ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Defending against cyber-attacks using the MITRE ATT&CK framework (Part 2)

In the second of three articles, Adrian Bishop at Huntsman Security explains how an attacker might explore a compromised network, and how they can discover and compromise other systems and accounts

 

In my last article, we analysed the first three stages of an assault, showing how an attacker could compromise a system and establish a persistent presence.

 

In this piece, let’s pick up from stage four and discuss how an attacker might explore a compromised network, and how they can discover and compromise other systems and accounts. This is the precursor to a data breach, and a critical moment for both the attacker and the organisation being targeted. A lot can be lost and gained depending on what you can spot in this moment! 

Stage 4: Privilege escalation

So far in our scenario, the target user has downloaded malicious content from a website that exploited an operating system vulnerability to run code with privileges the user does not normally have. This allows the code to perform actions with operating system or administrator permissions, such as creating scheduled tasks, installing software, or changing system configurations. 

 

How did they achieve this? The Techniques within the Privilege Escalation Tactic contain methods that enable commands or software to be executed with higher privileges than the user holds, including:

  • Exploiting weaknesses in application privilege controls or software.
  • Running commands and software with the privileges of other applications.
  • Getting the operating system to run software during boot, user logon, or as a system process.
  • Configuring system policies to run malicious software or escalate user privileges.

 Our attack scenario uses a single Technique to gain higher privileges:

Stage 5: Defence evasion

The Privilege Escalation exploit allows the malicious script to use Microsoft’s Background Intelligent Transfer Service (BITS) administration features to create BITS Jobs to download and launch additional software.

 

For an attacker to succeed in infiltrating a network they must remain undetected. Any actions they perform must be either undetectable or appear to be normal activity for the host they are performed on.

 

Some Defence Evasion Techniques our attacker might employ include:

  • User or system impersonation
  • Leveraging normal operating system features or activity
  • Endpoint protection evasion or disablement
  • Hiding or obfuscating data in registries and files
  • Direct data access
  • Vulnerability exploits
  • Permission modification
  • Deleting or stopping event logging

In our scenario, to avoid detection the attacker uses: 

Stage 6: Credential access

Included within this downloaded software is an automated tool suite which can further compromise the system. The suite of tools is executed with elevated privileges and used to search for valid user accounts that may provide additional access to systems. The tools include ways to search for cached Windows credentials on the local host, as well as credentials in files and browser caches. In addition, it installs a keylogger, to capture credentials used by the user for remote system access.

 

Once an attacker can upload and execute software on a host, they begin to search for information that will help them infiltrate further into the system or network. The most valuable data they will seek is valid account credentials. These credentials make their actions easier to perform and harder to detect, especially if they manage to find details for a user with higher privileged access to some or all systems. This activity is within the Credential Access Tactic and includes:

  • Dumping credentials from memory
  • Searching for credentials in files, registries, and credential stores
  • Password cracking
  • Capturing user credentials
  • Stealing valid authentication tokens

At this stage, our attacker uses the following Techniques:

Stage 7: Discovery

After exploring the compromised system for credentials, the attacker uses built-in and custom utilities to gather information about the host network, the Windows domain it belongs to, and sensitive groups and users within the domain.

 

Once an attacker has gathered credential data from the local system, they then discover other useful information about the system, the attached network, and remote systems. After searching the compromised host for useful information, data and credentials, an attacker will map out the surrounding network. This may be done over a period of time to avoid detection and ensure they discover as much information as possible.

 

The primary objective of this stage is to determine the next targets for attack and the methods to use. 

 

The Discovery Tactic includes Techniques for discovering information, including:

  • Domain accounts, groups, servers, and permissions
  • System and network configuration and connections
  • Application data, files, directories, and network shares
  • Domain policies for computer management, passwords, and trusts
  • Running applications, services, processes , and installed software

Within the discovery stage of our attack scenario the attacker used a combination of Techniques:

Stage 8: Lateral movement

After discovering other targets of interest, the attacker uses the retrieved account credentials to remotely execute commands on the discovered hosts. They also copy any required software and tools to network file shares from where it can be downloaded to systems they are targeting.

 

From the discovery stage the attacker can build a list of target systems and applications they want to compromise next. Depending upon the account credentials the attacker has harvested in the previous stage this may be a trivial task, and their ability to move around the network may be quick. Alternatively, they may have to wait for additional information or user credentials to be discovered before this can occur.

 

The Lateral Movement Tactic includes Techniques covering:

  • The exploitation of remote services
  • Internal spearphishing
  • Tool transfer
  • Remote services and remote service session hijacking
  • The use of removable media 

For this attack stage the movement of software and control to different systems utilises:

Kicking attackers out before it’s too late

The good news is that there are steps organisations can take to help mitigate the techniques described above. MITRE ATT&CK specifically identifies several mitigation strategies. These include:

  • Application isolation, sandboxing and OS exploit mitigation tools
  • Install software and operating system updates
  • Application and command execution prevention/control
  • Limit caching of credentials on endpoints
  • Hardening OS configuration through GPO policies
  • Host firewalling to restrict communications between approved systems 
  • Disabling WinRM service
  • Restricted file permissions on sensitive files/browser credential files
  • User training

There are also monitoring and detection activities that SOC teams can perform that point towards a potential attack:

  • Monitoring command execution for BITS and WinRM administration, known malicious utilities, unusual command and script usage/activity
  • Monitor for the creation of BITS Jobs
  • Detecting unknown drivers being loaded or registry changes for input drivers
  • Detecting file creation in unusual locations
  • Detecting abnormal communications between endpoints
  • Detecting logons using WinRM by valid accounts

Following the steps outlined above should mean you are able to thwart the attack before it reaches the data breach stage. For those that can’t achieve this, the next article will highlight what happens when attackers gather and exfiltrate sensitive data, whilst preventing the recovery of it, so be sure to check-back for the final part in a couple of weeks!

 


 

Adrian Bishop is Head of Engineering at Huntsman Security

 

Main image courtesy of iStockPhoto.com


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543