Real-world descriptions of how a group, tool or campaign used a technique.
1146 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1082 System Information Discovery |
CampaignLeviathan Australian Intrusions | Leviathan performed host enumeration and data gathering operations on victim machines during Leviathan Australian Intrusions. |
| T1083 File and Directory Discovery |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group conducted word searches within documents on a compromised host in search of security and financial matters. |
| T1083 File and Directory Discovery |
CampaignKV Botnet Activity | KV Botnet Activity gathers a list of filenames from the following locations during execution of the final botnet stage: |
| T1083 File and Directory Discovery |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors leveraged commands to locate accessible file shares, backup paths, or SharePoint content. |
| T1083 File and Directory Discovery |
CampaignOperation Honeybee | During Operation Honeybee, the threat actors used a malicious DLL to search for files with specific keywords. |
| T1083 File and Directory Discovery |
CampaignAnthropic AI-orchestrated Campaign | During the Anthropic AI-orchestrated Campaign, the adversary leveraged Claude Code to identify sensitive data within the victim environment for extraction. |
| T1083 File and Directory Discovery |
CampaignC0015 | During C0015, the threat actors conducted a file listing discovery against multiple hosts to ensure locker encryption was successful. |
| T1083 File and Directory Discovery |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 obtained information about the configured Exchange virtual directory using `Get-WebServicesVirtualDirectory`. |
| T1083 File and Directory Discovery |
CampaignOperation AkaiRyū | During Operation AkaiRyū, MirrorFace enumerated file system details in compromised environments. |
| T1083 File and Directory Discovery |
CampaignOperation CuckooBees | During Operation CuckooBees, the threat actors used `dir c:\\` to search for files. |
| T1083 File and Directory Discovery |
CampaignSalesforce Data Exfiltration | During Salesforce Data Exfiltration, threat actors queried customers' Salesforce environments to identify sensitive information for exfiltration. |
| T1083 File and Directory Discovery |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries obtained the contents of users’ directories using `dir /s /b C:\Users` command. |
| T1083 File and Directory Discovery |
CampaignNight Dragon | During Night Dragon, threat actors used zwShell to establish full remote control of the connected machine and browse the victim file system. |
| T1083 File and Directory Discovery |
CampaignOperation Wocao | During Operation Wocao, threat actors gathered a recursive directory listing to find files and directories of interest. |
| T1087 Account Discovery |
CampaignAnthropic AI-orchestrated Campaign | During the Anthropic AI-orchestrated Campaign, the adversary used Claude Code to query internal database user account tables to enumerate accounts and identify high-privilege accounts within compromised environments. |
| T1087 Account Discovery |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 obtained a list of users and their roles from an Exchange server using `Get-ManagementRoleAssignment`. |
| T1087.001 Local Account |
CampaignOperation Digital Eye | During Operation Digital Eye, threat actors used the local.exe tool to view local account information. |
| T1087.001 Local Account |
CampaignOperation CuckooBees | During Operation CuckooBees, the threat actors used the `net user` command to gather account information. |
| T1087.002 Domain Account |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group queried compromised victim's active directory servers to obtain the list of employees including administrator accounts. |
| T1087.002 Domain Account |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used PowerShell to discover domain accounts by exectuing `Get-ADUser` and `Get-ADGroupMember`. |
| T1087.002 Domain Account |
CampaignOperation CuckooBees | During Operation CuckooBees, the threat actors used the `dsquery` and `dsget` commands to get domain environment information and to query users in administrative groups. |
| T1087.002 Domain Account |
CampaignOperation Wocao | During Operation Wocao, threat actors used the `net` command to retrieve information about domain accounts. |
| T1087.003 Email Account |
CampaignHomeLand Justice | During HomeLand Justice, threat actors used compromised Exchange accounts to search mailboxes for administrator accounts. |
| T1087.003 Email Account |
CampaignC0027 | During C0027, Scattered Spider accessed Azure AD to identify email addresses. |
| T1087.004 Cloud Account |
CampaignC0027 | During C0027, Scattered Spider accessed Azure AD to download bulk lists of group members and to identify privileged users, along with the email addresses and AD attributes. |
| T1090 Proxy |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors used Fast Reverse Proxy to communicate with C2. |
| T1090 Proxy |
CampaignRedDelta Modified PlugX Infection Chain Operations | Mustang Panda proxied communication through the Cloudflare CDN service during RedDelta Modified PlugX Infection Chain Operations. |
| T1090 Proxy |
CampaignRedPenguin | During RedPenguin, UNC3886 used malware capable of establishing a SOCKS proxy connection to a specified IP and port. |
| T1090 Proxy |
CampaignOperation Sharpshooter | For Operation Sharpshooter, the threat actors used the ExpressVPN service to hide their location. |
| T1090 Proxy |
CampaignOperation MidnightEclipse | During Operation MidnightEclipse, threat actors used the GO Simple Tunnel reverse proxy tool. |
| T1090 Proxy |
CampaignSalesforce Data Exfiltration | During Salesforce Data Exfiltration, threat actors used Mullvad VPN IPs to proxy voice phishing calls. |
| T1090 Proxy |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries utilized the rsocx tool identified as `r.exe` and `rsocx.exe` to tunnel within the internal infrastructure using a Reverse SOCKS Proxy. |
| T1090 Proxy |
CampaignOperation Wocao | During Operation Wocao, threat actors used a custom proxy tool called "Agent" which has support for multiple hops. |
| T1090 Proxy |
CampaignC0017 | During C0017, APT41 used the Cloudflare CDN to proxy C2 traffic. |
| T1090 Proxy |
CampaignC0027 | During C0027, Scattered Spider installed the open-source rsocx reverse proxy tool on a targeted ESXi appliance. |
| T1090.001 Internal Proxy |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used SSH port forwarding capabilities on public-facing systems, and configured at least one instance of Cobalt Strike to use a network pipe over SMB. |
| T1090.001 Internal Proxy |
CampaignAPT28 Nearest Neighbor Campaign | During APT28 Nearest Neighbor Campaign, APT28 used the built-in |
| T1090.001 Internal Proxy |
CampaignOperation Wocao | During Operation Wocao, threat actors proxied traffic through multiple infected systems. |
| T1090.002 External Proxy |
CampaignQuad7 Activity | Quad7 Activity has initialized SOCKS5 proxies on compromised devices. |
| T1090.003 Multi-hop Proxy |
CampaignRedPenguin | During RedPenguin, UNC3886 used infrastructure associated with operational relay box (ORB) networks. |
| T1090.003 Multi-hop Proxy |
CampaignSPACEHOP Activity | SPACEHOP Activity has routed traffic through chains of compromised network devices to proxy C2 communications. |
| T1090.003 Multi-hop Proxy |
CampaignSalesforce Data Exfiltration | During Salesforce Data Exfiltration, threat actors used Tor IPs for voice calls and for the collection of stolen data. |
| T1090.003 Multi-hop Proxy |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries utilized Tor nodes for C2. |
| T1090.003 Multi-hop Proxy |
CampaignOperation Wocao | During Operation Wocao, threat actors executed commands through the installed web shell via Tor exit nodes. |
| T1090.003 Multi-hop Proxy |
CampaignQuad7 Activity | Quad7 Activity has routed traffic through chains of compromised network devices for password spray attacks. |
| T1090.003 Multi-hop Proxy |
CampaignFLORAHOX Activity | FLORAHOX Activity has routed traffic through a customized Tor relay network layer. |
| T1090.003 Multi-hop Proxy |
CampaignCostaRicto | During CostaRicto, the threat actors used a layer of proxies to manage C2 communications. |
| T1095 Non-Application Layer Protocol |
CampaignKV Botnet Activity | KV Botnet Activity command and control traffic uses a non-standard, likely custom protocol for communication. |
| T1095 Non-Application Layer Protocol |
CampaignRedDelta Modified PlugX Infection Chain Operations | Mustang Panda communicated over TCP 5000 from adversary administrative servers to adversary command and control nodes during RedDelta Modified PlugX Infection Chain Operations. |
| T1095 Non-Application Layer Protocol |
CampaignRedPenguin | During RedPenguin, UNC3886 leveraged malware that used UDP and TCP sockets for C2. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.