Real-world descriptions of how a group, tool or campaign used a technique.
4628 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1547.001 Registry Run Keys / Startup Folder |
GroupTeamPCP | TeamPCP has dropped malware into the Windows Startup folder to establish persistence. |
| T1547.004 Winlogon Helper DLL |
GroupTropic Trooper | Tropic Trooper has created the Registry key |
| T1547.004 Winlogon Helper DLL |
GroupTurla | Turla established persistence by adding a Shell value under the Registry key |
| T1547.004 Winlogon Helper DLL |
GroupWizard Spider | Wizard Spider has established persistence using Userinit by adding the Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon. |
| T1547.009 Shortcut Modification |
GroupGorgon Group | Gorgon Group malware can create a .lnk file and add a Registry Run key to establish persistence. |
| T1547.009 Shortcut Modification |
GroupAPT39 | APT39 has modified LNK shortcuts. |
| T1547.009 Shortcut Modification |
GroupLeviathan | Leviathan has used JavaScript to create a shortcut file in the Startup folder that points to its main backdoor. |
| T1547.009 Shortcut Modification |
GroupLazarus Group | Lazarus Group malware has maintained persistence on a system by creating a LNK shortcut in the user’s Startup folder. |
| T1547.012 Print Processors |
GroupEarth Lusca | Earth Lusca has added the Registry key `HKLM\SYSTEM\ControlSet001\Control\Print\Environments\Windows x64\Print Processors\UDPrint” /v Driver /d “spool.dll /f` to load malware as a Print Processor. |
| T1547.013 XDG Autostart Entries |
GroupContagious Interview | Contagious Interview has established persistence using InvisibleFerret malware to create a .desktop entry to run on startup on GNOME-based Linux devices. |
| T1548 Abuse Elevation Control Mechanism |
GroupUNC3886 | UNC3886 has used vSphere Installation Bundles (VIBs) that contained modified descriptor XML files with the `acceptance-level` set to `partner` which allowed for privilege escalation. |
| T1548.002 Bypass User Account Control |
GroupAPT38 | APT38 has used the legitimate application `ieinstal.exe` to bypass UAC. |
| T1548.002 Bypass User Account Control |
GroupPatchwork | Patchwork bypassed User Access Control (UAC). |
| T1548.002 Bypass User Account Control |
GroupEvilnum | Evilnum has used PowerShell to bypass UAC. |
| T1548.002 Bypass User Account Control |
GroupMuddyWater | MuddyWater uses various techniques to bypass UAC. |
| T1548.002 Bypass User Account Control |
GroupAPT37 | APT37 has a function in the initial dropper to bypass Windows UAC in order to execute the next payload with higher privileges. |
| T1548.002 Bypass User Account Control |
GroupAPT29 | APT29 has bypassed UAC. |
| T1548.002 Bypass User Account Control |
GroupMedusa Group | Medusa Group has attempted to bypass UAC using Component Object Model (COM) interface. |
| T1548.002 Bypass User Account Control |
GroupBRONZE BUTLER | BRONZE BUTLER has used a Windows 10 specific tool and xxmm to bypass UAC for privilege escalation. |
| T1548.002 Bypass User Account Control |
GroupEarth Lusca | Earth Lusca has used the Fodhelper UAC bypass technique to gain elevated privileges. |
| T1548.002 Bypass User Account Control |
GroupCobalt Group | Cobalt Group has bypassed UAC. |
| T1548.002 Bypass User Account Control |
GroupThreat Group-3390 | A Threat Group-3390 tool can use a public UAC bypass method to elevate privileges. |
| T1550.001 Application Access Token |
GroupHAFNIUM | HAFNIUM has abused service principals with administrative permissions for data exfiltration. |
| T1550.001 Application Access Token |
GroupAPT28 | APT28 has used several malicious applications that abused OAuth access tokens to gain access to target email accounts, including Gmail and Yahoo Mail. |
| T1550.001 Application Access Token |
GroupTeamPCP | TeamPCP has used stolen access tokens to inject malicious code into CI/CD workflows and to exfiltrate sensitive data from cloud, developer, and container environments. |
| T1550.001 Application Access Token |
GroupShinyHunters | ShinyHunters has used stolen OAuth keys to access cloud infrastructure and to bypass two-factor authentication. |
| T1550.002 Pass the Hash |
GroupGALLIUM | GALLIUM used dumped hashes to authenticate to other machines via pass the hash. |
| T1550.002 Pass the Hash |
GroupKimsuky | Kimsuky has used pass the hash for authentication to remote access software used in C2. |
| T1550.002 Pass the Hash |
GroupAPT41 | APT41 uses tools such as Mimikatz to enable lateral movement via captured password hashes. |
| T1550.002 Pass the Hash |
GroupAPT32 | APT32 has used pass the hash for lateral movement. |
| T1550.002 Pass the Hash |
GroupAquatic Panda | Aquatic Panda used a registry edit to enable a Windows feature called |
| T1550.002 Pass the Hash |
GroupAPT1 | The APT1 group is known to have used pass the hash. |
| T1550.002 Pass the Hash |
GroupChimera | Chimera has dumped password hashes for use in pass the hash authentication attacks. |
| T1550.002 Pass the Hash |
GroupEmber Bear | Ember Bear has used pass-the-hash techniques for lateral movement in victim environments. |
| T1550.002 Pass the Hash |
GroupAPT28 | APT28 has used pass the hash for lateral movement. |
| T1550.002 Pass the Hash |
GroupWizard Spider | Wizard Spider has used the `Invoke-SMBExec` PowerShell cmdlet to execute the pass-the-hash technique and utilized stolen password hashes to move laterally. |
| T1550.002 Pass the Hash |
GroupFIN13 | FIN13 has used the PowerShell utility `Invoke-SMBExec` to execute the pass the hash method for lateral movement within an compromised environment. |
| T1550.003 Pass the Ticket |
GroupAPT32 | APT32 successfully gained remote access by using pass the ticket. |
| T1550.003 Pass the Ticket |
GroupAPT29 | APT29 used Kerberos ticket attacks for lateral movement. |
| T1550.003 Pass the Ticket |
GroupBRONZE BUTLER | BRONZE BUTLER has created forged Kerberos Ticket Granting Ticket (TGT) and Ticket Granting Service (TGS) tickets to maintain administrative access. |
| T1550.004 Web Session Cookie |
GroupStar Blizzard | Star Blizzard has bypassed multi-factor authentication on victim email accounts by using session cookies stolen using EvilGinx. |
| T1552 Unsecured Credentials |
GroupVolt Typhoon | Volt Typhoon has obtained credentials insecurely stored on targeted network appliances. |
| T1552.001 Credentials In Files |
GroupIndrik Spider | Indrik Spider has searched files to obtain and exfiltrate credentials. |
| T1552.001 Credentials In Files |
GroupAPT3 | APT3 has a tool that can locate credentials in files on the file system such as those from Firefox or Chrome. |
| T1552.001 Credentials In Files |
GroupKimsuky | Kimsuky has used tools that are capable of obtaining credentials from saved mail. |
| T1552.001 Credentials In Files |
GroupMuddyWater | MuddyWater has run a tool that steals passwords saved in victim email. |
| T1552.001 Credentials In Files |
GroupLeafminer | Leafminer used several tools for retrieving login and password information, including LaZagne. |
| T1552.001 Credentials In Files |
GroupTeamTNT | TeamTNT has searched for unsecured AWS credentials and Docker API credentials. |
| T1552.001 Credentials In Files |
GroupScattered Spider | Scattered Spider Spider searches for credential storage documentation on a compromised host. |
| T1552.001 Credentials In Files |
GroupOilRig | OilRig has used credential dumping tools such as LaZagne to steal credentials to accounts logged into the compromised system and to Outlook Web Access. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.