Obtain Capabilities: Tool

Adversaries may buy, steal, or download software tools that can be used during targeting. Tools can be open or closed source, free or commercial. A tool can be used for malicious purposes by an adversary, but (unlike malware) were not intended to be used for those purposes (ex: PsExec). Tool acquisition can involve the procurement of commercial software licenses, including for red teaming tools such as Cobalt Strike. Commercial software may be obtained through purchase, stealing licenses (or licensed copies of the software), or cracking trial versions.[1]

Adversaries may obtain tools to support their operations, including to support execution of post-compromise behaviors. In addition to freely downloading or purchasing software, adversaries may steal software and/or software licenses from third-party entities (including other adversaries).

ID: T1588.002
Sub-technique of:  T1588
Platforms: PRE
Contributors: Mnemonic AS; SOCCRATES
Version: 1.1
Created: 01 October 2020
Last Modified: 17 October 2021

Procedure Examples

ID Name Description
G0099 APT-C-36

APT-C-36 obtained and used a modified variant of Imminent Monitor.[2]

G0006 APT1

APT1 has used various open-source tools for privilege escalation purposes.[3]

G0073 APT19

APT19 has obtained and used publicly-available tools like Empire.[4][5]

G0007 APT28

APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.[6][7][8]

G0016 APT29

APT29 has obtained and used a variety of tools including Mimikatz, SDelete, Tor, meek, and Cobalt Strike.[9][10][11]

G0050 APT32

APT32 has obtained and used tools such as Mimikatz and Cobalt Strike, and a variety of other open-source tools from GitHub.[12][13]

G0064 APT33

APT33 has obtained and leveraged publicly-available tools for early intrusion activities.[14][15]

G0082 APT38

APT38 has obtained and used open-source tools such as Mimikatz.[16]

G0087 APT39

APT39 has modified and used customized versions of publicly-available tools like PLINK and Mimikatz.[17][18]

G0096 APT41

APT41 has obtained and used tools such as Mimikatz, pwdump, PowerSploit, and Windows Credential Editor.[19]

G0143 Aquatic Panda

Aquatic Panda has acquired and used Cobalt Strike in its operations.[20]

G0135 BackdoorDiplomacy

BackdoorDiplomacy has obtained a variety of open-source reconnaissance and red team tools for discovery and lateral movement.[21]

G0098 BlackTech

BlackTech has obtained and used tools such as Putty, SNScan, and PsExec for its operations.[22]

G0108 Blue Mockingbird

Blue Mockingbird has obtained and used tools such as Mimikatz.[23]


BRONZE BUTLER has obtained and used open-source tools such as Mimikatz, gsecdump, and Windows Credential Editor.[24]

G0008 Carbanak

Carbanak has obtained and used open-source tools such as PsExec and Mimikatz.[25]

G0114 Chimera

Chimera has obtained and used tools such as BloodHound, Cobalt Strike, Mimikatz, and PsExec.[26][27]

G0003 Cleaver

Cleaver has obtained and used open-source tools such as PsExec, Windows Credential Editor, and Mimikatz.[28]

G0080 Cobalt Group

Cobalt Group has obtained and used a variety of tools including Mimikatz, PsExec, Cobalt Strike, and SDelete.[29]

G0052 CopyKittens

CopyKittens has used Metasploit and Empire for post-exploitation activities.[30]

G0132 CostaRicto

CostaRicto has obtained open source tools to use in their operations.[31]

G0079 DarkHydrus

DarkHydrus has obtained and used tools such as Mimikatz, Empire, and Cobalt Strike.[32]

G0105 DarkVishnya

DarkVishnya has obtained and used tools such as Impacket, Winexe, and PsExec.[33]

G0035 Dragonfly

Dragonfly has obtained and used tools such as Mimikatz, CrackMapExec, and PsExec.[34]

G0137 Ferocious Kitten

Ferocious Kitten has obtained open source tools for its operations, including JsonCPP and Psiphon.[35]

G0051 FIN10

FIN10 has relied on publicly-available software to gain footholds and establish persistence in victim environments.[36]

G0053 FIN5

FIN5 has obtained and used a customized version of PsExec, as well as use other tools such as pwdump, SDelete, and Windows Credential Editor.[37]

G0037 FIN6

FIN6 has obtained and used tools such as Mimikatz, Cobalt Strike, and AdFind.[38][39]

G0101 Frankenstein

Frankenstein has obtained and used Empire to deploy agents.[40]


GALLIUM has used a variety of widely-available tools, which in some cases they modified to add functionality and/or subvert antimalware solutions.[41]

G0078 Gorgon Group

Gorgon Group has obtained and used tools such as QuasarRAT and Remcos.[42]

G0100 Inception

Inception has obtained and used open-source tools such as LaZagne.[43]

G0136 IndigoZebra

IndigoZebra has acquired open source tools such as NBTscan and Meterpreter for their operations.[44][45]

G0004 Ke3chang

Ke3chang has obtained and used tools such as Mimikatz.[46]

G0094 Kimsuky

Kimsuky has obtained and used tools such as Nirsoft WebBrowserPassVIew, Mimikatz, and PsExec.[47][48]

G0032 Lazarus Group

Lazarus Group has obtained a variety of tools for their operations, including Responder, PuTTy PSCP, Wake-On-Lan, ChromePass, and dbxcli.[49][50][51]

G0077 Leafminer

Leafminer has obtained and used tools such as LaZagne, Mimikatz, PsExec, and MailSniper.[52]

G0059 Magic Hound

Magic Hound has obtained and used open-source penetration testing tools like Havij, sqlmap, Metasploit, and Mimikatz.[53][54][55]

G0045 menuPass

menuPass has used and modified open-source tools like Impacket, Mimikatz, and pwdump.[56]

G0069 MuddyWater

MuddyWater has made use of legitimate tools ConnectWise and RemoteUtilities for access to target environments.[57]

G0014 Night Dragon

Night Dragon has obtained and used tools such as gsecdump.[58]

G0040 Patchwork

Patchwork has obtained and used open-source tools such as QuasarRAT.[59]

G0011 PittyTiger

PittyTiger has obtained and used tools such as Mimikatz and gsecdump.[60]

G0034 Sandworm Team

Sandworm Team has acquired open-source tools for some of it's operations; for example it acquired Invoke-PSImage to establish an encrypted channel from a compromised host to Sandworm Team's C2 server as part of its preparation for the 2018 Winter Olympics attack.[61]

G0091 Silence

Silence has obtained and modified versions of publicly-available tools like Empire and PsExec.[62] [63]

G0122 Silent Librarian

Silent Librarian has obtained free and publicly available tools including SingleFile and HTTrack to copy login pages of targeted organizations.[64][65]

G0088 TEMP.Veles

TEMP.Veles has obtained and used tools such as Mimikatz and PsExec.[66]

G0027 Threat Group-3390

Threat Group-3390 has obtained and used tools such as Impacket, pwdump, Mimikatz, gsecdump, NBTscan, and Windows Credential Editor.[67][68]

G0076 Thrip

Thrip has obtained and used tools such as Mimikatz and PsExec.[69]

G0010 Turla

Turla has obtained and customized publicly-available tools like Mimikatz.[70]

G0107 Whitefly

Whitefly has obtained and used tools such as Mimikatz.[71]


WIRTE has obtained and used Empire for post-exploitation activities.[72]

G0102 Wizard Spider

Wizard Spider has obtained and used publicly-available post-exploitation frameworks and tools like Metasploit, Empire, Mimikatz.[73]


ID Mitigation Description
M1056 Pre-compromise

This technique cannot be easily mitigated with preventive controls since it is based on behaviors performed outside of the scope of enterprise defenses and controls.


ID Data Source Data Component Detects
DS0004 Malware Repository Malware Metadata

Monitor for contextual data about a malicious payload, such as compilation times, file hashes, as well as watermarks or other identifiable configuration information. In some cases, malware repositories can also be used to identify features of tool use associated with an adversary, such as watermarks in Cobalt Strike payloads.[74]Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on post-compromise phases of the adversary lifecycle.


