ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

4628 examples

TechniqueUsed byProcedure example
T1547.001
Registry Run Keys / Startup Folder
GroupTeamPCP

TeamPCP has dropped malware into the Windows Startup folder to establish persistence.

T1547.004
Winlogon Helper DLL
GroupTropic Trooper

Tropic Trooper has created the Registry key HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell and sets the value to establish persistence.

T1547.004
Winlogon Helper DLL
GroupTurla

Turla established persistence by adding a Shell value under the Registry key HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon.

T1547.004
Winlogon Helper DLL
GroupWizard Spider

Wizard Spider has established persistence using Userinit by adding the Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon.

T1547.009
Shortcut Modification
GroupGorgon Group

Gorgon Group malware can create a .lnk file and add a Registry Run key to establish persistence.

T1547.009
Shortcut Modification
GroupAPT39

APT39 has modified LNK shortcuts.

T1547.009
Shortcut Modification
GroupLeviathan

Leviathan has used JavaScript to create a shortcut file in the Startup folder that points to its main backdoor.

T1547.009
Shortcut Modification
GroupLazarus Group

Lazarus Group malware has maintained persistence on a system by creating a LNK shortcut in the user’s Startup folder.

T1547.012
Print Processors
GroupEarth Lusca

Earth Lusca has added the Registry key `HKLM\SYSTEM\ControlSet001\Control\Print\Environments\Windows x64\Print Processors\UDPrint” /v Driver /d “spool.dll /f` to load malware as a Print Processor.

T1547.013
XDG Autostart Entries
GroupContagious Interview

Contagious Interview has established persistence using InvisibleFerret malware to create a .desktop entry to run on startup on GNOME-based Linux devices.

T1548
Abuse Elevation Control Mechanism
GroupUNC3886

UNC3886 has used vSphere Installation Bundles (VIBs) that contained modified descriptor XML files with the `acceptance-level` set to `partner` which allowed for privilege escalation.

T1548.002
Bypass User Account Control
GroupAPT38

APT38 has used the legitimate application `ieinstal.exe` to bypass UAC.

T1548.002
Bypass User Account Control
GroupPatchwork

Patchwork bypassed User Access Control (UAC).

T1548.002
Bypass User Account Control
GroupEvilnum

Evilnum has used PowerShell to bypass UAC.

T1548.002
Bypass User Account Control
GroupMuddyWater

MuddyWater uses various techniques to bypass UAC.

T1548.002
Bypass User Account Control
GroupAPT37

APT37 has a function in the initial dropper to bypass Windows UAC in order to execute the next payload with higher privileges.

T1548.002
Bypass User Account Control
GroupAPT29

APT29 has bypassed UAC.

T1548.002
Bypass User Account Control
GroupMedusa Group

Medusa Group has attempted to bypass UAC using Component Object Model (COM) interface.

T1548.002
Bypass User Account Control
GroupBRONZE BUTLER

BRONZE BUTLER has used a Windows 10 specific tool and xxmm to bypass UAC for privilege escalation.

T1548.002
Bypass User Account Control
GroupEarth Lusca

Earth Lusca has used the Fodhelper UAC bypass technique to gain elevated privileges.

T1548.002
Bypass User Account Control
GroupCobalt Group

Cobalt Group has bypassed UAC.

T1548.002
Bypass User Account Control
GroupThreat Group-3390

A Threat Group-3390 tool can use a public UAC bypass method to elevate privileges.

T1550.001
Application Access Token
GroupHAFNIUM

HAFNIUM has abused service principals with administrative permissions for data exfiltration.

T1550.001
Application Access Token
GroupAPT28

APT28 has used several malicious applications that abused OAuth access tokens to gain access to target email accounts, including Gmail and Yahoo Mail.

T1550.001
Application Access Token
GroupTeamPCP

TeamPCP has used stolen access tokens to inject malicious code into CI/CD workflows and to exfiltrate sensitive data from cloud, developer, and container environments.

T1550.001
Application Access Token
GroupShinyHunters

ShinyHunters has used stolen OAuth keys to access cloud infrastructure and to bypass two-factor authentication.

T1550.002
Pass the Hash
GroupGALLIUM

GALLIUM used dumped hashes to authenticate to other machines via pass the hash.

T1550.002
Pass the Hash
GroupKimsuky

Kimsuky has used pass the hash for authentication to remote access software used in C2.

T1550.002
Pass the Hash
GroupAPT41

APT41 uses tools such as Mimikatz to enable lateral movement via captured password hashes.

T1550.002
Pass the Hash
GroupAPT32

APT32 has used pass the hash for lateral movement.

T1550.002
Pass the Hash
GroupAquatic Panda

Aquatic Panda used a registry edit to enable a Windows feature called RestrictedAdmin in victim environments. This change allowed Aquatic Panda to leverage "pass the hash" mechanisms as the alteration allows for RDP connections with a valid account name and hash only, without possessing a cleartext password value.

T1550.002
Pass the Hash
GroupAPT1

The APT1 group is known to have used pass the hash.

T1550.002
Pass the Hash
GroupChimera

Chimera has dumped password hashes for use in pass the hash authentication attacks.

T1550.002
Pass the Hash
GroupEmber Bear

Ember Bear has used pass-the-hash techniques for lateral movement in victim environments.

T1550.002
Pass the Hash
GroupAPT28

APT28 has used pass the hash for lateral movement.

T1550.002
Pass the Hash
GroupWizard Spider

Wizard Spider has used the `Invoke-SMBExec` PowerShell cmdlet to execute the pass-the-hash technique and utilized stolen password hashes to move laterally.

T1550.002
Pass the Hash
GroupFIN13

FIN13 has used the PowerShell utility `Invoke-SMBExec` to execute the pass the hash method for lateral movement within an compromised environment.

T1550.003
Pass the Ticket
GroupAPT32

APT32 successfully gained remote access by using pass the ticket.

T1550.003
Pass the Ticket
GroupAPT29

APT29 used Kerberos ticket attacks for lateral movement.

T1550.003
Pass the Ticket
GroupBRONZE BUTLER

BRONZE BUTLER has created forged Kerberos Ticket Granting Ticket (TGT) and Ticket Granting Service (TGS) tickets to maintain administrative access.

T1550.004
Web Session Cookie
GroupStar Blizzard

Star Blizzard has bypassed multi-factor authentication on victim email accounts by using session cookies stolen using EvilGinx.

T1552
Unsecured Credentials
GroupVolt Typhoon

Volt Typhoon has obtained credentials insecurely stored on targeted network appliances.

T1552.001
Credentials In Files
GroupIndrik Spider

Indrik Spider has searched files to obtain and exfiltrate credentials.

T1552.001
Credentials In Files
GroupAPT3

APT3 has a tool that can locate credentials in files on the file system such as those from Firefox or Chrome.

T1552.001
Credentials In Files
GroupKimsuky

Kimsuky has used tools that are capable of obtaining credentials from saved mail.

T1552.001
Credentials In Files
GroupMuddyWater

MuddyWater has run a tool that steals passwords saved in victim email.

T1552.001
Credentials In Files
GroupLeafminer

Leafminer used several tools for retrieving login and password information, including LaZagne.

T1552.001
Credentials In Files
GroupTeamTNT

TeamTNT has searched for unsecured AWS credentials and Docker API credentials.

T1552.001
Credentials In Files
GroupScattered Spider

Scattered Spider Spider searches for credential storage documentation on a compromised host.

T1552.001
Credentials In Files
GroupOilRig

OilRig has used credential dumping tools such as LaZagne to steal credentials to accounts logged into the compromised system and to Outlook Web Access.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.