ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1210×

12 examples

TechniqueUsed byProcedure example
T1210
Exploitation of Remote Services
GroupDragonfly

Dragonfly has exploited a Windows Netlogon vulnerability (CVE-2020-1472) to obtain access to Windows Active Directory servers.

T1210
Exploitation of Remote Services
GroupmenuPass

menuPass has used tools to exploit the ZeroLogon vulnerability (CVE-2020-1472).

T1210
Exploitation of Remote Services
GroupMuddyWater

MuddyWater has exploited the Microsoft Netlogon vulnerability (CVE-2020-1472).

T1210
Exploitation of Remote Services
GroupFIN7

FIN7 has exploited ZeroLogon (CVE-2020-1472) against vulnerable domain controllers.

T1210
Exploitation of Remote Services
GroupEmber Bear

Ember Bear has used exploits for vulnerabilities such as MS17-010, also known as `Eternal Blue`, during operations.

T1210
Exploitation of Remote Services
GroupAPT28

APT28 exploited a Windows SMB Remote Code Execution Vulnerability to conduct lateral movement.

T1210
Exploitation of Remote Services
GroupFox Kitten

Fox Kitten has exploited known vulnerabilities in remote services including RDP.

T1210
Exploitation of Remote Services
GroupTonto Team

Tonto Team has used EternalBlue exploits for lateral movement.

T1210
Exploitation of Remote Services
GroupEarth Lusca

Earth Lusca has used Mimikatz to exploit a domain controller via the ZeroLogon exploit (CVE-2020-1472).

T1210
Exploitation of Remote Services
GroupWizard Spider

Wizard Spider has exploited or attempted to exploit Zerologon (CVE-2020-1472) and EternalBlue (MS17-010) vulnerabilities.

T1210
Exploitation of Remote Services
GroupThreat Group-3390

Threat Group-3390 has exploited MS17-010 to move laterally to other systems on the network.

T1210
Exploitation of Remote Services
GroupShinyHunters

ShinyHunters has exploited vulnerabilities in remote services for lateral movement.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.