Real-world descriptions of how a group, tool or campaign used a technique.
1146 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1001 Data Obfuscation |
CampaignOperation Wocao | During Operation Wocao, threat actors encrypted IP addresses used for "Agent" proxy hops with RC4. |
| T1001.002 Steganography |
CampaignOperation Ghost | During Operation Ghost, APT29 used steganography to hide the communications between the implants and their C&C servers. |
| T1001.003 Protocol or Service Impersonation |
CampaignC0017 | During C0017, APT41 frequently configured the URL endpoints of their stealthy passive backdoor LOWKEY.PASSIVE to masquerade as normal web application traffic on an infected server. |
| T1003.001 LSASS Memory |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors used Mimikatz to dump LSASS memory. |
| T1003.001 LSASS Memory |
CampaignTriton Safety Instrumented System Attack | In the Triton Safety Instrumented System Attack, TEMP.Veles used Mimikatz. |
| T1003.001 LSASS Memory |
CampaignCutting Edge | During Cutting Edge, threat actors used Task Manager to dump LSASS memory from Windows devices to disk. |
| T1003.001 LSASS Memory |
CampaignOperation Digital Eye | During Operation Digital Eye, threat actors targeted memory from the LSASS process to extract credentials. |
| T1003.001 LSASS Memory |
CampaignHomeLand Justice | During HomeLand Justice, threat actors dumped LSASS memory on compromised hosts. |
| T1003.001 LSASS Memory |
CampaignC0032 | During the C0032 campaign, TEMP.Veles used Mimikatz and a custom tool, SecHack, to harvest credentials. |
| T1003.001 LSASS Memory |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries attempted to dump credentials utilizing LSASS. |
| T1003.001 LSASS Memory |
Campaign2016 Ukraine Electric Power Attack | During the 2016 Ukraine Electric Power Attack, Sandworm Team used Mimikatz to capture and use legitimate credentials. |
| T1003.001 LSASS Memory |
CampaignOperation Wocao | During Operation Wocao, threat actors used ProcDump to dump credentials from memory. |
| T1003.002 Security Account Manager |
CampaignFrostyGoop Incident | During FrostyGoop Incident, the adversary retrieved the contents of the Security Account Manager (SAM) hive in the victim environment for credential capture. |
| T1003.002 Security Account Manager |
CampaignOperation Digital Eye | During Operation Digital Eye, threat actors used `reg save` to retrieve credentials from the Security Account Manager (SAM) database. |
| T1003.002 Security Account Manager |
CampaignOperation CuckooBees | During Operation CuckooBees, the threat actors leveraged a custom tool to dump OS credentials and used following commands: `reg save HKLM\\SYSTEM system.hiv`, `reg save HKLM\\SAM sam.hiv`, and `reg save HKLM\\SECURITY security.hiv`, to dump SAM, SYSTEM and SECURITY hives. |
| T1003.002 Security Account Manager |
CampaignAPT28 Nearest Neighbor Campaign | During APT28 Nearest Neighbor Campaign, APT28 used the following commands to dump SAM, SYSTEM, and SECURITY hives: |
| T1003.002 Security Account Manager |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries had stolen Security Account Manager (SAM) and SYSTEM registry hives. |
| T1003.002 Security Account Manager |
CampaignNight Dragon | During Night Dragon, threat actors dumped account hashes using gsecdump. |
| T1003.002 Security Account Manager |
CampaignC0017 | During C0017, APT41 copied the `SAM` and `SYSTEM` Registry hives for credential harvesting. |
| T1003.003 NTDS |
CampaignOperation MidnightEclipse | During Operation MidnightEclipse, threat actors obtained active directory credentials via the NTDS.DIT file. |
| T1003.003 NTDS |
CampaignCutting Edge | During Cutting Edge, threat actors accessed and mounted virtual hard disk backups to extract |
| T1003.003 NTDS |
CampaignAPT28 Nearest Neighbor Campaign | During APT28 Nearest Neighbor Campaign, APT28 dumped NTDS.dit through creating volume shadow copies via |
| T1003.003 NTDS |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries dumped the entire Active Directory database by extracting the contents of the ntds.dit file. |
| T1003.006 DCSync |
CampaignC0027 | During C0027, Scattered Spider performed domain replication. |
| T1003.006 DCSync |
CampaignOperation Wocao | During Operation Wocao, threat actors used Mimikatz's DCSync to dump credentials from the memory of the targeted system. |
| T1003.006 DCSync |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used privileged accounts to replicate directory service data with domain controllers. |
| T1003.008 /etc/passwd and /etc/shadow |
CampaignShadowRay | During ShadowRay, threat actors used `cat /etc/shadow` to steal password hashes. |
| T1005 Data from Local System |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group used malicious Trojans and DLL files to exfiltrate data from an infected host. |
| T1005 Data from Local System |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors extracted information from the compromised systems. |
| T1005 Data from Local System |
CampaignFrankenstein | During Frankenstein, the threat actors used Empire to gather various local system information. |
| T1005 Data from Local System |
CampaignOperation Honeybee | During Operation Honeybee, the threat actors collected data from compromised hosts. |
| T1005 Data from Local System |
CampaignOperation MidnightEclipse | During Operation MidnightEclipse, threat actors stole saved cookies and login data from targeted systems. |
| T1005 Data from Local System |
CampaignCutting Edge | During Cutting Edge, threat actors stole the running configuration and cache data from targeted Ivanti Connect Secure VPNs. |
| T1005 Data from Local System |
CampaignAnthropic AI-orchestrated Campaign | During the Anthropic AI-orchestrated Campaign, the adversary tasked Claude Code to automatically gather sensitive data stored within the local system to include credentials, system configurations and sensitive operational data. |
| T1005 Data from Local System |
CampaignC0015 | During C0015, the threat actors obtained files and data from the compromised network. |
| T1005 Data from Local System |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 extracted files from compromised networks. |
| T1005 Data from Local System |
CampaignOperation CuckooBees | During Operation CuckooBees, the threat actors collected data, files, and other information from compromised networks. |
| T1005 Data from Local System |
CampaignNight Dragon | During Night Dragon, the threat actors collected files and other data from compromised systems. |
| T1005 Data from Local System |
CampaignOperation Wocao | During Operation Wocao, threat actors exfiltrated files and directories of interest from the targeted system. |
| T1005 Data from Local System |
CampaignC0017 | During C0017, APT41 collected information related to compromised machines as well as Personal Identifiable Information (PII) from victim networks. |
| T1005 Data from Local System |
CampaignC0026 | During C0026, the threat actors collected documents from compromised hosts. |
| T1005 Data from Local System |
CampaignCostaRicto | During CostaRicto, the threat actors collected data and files from compromised networks. |
| T1006 Direct Volume Access |
CampaignAPT28 Nearest Neighbor Campaign | During APT28 Nearest Neighbor Campaign, APT28 accessed volume shadow copies through executing |
| T1006 Direct Volume Access |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries copied volume shadow copies through executing `vssadmin` in order to dump the `NTDS.dit` file. |
| T1007 System Service Discovery |
CampaignOperation CuckooBees | During Operation CuckooBees, the threat actors used the `net start` command as part of their initial reconnaissance. |
| T1007 System Service Discovery |
CampaignOperation Wocao | During Operation Wocao, threat actors used the `tasklist` command to search for one of its backdoors. |
| T1008 Fallback Channels |
CampaignNight Dragon | During Night Dragon, threat actors used company extranet servers as secondary C2 servers. |
| T1012 Query Registry |
CampaignOperation Wocao | During Operation Wocao, the threat actors executed `/c cd /d c:\windows\temp\ & reg query HKEY_CURRENT_USER\Software\<username>\PuTTY\Sessions\` to detect recent PuTTY sessions, likely to further lateral movement. |
| T1014 Rootkit |
CampaignRedPenguin | During RedPenguin, UNC3886 used rootkits such as REPTILE and MEDUSA. |
| T1014 Rootkit |
CampaignArcaneDoor | ArcaneDoor included hooking the `processHostScanReply()` function on victim Cisco ASA devices. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.