Real-world descriptions of how a group, tool or campaign used a technique.
4628 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1555.005 Password Managers |
GroupStorm-0501 | Storm-0501 has stolen credentials contained in the password manager Keepass by utilizing Find-KeePassConfig.ps1. |
| T1555.005 Password Managers |
GroupFox Kitten | Fox Kitten has used scripts to access credential information from the KeePass database. |
| T1555.005 Password Managers |
GroupLAPSUS$ | LAPSUS$ has accessed local password managers and databases to obtain further credentials from a compromised network. |
| T1555.005 Password Managers |
GroupThreat Group-3390 | Threat Group-3390 obtained a KeePass database from a compromised host. |
| T1555.006 Cloud Secrets Management Stores |
GroupHAFNIUM | HAFNIUM has moved laterally from on-premises environments to steal passwords from Azure key vaults. |
| T1555.006 Cloud Secrets Management Stores |
GroupStorm-0501 | Storm-0501 has utilized Azure Key Vault to store the encryption key using the operation `Microsoft.KeyVault/Vaults/write`. |
| T1555.006 Cloud Secrets Management Stores |
GroupTeamPCP | TeamPCP has used malware to exfiltrate cloud secrets from targeted environments including AWS, GCP, and Azure. |
| T1556 Modify Authentication Process |
GroupFIN13 | FIN13 has replaced legitimate KeePass binaries with trojanized versions to collect passwords from numerous applications. |
| T1556.001 Domain Controller Authentication |
GroupChimera | Chimera's malware has altered the NTLM authentication program on domain controllers to allow Chimera to login without a valid credential. |
| T1556.002 Password Filter DLL |
GroupStrider | Strider has registered its persistence module on domain controllers as a Windows LSA (Local System Authority) password filter to acquire credentials any time a domain, local user, or administrator logs in or changes a password. |
| T1556.002 Password Filter DLL |
GroupOilRig | OilRig has registered a password filter DLL in order to drop malware. |
| T1556.002 Password Filter DLL |
GroupMirrorFace | MirrorFace has used a tool named MRSAStealer as a password filter to collect credentials on password changes. |
| T1556.006 Multi-Factor Authentication |
GroupScattered Spider | After compromising user accounts, Scattered Spider registers their own MFA tokens. |
| T1556.007 Hybrid Identity |
GroupAPT29 | APT29 has edited the `Microsoft.IdentityServer.Servicehost.exe.config` file to load a malicious DLL into the AD FS process, thereby enabling persistent access to any service federated with AD FS for a user with a specified User Principal Name. |
| T1556.009 Conditional Access Policies |
GroupScattered Spider | Scattered Spider has added additional trusted locations to Azure AD conditional access policies. |
| T1556.009 Conditional Access Policies |
GroupStorm-0501 | Storm-0501 has registered their own MFA method, and leveraged a victim hybrid joined server to circumvent Conditional Access Policies. |
| T1557 Adversary-in-the-Middle |
GroupKimsuky | Kimsuky has used modified versions of PHProxy to examine web traffic between the victim and the accessed website. |
| T1557 Adversary-in-the-Middle |
GroupMustang Panda | Mustang Panda leveraged a captive portal hijack that redirected the victim to a webpage that prompted the victim to download a malicious payload. |
| T1557 Adversary-in-the-Middle |
GroupSea Turtle | Sea Turtle modified DNS records at service providers to redirect traffic from legitimate resources to Sea Turtle-controlled servers to enable adversary-in-the-middle attacks for credential capture. |
| T1557.001 Name Resolution Poisoning and SMB Relay |
GroupLazarus Group | Lazarus Group executed Responder using the command |
| T1557.001 Name Resolution Poisoning and SMB Relay |
GroupWizard Spider | Wizard Spider has used the Invoke-Inveigh PowerShell cmdlets, likely for name service poisoning. |
| T1557.002 ARP Cache Poisoning |
GroupCleaver | Cleaver has used custom tools to facilitate ARP cache poisoning. |
| T1557.002 ARP Cache Poisoning |
GroupLuminousMoth | LuminousMoth has used ARP spoofing to redirect a compromised machine to an actor-controlled website. |
| T1557.004 Evil Twin |
GroupAPT28 | APT28 has used a Wi-Fi Pineapple to set up Evil Twin Wi-Fi Poisoning for the purposes of capturing victim credentials or planting espionage-oriented malware. |
| T1558 Steal or Forge Kerberos Tickets |
GroupAkira | Akira have used scripts to dump Kerberos authentication credentials. |
| T1558.001 Golden Ticket |
GroupKe3chang | Ke3chang has used Mimikatz to generate Kerberos golden tickets. |
| T1558.003 Kerberoasting |
GroupIndrik Spider | Indrik Spider has conducted Kerberoasting attacks using a module from GitHub. |
| T1558.003 Kerberoasting |
GroupFIN7 | FIN7 has used Kerberoasting PowerShell commands such as, `Invoke-Kerberoast` for credential access and to enable lateral movement. |
| T1558.003 Kerberoasting |
GroupWizard Spider | Wizard Spider has used Rubeus, MimiKatz Kerberos module, and the Invoke-Kerberoast cmdlet to steal AES hashes. |
| T1559.001 Component Object Model |
GroupKimsuky | Kimsuky has leveraged Component Object Model (COM) to create scheduled tasks to include using naming conventions that mimic legitimate applications. Kimsuky has leveraged obfuscation VBScript to form a string in `WScript.Shell` which has downloaded a malicious payload to the victim environment. |
| T1559.001 Component Object Model |
GroupMuddyWater | MuddyWater has used malware that has the capability to execute malicious code via COM, DCOM, and Outlook. |
| T1559.001 Component Object Model |
GroupGamaredon Group | Gamaredon Group malware can insert malicious macros into documents using a |
| T1559.001 Component Object Model |
GroupMedusa Group | Medusa Group has leveraged Component Object Model (COM) to bypass UAC. |
| T1559.002 Dynamic Data Exchange |
GroupPatchwork | Patchwork leveraged the DDE protocol to deliver their malware. |
| T1559.002 Dynamic Data Exchange |
GroupMuddyWater | MuddyWater has used malware that can execute PowerShell scripts via DDE. |
| T1559.002 Dynamic Data Exchange |
GroupGallmaker | Gallmaker attempted to exploit Microsoft’s DDE protocol in order to gain access to victim machines and for execution. |
| T1559.002 Dynamic Data Exchange |
GroupFIN7 | FIN7 spear phishing campaigns have included malicious Word documents with DDE execution. |
| T1559.002 Dynamic Data Exchange |
GroupSidewinder | Sidewinder has used the ActiveXObject utility to create OLE objects to obtain execution through Internet Explorer. |
| T1559.002 Dynamic Data Exchange |
GroupAPT37 | APT37 has used Windows DDE for execution of commands and a malicious VBS. |
| T1559.002 Dynamic Data Exchange |
GroupLeviathan | Leviathan has utilized OLE as a method to insert malicious content inside various phishing documents. |
| T1559.002 Dynamic Data Exchange |
GroupTA505 | TA505 has leveraged malicious Word documents that abused DDE. |
| T1559.002 Dynamic Data Exchange |
GroupBITTER | BITTER has executed OLE objects using Microsoft Equation Editor to download and run malicious payloads. |
| T1559.002 Dynamic Data Exchange |
GroupAPT28 | APT28 has delivered JHUHUGIT and Koadic by executing PowerShell commands through DDE in Word documents. |
| T1559.002 Dynamic Data Exchange |
GroupCobalt Group | Cobalt Group has sent malicious Word OLE compound documents to victims. |
| T1560 Archive Collected Data |
GroupBlackByte | BlackByte compressed data collected from victim environments prior to exfiltration. |
| T1560 Archive Collected Data |
GroupPatchwork | Patchwork encrypted the collected files' path with AES and then encoded them with base64. |
| T1560 Archive Collected Data |
GroupDragonfly | Dragonfly has compressed data into .zip files prior to exfiltration. |
| T1560 Archive Collected Data |
GroupmenuPass | menuPass has encrypted files and information before exfiltration. |
| T1560 Archive Collected Data |
GroupAPT32 | APT32's backdoor has used LZMA compression and RC4 encryption before exfiltration. |
| T1560 Archive Collected Data |
GroupFIN6 | Following data collection, FIN6 has compressed log files into a ZIP archive prior to staging and exfiltration. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.