Real-world descriptions of how a group, tool or campaign used a technique.
73 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.001 LSASS Memory |
ToolEmpire | Empire contains an implementation of Mimikatz to gather credentials from memory. |
| T1016 System Network Configuration Discovery |
ToolEmpire | Empire can acquire network configuration information like DNS servers, public IP, and network proxies used by a host. |
| T1020 Automated Exfiltration |
ToolEmpire | Empire has the ability to automatically send collected data back to the threat actors' C2. |
| T1021.003 Distributed Component Object Model |
ToolEmpire | Empire can utilize |
| T1021.004 SSH |
ToolEmpire | Empire contains modules for executing commands over SSH as well as in-memory VNC agent injection. |
| T1027.010 Command Obfuscation |
ToolEmpire | Empire has the ability to obfuscate commands using |
| T1033 System Owner/User Discovery |
ToolEmpire | Empire can enumerate the username on targeted hosts. |
| T1040 Network Sniffing |
ToolEmpire | Empire can be used to conduct packet captures on target hosts. |
| T1041 Exfiltration Over C2 Channel |
ToolEmpire | Empire can send data gathered from a target through the command and control channel. |
| T1046 Network Service Discovery |
ToolEmpire | Empire can perform port scans from an infected host. |
| T1047 Windows Management Instrumentation |
ToolEmpire | Empire can use WMI to deliver a payload to a remote host. |
| T1049 System Network Connections Discovery |
ToolEmpire | Empire can enumerate the current network connections of a host. |
| T1053.005 Scheduled Task |
ToolEmpire | Empire has modules to interact with the Windows task scheduler. |
| T1055 Process Injection |
ToolEmpire | Empire contains multiple modules for injecting into processes, such as |
| T1056.001 Keylogging |
ToolEmpire | Empire includes keylogging capabilities for Windows, Linux, and macOS systems. |
| T1056.004 Credential API Hooking |
ToolEmpire | Empire contains some modules that leverage API hooking to carry out tasks, such as netripper. |
| T1057 Process Discovery |
ToolEmpire | Empire can find information about processes running on local and remote systems. |
| T1059 Command and Scripting Interpreter |
ToolEmpire | Empire uses a command-line interface to interact with systems. |
| T1059.001 PowerShell |
ToolEmpire | Empire leverages PowerShell for the majority of its client-side agent tasks. Empire also contains the ability to conduct PowerShell remoting with the |
| T1059.003 Windows Command Shell |
ToolEmpire | Empire has modules for executing scripts. |
| T1068 Exploitation for Privilege Escalation |
ToolEmpire | Empire can exploit vulnerabilities such as MS16-032 and MS16-135. |
| T1070.006 Timestomp |
ToolEmpire | Empire can timestomp any files or payloads placed on a target machine to help them blend in. |
| T1071.001 Web Protocols |
ToolEmpire | Empire can conduct command and control over protocols like HTTP and HTTPS. |
| T1082 System Information Discovery |
ToolEmpire | Empire can enumerate host system information like OS, architecture, domain name, applied patches, and more. |
| T1083 File and Directory Discovery |
ToolEmpire | Empire includes various modules for finding files of interest on hosts and network shares. |
| T1087.001 Local Account |
ToolEmpire | Empire can acquire local and domain user account information. |
| T1087.002 Domain Account |
ToolEmpire | Empire can acquire local and domain user account information. |
| T1102.002 Bidirectional Communication |
ToolEmpire | Empire can use Dropbox and GitHub for C2. |
| T1105 Ingress Tool Transfer |
ToolEmpire | Empire can upload and download to and from a victim machine. |
| T1106 Native API |
ToolEmpire | Empire contains a variety of enumeration modules that have an option to use API calls to carry out tasks. |
| T1113 Screen Capture |
ToolEmpire | Empire is capable of capturing screenshots on Windows and macOS systems. |
| T1114.001 Local Email Collection |
ToolEmpire | Empire has the ability to collect emails on a target system. |
| T1115 Clipboard Data |
ToolEmpire | Empire can harvest clipboard data on both Windows and macOS systems. |
| T1119 Automated Collection |
ToolEmpire | Empire can automatically gather the username, domain name, machine name, and other information from a compromised system. |
| T1125 Video Capture |
ToolEmpire | Empire can capture webcam data on Windows and macOS systems. |
| T1127.001 MSBuild |
ToolEmpire | Empire can use built-in modules to abuse trusted utilities like MSBuild.exe. |
| T1134 Access Token Manipulation |
ToolEmpire | Empire can use PowerSploit's |
| T1134.002 Create Process with Token |
ToolEmpire | Empire can use |
| T1134.005 SID-History Injection |
ToolEmpire | Empire can add a SID-History to a user if on a domain controller. |
| T1135 Network Share Discovery |
ToolEmpire | Empire can find shared drives on the local system. |
| T1136.001 Local Account |
ToolEmpire | Empire has a module for creating a local user if permissions allow. |
| T1136.002 Domain Account |
ToolEmpire | Empire has a module for creating a new domain user if permissions allow. |
| T1210 Exploitation of Remote Services |
ToolEmpire | Empire has a limited number of built-in modules for exploiting remote SMB, JBoss, and Jenkins servers. |
| T1217 Browser Information Discovery |
ToolEmpire | Empire has the ability to gather browser data such as bookmarks and visited sites. |
| T1482 Domain Trust Discovery |
ToolEmpire | Empire has modules for enumerating domain trusts. |
| T1484.001 Group Policy Modification |
ToolEmpire | Empire can use |
| T1518.001 Security Software Discovery |
ToolEmpire | Empire can enumerate antivirus software on the target. |
| T1543.003 Windows Service |
ToolEmpire | Empire can utilize built-in modules to modify service binaries and restore them to their original state. |
| T1546.008 Accessibility Features |
ToolEmpire | Empire can leverage WMI debugging to remotely replace binaries like sethc.exe, Utilman.exe, and Magnify.exe with cmd.exe. |
| T1547.001 Registry Run Keys / Startup Folder |
ToolEmpire | Empire can modify the registry run keys |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.