Real-world descriptions of how a group, tool or campaign used a technique.
35 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.001 LSASS Memory |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors used Mimikatz to dump LSASS memory. |
| T1005 Data from Local System |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors extracted information from the compromised systems. |
| T1027.002 Software Packing |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors UPX-packed malicous payloads including 4L4MD4R ransomware. |
| T1027.010 Command Obfuscation |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors executed Base64-encoded PowerShell commands. |
| T1033 System Owner/User Discovery |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors executed `whoami` on victim machines to enumerate user context and validate privilege levels. |
| T1041 Exfiltration Over C2 Channel |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors exfiltrated stolen credentials and internal data over HTTPS to C2 infrastructure. |
| T1047 Windows Management Instrumentation |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors used WMI for execution. |
| T1053.005 Scheduled Task |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors used scheduled tasks to help establish persistence. |
| T1059.001 PowerShell |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors used PowerShell to execute attacker-controlled encoded commands. |
| T1059.003 Windows Command Shell |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors utilized `cmd.exe` and batch scripts within the victim environment. |
| T1071.001 Web Protocols |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors issued HTTP `POST` requests to web shells with spoofed or empty Referrer headers, to circumvent authorization controls. |
| T1074.001 Local Data Staging |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors staged stolen data from web.config files to debug_dev.js. |
| T1082 System Information Discovery |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors fingerprinted targeted SharePoint servers to identify OS version and running processes. |
| T1083 File and Directory Discovery |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors leveraged commands to locate accessible file shares, backup paths, or SharePoint content. |
| T1090 Proxy |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors used Fast Reverse Proxy to communicate with C2. |
| T1105 Ingress Tool Transfer |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors used a loader to download and execute ransomware. |
| T1112 Modify Registry |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors, including Storm-2603, disabled security services via Registry modifications. |
| T1119 Automated Collection |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors used a command shell to automatically iterate through web.config files to expose and collect machineKey settings. |
| T1140 Deobfuscate/Decode Files or Information |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors decrypted scripts prior to execution. |
| T1190 Exploit Public-Facing Application |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors exploited authentication bypass and remote code execution vulnerabilities (CVE-2025-49706 and CVE-2025-49704) against on-premises SharePoint servers. This activity was characterized by crafted `POST` requests to the ToolPane endpoint `/_layouts/15/ToolPane.aspx`. |
| T1484.001 Group Policy Modification |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors, including Storm-2603, modified group policy to enable ransomware distribution. |
| T1486 Data Encrypted for Impact |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors deployed ransomware including 4L4MD4R and Warlock. |
| T1505.003 Web Shell |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors followed exploitation of SharePoint servers with installation of a malicious .aspx web shell (spinstall0.aspx) that was written to the `_layouts/15/` directory, granting persistent HTTP-based access. |
| T1505.004 IIS Components |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors modified Internet Information Services (IIS) components to load suspicious .NET assemblies for persistence. |
| T1552.001 Credentials In Files |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors accessed web.config and machine.config to extract MachineKey values, enabling them to forge legitimate VIEWSTATE tokens for future deserialization payloads. |
| T1569.002 Service Execution |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors leveraged PsExec for command execution and used `services.exe` to disable Microsoft Defender via Registry keys. |
| T1570 Lateral Tool Transfer |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors used Impacket to remotely stage and execute payloads via WMI. |
| T1572 Protocol Tunneling |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors utilized ngrok tunnels to deliver PowerShell payloads. |
| T1583.001 Domains |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors registered C2 domains to spoof legitimate Microsoft domains. |
| T1585.002 Email Accounts |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors created Proton mail accounts for communication with organizations infected with ransomware. |
| T1588.002 Tool |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors leveraged tools including Impacket, PsExec, and Mimikatz. |
| T1595.002 Vulnerability Scanning |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors scanned for SharePoint servers vulnerable to CVE-2025-53770. |
| T1620 Reflective Code Loading |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors reflectively loaded payloads using `System.Reflection.Assembly.Load`. |
| T1657 Financial Theft |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors demanded ransom payments to unencrypt filesystems and to refrain from publishing sensitive data exfiltrated from victim networks. |
| T1685 Disable or Modify Tools |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors disabled Microsoft Defender through Registry settings and real-time monitoring via PowerShell. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.