ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Campaign: C0048×

17 examples

TechniqueUsed byProcedure example
T1003.003
NTDS
CampaignOperation MidnightEclipse

During Operation MidnightEclipse, threat actors obtained active directory credentials via the NTDS.DIT file.

T1005
Data from Local System
CampaignOperation MidnightEclipse

During Operation MidnightEclipse, threat actors stole saved cookies and login data from targeted systems.

T1021.002
SMB/Windows Admin Shares
CampaignOperation MidnightEclipse

During Operation MidnightEclipse, threat actors used SMB to pivot internally in victim networks.

T1021.006
Windows Remote Management
CampaignOperation MidnightEclipse

During Operation MidnightEclipse, threat actors used WinRM to move laterally in targeted networks.

T1053.003
Cron
CampaignOperation MidnightEclipse

During Operation MidnightEclipse, threat actors configured cron jobs to retrieve payloads from actor-controlled infrastructure.

T1059.004
Unix Shell
CampaignOperation MidnightEclipse

During Operation MidnightEclipse, threat actors piped output from stdout to bash for execution.

T1071.001
Web Protocols
CampaignOperation MidnightEclipse

During Operation MidnightEclipse, threat actors used `wget` via HTTP to retrieve payloads.

T1074.001
Local Data Staging
CampaignOperation MidnightEclipse

During Operation MidnightEclipse, threat actors copied files to the web application folder on compromised devices for exfiltration.

T1078
Valid Accounts
CampaignOperation MidnightEclipse

During Operation MidnightEclipse, threat actors extracted sensitive credentials while moving laterally through compromised networks.

T1078.002
Domain Accounts
CampaignOperation MidnightEclipse

During Operation MidnightEclipse, threat actors used a compromised domain admin account to move laterally.

T1090
Proxy
CampaignOperation MidnightEclipse

During Operation MidnightEclipse, threat actors used the GO Simple Tunnel reverse proxy tool.

T1105
Ingress Tool Transfer
CampaignOperation MidnightEclipse

During Operation MidnightEclipse, threat actors downloaded additional payloads on compromised devices.

T1190
Exploit Public-Facing Application
CampaignOperation MidnightEclipse

During Operation MidnightEclipse, threat actors exploited CVE-2024-3400 in Palo Alto Networks GlobalProtect.

T1559
Inter-Process Communication
CampaignOperation MidnightEclipse

During Operation MidnightEclipse, threat actors wrote output to stdout then piped it to bash for execution.

T1584.003
Virtual Private Server
CampaignOperation MidnightEclipse

During Operation MidnightEclipse, threat actors abused Virtual Private Servers to store malicious files.

T1584.006
Web Services
CampaignOperation MidnightEclipse

During Operation MidnightEclipse, threat actors abused compromised AWS buckets to store files.

T1588.002
Tool
CampaignOperation MidnightEclipse

During Operation MidnightEclipse, threat actors used the GO Simple Tunnel (GOST) reverse proxy tool.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.