ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

1146 examples

TechniqueUsed byProcedure example
T1082
System Information Discovery
CampaignLeviathan Australian Intrusions

Leviathan performed host enumeration and data gathering operations on victim machines during Leviathan Australian Intrusions.

T1083
File and Directory Discovery
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group conducted word searches within documents on a compromised host in search of security and financial matters.

T1083
File and Directory Discovery
CampaignKV Botnet Activity

KV Botnet Activity gathers a list of filenames from the following locations during execution of the final botnet stage: \/usr\/sbin\/, \/usr\/bin\/, \/sbin\/, \/pfrm2.0\/bin\/, \/usr\/local\/bin\/.

T1083
File and Directory Discovery
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors leveraged commands to locate accessible file shares, backup paths, or SharePoint content.

T1083
File and Directory Discovery
CampaignOperation Honeybee

During Operation Honeybee, the threat actors used a malicious DLL to search for files with specific keywords.

T1083
File and Directory Discovery
CampaignAnthropic AI-orchestrated Campaign

During the Anthropic AI-orchestrated Campaign, the adversary leveraged Claude Code to identify sensitive data within the victim environment for extraction.

T1083
File and Directory Discovery
CampaignC0015

During C0015, the threat actors conducted a file listing discovery against multiple hosts to ensure locker encryption was successful.

T1083
File and Directory Discovery
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 obtained information about the configured Exchange virtual directory using `Get-WebServicesVirtualDirectory`.

T1083
File and Directory Discovery
CampaignOperation AkaiRyū

During Operation AkaiRyū, MirrorFace enumerated file system details in compromised environments.

T1083
File and Directory Discovery
CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors used `dir c:\\` to search for files.

T1083
File and Directory Discovery
CampaignSalesforce Data Exfiltration

During Salesforce Data Exfiltration, threat actors queried customers' Salesforce environments to identify sensitive information for exfiltration.

T1083
File and Directory Discovery
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries obtained the contents of users’ directories using `dir /s /b C:\Users` command.

T1083
File and Directory Discovery
CampaignNight Dragon

During Night Dragon, threat actors used zwShell to establish full remote control of the connected machine and browse the victim file system.

T1083
File and Directory Discovery
CampaignOperation Wocao

During Operation Wocao, threat actors gathered a recursive directory listing to find files and directories of interest.

T1087
Account Discovery
CampaignAnthropic AI-orchestrated Campaign

During the Anthropic AI-orchestrated Campaign, the adversary used Claude Code to query internal database user account tables to enumerate accounts and identify high-privilege accounts within compromised environments.

T1087
Account Discovery
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 obtained a list of users and their roles from an Exchange server using `Get-ManagementRoleAssignment`.

T1087.001
Local Account
CampaignOperation Digital Eye

During Operation Digital Eye, threat actors used the local.exe tool to view local account information.

T1087.001
Local Account
CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors used the `net user` command to gather account information.

T1087.002
Domain Account
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group queried compromised victim's active directory servers to obtain the list of employees including administrator accounts.

T1087.002
Domain Account
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used PowerShell to discover domain accounts by exectuing `Get-ADUser` and `Get-ADGroupMember`.

T1087.002
Domain Account
CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors used the `dsquery` and `dsget` commands to get domain environment information and to query users in administrative groups.

T1087.002
Domain Account
CampaignOperation Wocao

During Operation Wocao, threat actors used the `net` command to retrieve information about domain accounts.

T1087.003
Email Account
CampaignHomeLand Justice

During HomeLand Justice, threat actors used compromised Exchange accounts to search mailboxes for administrator accounts.

T1087.003
Email Account
CampaignC0027

During C0027, Scattered Spider accessed Azure AD to identify email addresses.

T1087.004
Cloud Account
CampaignC0027

During C0027, Scattered Spider accessed Azure AD to download bulk lists of group members and to identify privileged users, along with the email addresses and AD attributes.

T1090
Proxy
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors used Fast Reverse Proxy to communicate with C2.

T1090
Proxy
CampaignRedDelta Modified PlugX Infection Chain Operations

Mustang Panda proxied communication through the Cloudflare CDN service during RedDelta Modified PlugX Infection Chain Operations.

T1090
Proxy
CampaignRedPenguin

During RedPenguin, UNC3886 used malware capable of establishing a SOCKS proxy connection to a specified IP and port.

T1090
Proxy
CampaignOperation Sharpshooter

For Operation Sharpshooter, the threat actors used the ExpressVPN service to hide their location.

T1090
Proxy
CampaignOperation MidnightEclipse

During Operation MidnightEclipse, threat actors used the GO Simple Tunnel reverse proxy tool.

T1090
Proxy
CampaignSalesforce Data Exfiltration

During Salesforce Data Exfiltration, threat actors used Mullvad VPN IPs to proxy voice phishing calls.

T1090
Proxy
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries utilized the rsocx tool identified as `r.exe` and `rsocx.exe` to tunnel within the internal infrastructure using a Reverse SOCKS Proxy.

T1090
Proxy
CampaignOperation Wocao

During Operation Wocao, threat actors used a custom proxy tool called "Agent" which has support for multiple hops.

T1090
Proxy
CampaignC0017

During C0017, APT41 used the Cloudflare CDN to proxy C2 traffic.

T1090
Proxy
CampaignC0027

During C0027, Scattered Spider installed the open-source rsocx reverse proxy tool on a targeted ESXi appliance.

T1090.001
Internal Proxy
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used SSH port forwarding capabilities on public-facing systems, and configured at least one instance of Cobalt Strike to use a network pipe over SMB.

T1090.001
Internal Proxy
CampaignAPT28 Nearest Neighbor Campaign

During APT28 Nearest Neighbor Campaign, APT28 used the built-in netsh portproxy command to create internal proxies on compromised systems.

T1090.001
Internal Proxy
CampaignOperation Wocao

During Operation Wocao, threat actors proxied traffic through multiple infected systems.

T1090.002
External Proxy
CampaignQuad7 Activity

Quad7 Activity has initialized SOCKS5 proxies on compromised devices.

T1090.003
Multi-hop Proxy
CampaignRedPenguin

During RedPenguin, UNC3886 used infrastructure associated with operational relay box (ORB) networks.

T1090.003
Multi-hop Proxy
CampaignSPACEHOP Activity

SPACEHOP Activity has routed traffic through chains of compromised network devices to proxy C2 communications.

T1090.003
Multi-hop Proxy
CampaignSalesforce Data Exfiltration

During Salesforce Data Exfiltration, threat actors used Tor IPs for voice calls and for the collection of stolen data.

T1090.003
Multi-hop Proxy
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries utilized Tor nodes for C2.

T1090.003
Multi-hop Proxy
CampaignOperation Wocao

During Operation Wocao, threat actors executed commands through the installed web shell via Tor exit nodes.

T1090.003
Multi-hop Proxy
CampaignQuad7 Activity

Quad7 Activity has routed traffic through chains of compromised network devices for password spray attacks.

T1090.003
Multi-hop Proxy
CampaignFLORAHOX Activity

FLORAHOX Activity has routed traffic through a customized Tor relay network layer.

T1090.003
Multi-hop Proxy
CampaignCostaRicto

During CostaRicto, the threat actors used a layer of proxies to manage C2 communications.

T1095
Non-Application Layer Protocol
CampaignKV Botnet Activity

KV Botnet Activity command and control traffic uses a non-standard, likely custom protocol for communication.

T1095
Non-Application Layer Protocol
CampaignRedDelta Modified PlugX Infection Chain Operations

Mustang Panda communicated over TCP 5000 from adversary administrative servers to adversary command and control nodes during RedDelta Modified PlugX Infection Chain Operations.

T1095
Non-Application Layer Protocol
CampaignRedPenguin

During RedPenguin, UNC3886 leveraged malware that used UDP and TCP sockets for C2.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.