Real-world descriptions of how a group, tool or campaign used a technique.
17 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.003 NTDS |
CampaignOperation MidnightEclipse | During Operation MidnightEclipse, threat actors obtained active directory credentials via the NTDS.DIT file. |
| T1005 Data from Local System |
CampaignOperation MidnightEclipse | During Operation MidnightEclipse, threat actors stole saved cookies and login data from targeted systems. |
| T1021.002 SMB/Windows Admin Shares |
CampaignOperation MidnightEclipse | During Operation MidnightEclipse, threat actors used SMB to pivot internally in victim networks. |
| T1021.006 Windows Remote Management |
CampaignOperation MidnightEclipse | During Operation MidnightEclipse, threat actors used WinRM to move laterally in targeted networks. |
| T1053.003 Cron |
CampaignOperation MidnightEclipse | During Operation MidnightEclipse, threat actors configured cron jobs to retrieve payloads from actor-controlled infrastructure. |
| T1059.004 Unix Shell |
CampaignOperation MidnightEclipse | During Operation MidnightEclipse, threat actors piped output from stdout to bash for execution. |
| T1071.001 Web Protocols |
CampaignOperation MidnightEclipse | During Operation MidnightEclipse, threat actors used `wget` via HTTP to retrieve payloads. |
| T1074.001 Local Data Staging |
CampaignOperation MidnightEclipse | During Operation MidnightEclipse, threat actors copied files to the web application folder on compromised devices for exfiltration. |
| T1078 Valid Accounts |
CampaignOperation MidnightEclipse | During Operation MidnightEclipse, threat actors extracted sensitive credentials while moving laterally through compromised networks. |
| T1078.002 Domain Accounts |
CampaignOperation MidnightEclipse | During Operation MidnightEclipse, threat actors used a compromised domain admin account to move laterally. |
| T1090 Proxy |
CampaignOperation MidnightEclipse | During Operation MidnightEclipse, threat actors used the GO Simple Tunnel reverse proxy tool. |
| T1105 Ingress Tool Transfer |
CampaignOperation MidnightEclipse | During Operation MidnightEclipse, threat actors downloaded additional payloads on compromised devices. |
| T1190 Exploit Public-Facing Application |
CampaignOperation MidnightEclipse | During Operation MidnightEclipse, threat actors exploited CVE-2024-3400 in Palo Alto Networks GlobalProtect. |
| T1559 Inter-Process Communication |
CampaignOperation MidnightEclipse | During Operation MidnightEclipse, threat actors wrote output to stdout then piped it to bash for execution. |
| T1584.003 Virtual Private Server |
CampaignOperation MidnightEclipse | During Operation MidnightEclipse, threat actors abused Virtual Private Servers to store malicious files. |
| T1584.006 Web Services |
CampaignOperation MidnightEclipse | During Operation MidnightEclipse, threat actors abused compromised AWS buckets to store files. |
| T1588.002 Tool |
CampaignOperation MidnightEclipse | During Operation MidnightEclipse, threat actors used the GO Simple Tunnel (GOST) reverse proxy tool. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.