Real-world descriptions of how a group, tool or campaign used a technique.
1146 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1095 Non-Application Layer Protocol |
CampaignCutting Edge | During Cutting Edge, threat actors used the Unix socket and a reverse TCP shell for C2 communications. |
| T1095 Non-Application Layer Protocol |
CampaignC0021 | During C0021, the threat actors used TCP for some C2 communications. |
| T1095 Non-Application Layer Protocol |
CampaignVersa Director Zero Day Exploitation | Versa Director Zero Day Exploitation used a non-standard TCP session to initialize communication prior to establishing HTTPS command and control. |
| T1095 Non-Application Layer Protocol |
CampaignOperation Wocao | During Operation Wocao, threat actors used a custom protocol for command and control. |
| T1095 Non-Application Layer Protocol |
Campaign2022 Ukraine Electric Power Attack | During the 2022 Ukraine Electric Power Attack, Sandworm Team proxied C2 communications within a TLS-based tunnel. |
| T1098 Account Manipulation |
Campaign2016 Ukraine Electric Power Attack | During the 2016 Ukraine Electric Power Attack, Sandworm Team used the `sp_addlinkedsrvlogin` command in MS-SQL to create a link between a created account and other servers in the network. |
| T1098.001 Additional Cloud Credentials |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 added credentials to OAuth Applications and Service Principals. |
| T1098.001 Additional Cloud Credentials |
CampaignC0027 | During C0027, Scattered Spider used aws_consoler to create temporary federated credentials for fake users in order to obfuscate which AWS credential is compromised and enable pivoting from the AWS CLI to console sessions without MFA. |
| T1098.002 Additional Email Delegate Permissions |
CampaignHomeLand Justice | During HomeLand Justice, threat actors added the `ApplicationImpersonation` management role to accounts under their control to impersonate users and take ownership of targeted mailboxes. |
| T1098.002 Additional Email Delegate Permissions |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 added their own devices as allowed IDs for active sync using `Set-CASMailbox`, allowing it to obtain copies of victim mailboxes. It also added additional permissions (such as Mail.Read and Mail.ReadWrite) to compromised Application or Service Principals. |
| T1098.003 Additional Cloud Roles |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 granted `company administrator` privileges to a newly created service principle. |
| T1098.003 Additional Cloud Roles |
CampaignC0027 | During C0027, Scattered Spider used IAM manipulation to gain persistence and to assume or elevate privileges. |
| T1098.004 SSH Authorized Keys |
CampaignOperation Digital Eye | During Operation Digital Eye, threat actors used SSH access enabled by authorized_keys files for remote execution. |
| T1098.005 Device Registration |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 registered devices in order to enable mailbox syncing via the `Set-CASMailbox` command. |
| T1098.005 Device Registration |
CampaignC0027 | During C0027, Scattered Spider registered devices for MFA to maintain persistence through victims' VPN. |
| T1102 Web Service |
CampaignOperation Spalax | During Operation Spalax, the threat actors used OneDrive and MediaFire to host payloads. |
| T1102 Web Service |
CampaignAPT41 DUST | APT41 DUST used compromised Google Workspace accounts for command and control. |
| T1102 Web Service |
CampaignC0017 | During C0017, APT41 used the Cloudflare services for C2 communications. |
| T1102 Web Service |
CampaignC0027 | During C0027, Scattered Spider downloaded tools from sites including file.io, GitHub, and paste.ee. |
| T1102.001 Dead Drop Resolver |
Campaign3CX Supply Chain Attack | During the 3CX Supply Chain Attack, AppleJeus leveraged a GitHub repository to host icon files containing the command and control URL. |
| T1102.001 Dead Drop Resolver |
CampaignC0017 | During C0017, APT41 used dead drop resolvers on two separate tech community forums for their KEYPLUG Windows-version backdoor; notably APT41 updated the community forum posts frequently with new dead drop resolvers during the campaign. |
| T1102.002 Bidirectional Communication |
CampaignOperation Ghost | For Operation Ghost, APT29 used social media platforms to hide communications to C2 servers. |
| T1102.002 Bidirectional Communication |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries had communicated to both Dropbox and Pastebin. |
| T1102.003 One-Way Communication |
CampaignArcaneDoor | ArcaneDoor utilized HTTP command and control traffic where commands are intercepted from HTTP traffic to the device, parsed for appropriate identifiers and commands, and then executed. |
| T1104 Multi-Stage Channels |
CampaignRedPenguin | During RedPenguin, UNC3886 used malware with separate channels to request and carry out tasks from C2. |
| T1105 Ingress Tool Transfer |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group downloaded multistage malware and tools onto a compromised host. |
| T1105 Ingress Tool Transfer |
CampaignKV Botnet Activity | KV Botnet Activity included the use of scripts to download additional payloads when compromising network nodes. |
| T1105 Ingress Tool Transfer |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors used a loader to download and execute ransomware. |
| T1105 Ingress Tool Transfer |
CampaignFrankenstein | During Frankenstein, the threat actors downloaded files and tools onto a victim machine. |
| T1105 Ingress Tool Transfer |
CampaignRedPenguin | During RedPenguin, UNC3886 used backdoor malware capable of downloading files to compromised infrastructure. |
| T1105 Ingress Tool Transfer |
CampaignOperation Sharpshooter | During Operation Sharpshooter, additional payloads were downloaded after a target was infected with a first-stage downloader. |
| T1105 Ingress Tool Transfer |
CampaignOperation Honeybee | During Operation Honeybee, the threat actors downloaded additional malware and malicious scripts onto a compromised host. |
| T1105 Ingress Tool Transfer |
CampaignOperation MidnightEclipse | During Operation MidnightEclipse, threat actors downloaded additional payloads on compromised devices. |
| T1105 Ingress Tool Transfer |
Campaign2015 Ukraine Electric Power Attack | During the 2015 Ukraine Electric Power Attack, Sandworm Team pushed additional malicious tools onto an infected system to steal user credentials, move laterally, and destroy data. |
| T1105 Ingress Tool Transfer |
CampaignCutting Edge | During Cutting Edge, threat actors leveraged exploits to download remote files to Ivanti Connect Secure VPNs. |
| T1105 Ingress Tool Transfer |
CampaignC0018 | During C0018, the threat actors downloaded additional tools, such as Mimikatz and Sliver, as well as Cobalt Strike and AvosLocker ransomware onto the victim network. |
| T1105 Ingress Tool Transfer |
CampaignWater Curupira Pikabot Distribution | Water Curupira Pikabot Distribution used Curl.exe to download the Pikabot payload from an external server, saving the file to the victim machine's temporary directory. |
| T1105 Ingress Tool Transfer |
CampaignShadowRay | During ShadowRay, threat actors downloaded and executed the XMRig miner on targeted hosts. |
| T1105 Ingress Tool Transfer |
CampaignC0021 | During C0021, the threat actors downloaded additional tools and files onto victim machines. |
| T1105 Ingress Tool Transfer |
CampaignC0015 | During C0015, the threat actors downloaded additional tools and files onto a compromised network. |
| T1105 Ingress Tool Transfer |
CampaignHomeLand Justice | During HomeLand Justice, threat actors used web shells to download files to compromised infrastructure. |
| T1105 Ingress Tool Transfer |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 downloaded additional malware, such as TEARDROP and Cobalt Strike, onto a compromised host following initial access. |
| T1105 Ingress Tool Transfer |
CampaignFunnyDream | During FunnyDream, the threat actors downloaded additional droppers and backdoors onto a compromised system. |
| T1105 Ingress Tool Transfer |
CampaignOuter Space | During Outer Space, OilRig downloaded additional tools to comrpomised infrastructure. |
| T1105 Ingress Tool Transfer |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries downloaded malicious payloads to the victim server. |
| T1105 Ingress Tool Transfer |
CampaignC0010 | During C0010, UNC3890 actors downloaded tools and malware onto a compromised host. |
| T1105 Ingress Tool Transfer |
CampaignAPT41 DUST | APT41 DUST involved execution of `certutil.exe` via web shell to download the DUSTPAN dropper. |
| T1105 Ingress Tool Transfer |
CampaignNight Dragon | During Night Dragon, threat actors used administrative utilities to deliver Trojan components to remote systems. |
| T1105 Ingress Tool Transfer |
CampaignOperation Wocao | During Operation Wocao, threat actors downloaded additional files to the infected system. |
| T1105 Ingress Tool Transfer |
CampaignC0017 | During C0017, APT41 downloaded malicious payloads onto compromised systems. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.