-middle attacks for credential capture.

T1557
Adversary-in-the-Middle
MalwareLine Runner

Line Runner intercepts HTTP requests to the victim Cisco ASA, looking for a request with a 32-character, victim dependent parameter. If that parameter matches a value in the malware, a contained payload is then written to a Lua script and executed.

T1557
Adversary-in-the-Middle
MalwareDok

Dok proxies web traffic to potentially monitor and alter victim HTTP(S) traffic.

T1557
Adversary-in-the-Middle
ToolNPPSPY

NPPSPY opens a new network listener for the mpnotify.exe process that is typically contacted by the Winlogon process in Windows. A new, alternative RPC channel is set up with a malicious DLL recording plaintext credentials entered into Winlogon, effectively intercepting and redirecting the logon information.

T1557
Adversary-in-the-Middle
Toolevilginx2

evilginx2 has the ability to act as an adversary-in-the-middle (AiTM) relay between a legitimate website and a phished user to capture all transmitted data including usernames, passwords, authentication tokens, and session cookies and tokens.

T1557
Adversary-in-the-Middle
MalwareKali365

Kali365 has created obfuscated phishing landing pages that act as an adversary in the middle infrastructure that intercepts communications between the victim host and legitimate services to steal credentials and user sessions.

T1557.001
Name Resolution Poisoning and SMB Relay
GroupLazarus Group

Lazarus Group executed Responder using the command [Responder file path] -i [IP address] -rPv on a compromised host to harvest credentials and move laterally.

T1557.001
Name Resolution Poisoning and SMB Relay
GroupWizard Spider

Wizard Spider has used the Invoke-Inveigh PowerShell cmdlets, likely for name service poisoning.

T1557.001
Name Resolution Poisoning and SMB Relay
ToolImpacket

Impacket modules like ntlmrelayx and smbrelayx can be used in conjunction with Network Sniffing and Name Resolution Poisoning and SMB Relay to gather NetNTLM credentials for Brute Force or relay attacks that can gain code execution.

T1557.001
Name Resolution Poisoning and SMB Relay
ToolEmpire

Empire can use Inveigh to conduct name service poisoning for credential theft and associated relay attacks.

T1557.001
Name Resolution Poisoning and SMB Relay
ToolPoshC2

PoshC2 can use Inveigh to conduct name service poisoning for credential theft and associated relay attacks.

T1557.001
Name Resolution Poisoning and SMB Relay
ToolResponder

Responder is used to poison name services to gather hashes and credentials from systems within a local network.

T1557.001
Name Resolution Poisoning and SMB Relay
ToolPupy

Pupy can sniff plaintext network credentials and use NBNS Spoofing to poison name services.

T1557.002
ARP Cache Poisoning
GroupCleaver

Cleaver has used custom tools to facilitate ARP cache poisoning.

T1557.002
ARP Cache Poisoning
GroupLuminousMoth

LuminousMoth has used ARP spoofing to redirect a compromised machine to an actor-controlled website.

T1557.004
Evil Twin
GroupAPT28

APT28 has used a Wi-Fi Pineapple to set up Evil Twin Wi-Fi Poisoning for the purposes of capturing victim credentials or planting espionage-oriented malware.

T1558
Steal or Forge Kerberos Tickets
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries used the Rubeus tool to forge a Diamond Ticket that is a modified legitimate Kerberos ticket.

T1558
Steal or Forge Kerberos Tickets
GroupAkira

Akira have used scripts to dump Kerberos authentication credentials.

T1558.001
Golden Ticket
GroupKe3chang

Ke3chang has used Mimikatz to generate Kerberos golden tickets.

T1558.001
Golden Ticket
ToolSliver

Sliver incorporates the Rubeus framework to allow for Kerberos ticket manipulation, specifically for forging Kerberos Golden Tickets.

T1558.001
Golden Ticket
ToolEmpire

Empire can leverage its implementation of Mimikatz to obtain and use golden tickets.

T1558.001
Golden Ticket
ToolMimikatz

Mimikatz's kerberos module can create golden tickets.

T1558.001
Golden Ticket
ToolRubeus

Rubeus can forge a ticket-granting ticket.

T1558.002
Silver Ticket
ToolAADInternals

AADInternals can be used to forge Kerberos tickets using the password hash of the AZUREADSSOACC account.

T1558.002
Silver Ticket
ToolEmpire

Empire can leverage its implementation of Mimikatz to obtain and use silver tickets.

T1558.002
Silver Ticket
ToolMimikatz

Mimikatz's kerberos module can create silver tickets.

T1558.002
Silver Ticket
ToolRubeus

Rubeus can create silver tickets.

T1558.003
Kerberoasting
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 obtained Ticket Granting Service (TGS) tickets for Active Directory Service Principle Names to crack offline.

T1558.003
Kerberoasting
CampaignOperation Wocao

During Operation Wocao, threat actors used PowerSploit's `Invoke-Kerberoast` module to request encrypted service tickets and bruteforce the passwords of Windows service accounts offline.

T1558.003
Kerberoasting
CampaignLeviathan Australian Intrusions

Leviathan used Kerberoasting techniques during Leviathan Australian Intrusions.

T1558.003
Kerberoasting
GroupIndrik Spider

Indrik Spider has conducted Kerberoasting attacks using a module from GitHub.

T1558.003
Kerberoasting
GroupFIN7

FIN7 has used Kerberoasting PowerShell commands such as, `Invoke-Kerberoast` for credential access and to enable lateral movement.

T1558.003
Kerberoasting
GroupWizard Spider

Wizard Spider has used Rubeus, MimiKatz Kerberos module, and the Invoke-Kerberoast cmdlet to steal AES hashes.

T1558.003
Kerberoasting
ToolSILENTTRINITY

SILENTTRINITY contains a module to conduct Kerberoasting.

T1558.003
Kerberoasting
ToolPowerSploit

PowerSploit's Invoke-Kerberoast module can request service tickets and return crackable ticket hashes.

T1558.003
Kerberoasting
ToolImpacket

Impacket modules like GetUserSPNs can be used to get Service Principal Names (SPNs) for user accounts. The output is formatted to be compatible with cracking tools like John the Ripper and Hashcat.

T1558.003
Kerberoasting
ToolEmpire

Empire uses PowerSploit's Invoke-Kerberoast to request service tickets and return crackable ticket hashes.

T1558.003
Kerberoasting
ToolBrute Ratel C4

Brute Ratel C4 can decode Kerberos 5 tickets and convert it to hashcat format for subsequent cracking.

T1558.003
Kerberoasting
ToolRubeus

Rubeus can use the `KerberosRequestorSecurityToken.GetRequest` method to request kerberoastable service tickets.

T1558.004
AS-REP Roasting
ToolRubeus

Rubeus can reveal the credentials of accounts that have Kerberos pre-authentication disabled through AS-REP roasting.

T1558.005
Ccache Files
ToolImpacket

Impacket tools – such as getST.py or ticketer.py – can be used to steal or forge Kerberos tickets using ccache files given a password, hash, aesKey, or TGT.

T1559
Inter-Process Communication
CampaignOperation MidnightEclipse

During Operation MidnightEclipse, threat actors wrote output to stdout then piped it to bash for execution.

T1559
Inter-Process Communication
Campaign3CX Supply Chain Attack

During the 3CX Supply Chain Attack, AppleJeus's VEILEDSIGNAL creates and listens on a Windows named pipe to exchange messages between modules.

T1559
Inter-Process Communication
MalwareNinja

Ninja can use pipes to redirect the standard input and the standard output.

T1559
Inter-Process Communication
MalwareRotaJakiro

When executing with non-root permissions, RotaJakiro uses the the `shmget API` to create shared memory between other known RotaJakiro processes. This allows processes to communicate with each other and share their PID.

T1559
Inter-Process Communication
MalwareHavoc

The Havoc SMB demon can use named pipes for communication through a parent demon.

T1559
Inter-Process Communication
MalwareTONESHELL

TONESHELL has facilitated inter-process communication between DLL components via the use of pipes. TONESHELL has also created a reverse shell using two anonymous pipes to write data to stdin and read data from stdout and stderr.

T1559
Inter-Process Communication
MalwareMedusa Ransomware

Medusa Ransomware has leveraged the `CreatePipe` API to enable inter-process communication.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.