ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

1146 examples

TechniqueUsed byProcedure example
T1001
Data Obfuscation
CampaignOperation Wocao

During Operation Wocao, threat actors encrypted IP addresses used for "Agent" proxy hops with RC4.

T1001.002
Steganography
CampaignOperation Ghost

During Operation Ghost, APT29 used steganography to hide the communications between the implants and their C&C servers.

T1001.003
Protocol or Service Impersonation
CampaignC0017

During C0017, APT41 frequently configured the URL endpoints of their stealthy passive backdoor LOWKEY.PASSIVE to masquerade as normal web application traffic on an infected server.

T1003.001
LSASS Memory
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors used Mimikatz to dump LSASS memory.

T1003.001
LSASS Memory
CampaignTriton Safety Instrumented System Attack

In the Triton Safety Instrumented System Attack, TEMP.Veles used Mimikatz.

T1003.001
LSASS Memory
CampaignCutting Edge

During Cutting Edge, threat actors used Task Manager to dump LSASS memory from Windows devices to disk.

T1003.001
LSASS Memory
CampaignOperation Digital Eye

During Operation Digital Eye, threat actors targeted memory from the LSASS process to extract credentials.

T1003.001
LSASS Memory
CampaignHomeLand Justice

During HomeLand Justice, threat actors dumped LSASS memory on compromised hosts.

T1003.001
LSASS Memory
CampaignC0032

During the C0032 campaign, TEMP.Veles used Mimikatz and a custom tool, SecHack, to harvest credentials.

T1003.001
LSASS Memory
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries attempted to dump credentials utilizing LSASS.

T1003.001
LSASS Memory
Campaign2016 Ukraine Electric Power Attack

During the 2016 Ukraine Electric Power Attack, Sandworm Team used Mimikatz to capture and use legitimate credentials.

T1003.001
LSASS Memory
CampaignOperation Wocao

During Operation Wocao, threat actors used ProcDump to dump credentials from memory.

T1003.002
Security Account Manager
CampaignFrostyGoop Incident

During FrostyGoop Incident, the adversary retrieved the contents of the Security Account Manager (SAM) hive in the victim environment for credential capture.

T1003.002
Security Account Manager
CampaignOperation Digital Eye

During Operation Digital Eye, threat actors used `reg save` to retrieve credentials from the Security Account Manager (SAM) database.

T1003.002
Security Account Manager
CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors leveraged a custom tool to dump OS credentials and used following commands: `reg save HKLM\\SYSTEM system.hiv`, `reg save HKLM\\SAM sam.hiv`, and `reg save HKLM\\SECURITY security.hiv`, to dump SAM, SYSTEM and SECURITY hives.

T1003.002
Security Account Manager
CampaignAPT28 Nearest Neighbor Campaign

During APT28 Nearest Neighbor Campaign, APT28 used the following commands to dump SAM, SYSTEM, and SECURITY hives: reg save hklm\sam, reg save hklm\system, and reg save hklm\security.

T1003.002
Security Account Manager
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries had stolen Security Account Manager (SAM) and SYSTEM registry hives.

T1003.002
Security Account Manager
CampaignNight Dragon

During Night Dragon, threat actors dumped account hashes using gsecdump.

T1003.002
Security Account Manager
CampaignC0017

During C0017, APT41 copied the `SAM` and `SYSTEM` Registry hives for credential harvesting.

T1003.003
NTDS
CampaignOperation MidnightEclipse

During Operation MidnightEclipse, threat actors obtained active directory credentials via the NTDS.DIT file.

T1003.003
NTDS
CampaignCutting Edge

During Cutting Edge, threat actors accessed and mounted virtual hard disk backups to extract
ntds.dit.

T1003.003
NTDS
CampaignAPT28 Nearest Neighbor Campaign

During APT28 Nearest Neighbor Campaign, APT28 dumped NTDS.dit through creating volume shadow copies via vssadmin.

T1003.003
NTDS
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries dumped the entire Active Directory database by extracting the contents of the ntds.dit file.

T1003.006
DCSync
CampaignC0027

During C0027, Scattered Spider performed domain replication.

T1003.006
DCSync
CampaignOperation Wocao

During Operation Wocao, threat actors used Mimikatz's DCSync to dump credentials from the memory of the targeted system.

T1003.006
DCSync
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used privileged accounts to replicate directory service data with domain controllers.

T1003.008
/etc/passwd and /etc/shadow
CampaignShadowRay

During ShadowRay, threat actors used `cat /etc/shadow` to steal password hashes.

T1005
Data from Local System
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group used malicious Trojans and DLL files to exfiltrate data from an infected host.

T1005
Data from Local System
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors extracted information from the compromised systems.

T1005
Data from Local System
CampaignFrankenstein

During Frankenstein, the threat actors used Empire to gather various local system information.

T1005
Data from Local System
CampaignOperation Honeybee

During Operation Honeybee, the threat actors collected data from compromised hosts.

T1005
Data from Local System
CampaignOperation MidnightEclipse

During Operation MidnightEclipse, threat actors stole saved cookies and login data from targeted systems.

T1005
Data from Local System
CampaignCutting Edge

During Cutting Edge, threat actors stole the running configuration and cache data from targeted Ivanti Connect Secure VPNs.

T1005
Data from Local System
CampaignAnthropic AI-orchestrated Campaign

During the Anthropic AI-orchestrated Campaign, the adversary tasked Claude Code to automatically gather sensitive data stored within the local system to include credentials, system configurations and sensitive operational data.

T1005
Data from Local System
CampaignC0015

During C0015, the threat actors obtained files and data from the compromised network.

T1005
Data from Local System
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 extracted files from compromised networks.

T1005
Data from Local System
CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors collected data, files, and other information from compromised networks.

T1005
Data from Local System
CampaignNight Dragon

During Night Dragon, the threat actors collected files and other data from compromised systems.

T1005
Data from Local System
CampaignOperation Wocao

During Operation Wocao, threat actors exfiltrated files and directories of interest from the targeted system.

T1005
Data from Local System
CampaignC0017

During C0017, APT41 collected information related to compromised machines as well as Personal Identifiable Information (PII) from victim networks.

T1005
Data from Local System
CampaignC0026

During C0026, the threat actors collected documents from compromised hosts.

T1005
Data from Local System
CampaignCostaRicto

During CostaRicto, the threat actors collected data and files from compromised networks.

T1006
Direct Volume Access
CampaignAPT28 Nearest Neighbor Campaign

During APT28 Nearest Neighbor Campaign, APT28 accessed volume shadow copies through executing vssadmin in order to dump the NTDS.dit file.

T1006
Direct Volume Access
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries copied volume shadow copies through executing `vssadmin` in order to dump the `NTDS.dit` file.

T1007
System Service Discovery
CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors used the `net start` command as part of their initial reconnaissance.

T1007
System Service Discovery
CampaignOperation Wocao

During Operation Wocao, threat actors used the `tasklist` command to search for one of its backdoors.

T1008
Fallback Channels
CampaignNight Dragon

During Night Dragon, threat actors used company extranet servers as secondary C2 servers.

T1012
Query Registry
CampaignOperation Wocao

During Operation Wocao, the threat actors executed `/c cd /d c:\windows\temp\ & reg query HKEY_CURRENT_USER\Software\<username>\PuTTY\Sessions\` to detect recent PuTTY sessions, likely to further lateral movement.

T1014
Rootkit
CampaignRedPenguin

During RedPenguin, UNC3886 used rootkits such as REPTILE and MEDUSA.

T1014
Rootkit
CampaignArcaneDoor

ArcaneDoor included hooking the `processHostScanReply()` function on victim Cisco ASA devices.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.