ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

1146 examples

TechniqueUsed byProcedure example
T1095
Non-Application Layer Protocol
CampaignCutting Edge

During Cutting Edge, threat actors used the Unix socket and a reverse TCP shell for C2 communications.

T1095
Non-Application Layer Protocol
CampaignC0021

During C0021, the threat actors used TCP for some C2 communications.

T1095
Non-Application Layer Protocol
CampaignVersa Director Zero Day Exploitation

Versa Director Zero Day Exploitation used a non-standard TCP session to initialize communication prior to establishing HTTPS command and control.

T1095
Non-Application Layer Protocol
CampaignOperation Wocao

During Operation Wocao, threat actors used a custom protocol for command and control.

T1095
Non-Application Layer Protocol
Campaign2022 Ukraine Electric Power Attack

During the 2022 Ukraine Electric Power Attack, Sandworm Team proxied C2 communications within a TLS-based tunnel.

T1098
Account Manipulation
Campaign2016 Ukraine Electric Power Attack

During the 2016 Ukraine Electric Power Attack, Sandworm Team used the `sp_addlinkedsrvlogin` command in MS-SQL to create a link between a created account and other servers in the network.

T1098.001
Additional Cloud Credentials
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 added credentials to OAuth Applications and Service Principals.

T1098.001
Additional Cloud Credentials
CampaignC0027

During C0027, Scattered Spider used aws_consoler to create temporary federated credentials for fake users in order to obfuscate which AWS credential is compromised and enable pivoting from the AWS CLI to console sessions without MFA.

T1098.002
Additional Email Delegate Permissions
CampaignHomeLand Justice

During HomeLand Justice, threat actors added the `ApplicationImpersonation` management role to accounts under their control to impersonate users and take ownership of targeted mailboxes.

T1098.002
Additional Email Delegate Permissions
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 added their own devices as allowed IDs for active sync using `Set-CASMailbox`, allowing it to obtain copies of victim mailboxes. It also added additional permissions (such as Mail.Read and Mail.ReadWrite) to compromised Application or Service Principals.

T1098.003
Additional Cloud Roles
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 granted `company administrator` privileges to a newly created service principle.

T1098.003
Additional Cloud Roles
CampaignC0027

During C0027, Scattered Spider used IAM manipulation to gain persistence and to assume or elevate privileges.

T1098.004
SSH Authorized Keys
CampaignOperation Digital Eye

During Operation Digital Eye, threat actors used SSH access enabled by authorized_keys files for remote execution.

T1098.005
Device Registration
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 registered devices in order to enable mailbox syncing via the `Set-CASMailbox` command.

T1098.005
Device Registration
CampaignC0027

During C0027, Scattered Spider registered devices for MFA to maintain persistence through victims' VPN.

T1102
Web Service
CampaignOperation Spalax

During Operation Spalax, the threat actors used OneDrive and MediaFire to host payloads.

T1102
Web Service
CampaignAPT41 DUST

APT41 DUST used compromised Google Workspace accounts for command and control.

T1102
Web Service
CampaignC0017

During C0017, APT41 used the Cloudflare services for C2 communications.

T1102
Web Service
CampaignC0027

During C0027, Scattered Spider downloaded tools from sites including file.io, GitHub, and paste.ee.

T1102.001
Dead Drop Resolver
Campaign3CX Supply Chain Attack

During the 3CX Supply Chain Attack, AppleJeus leveraged a GitHub repository to host icon files containing the command and control URL.

T1102.001
Dead Drop Resolver
CampaignC0017

During C0017, APT41 used dead drop resolvers on two separate tech community forums for their KEYPLUG Windows-version backdoor; notably APT41 updated the community forum posts frequently with new dead drop resolvers during the campaign.

T1102.002
Bidirectional Communication
CampaignOperation Ghost

For Operation Ghost, APT29 used social media platforms to hide communications to C2 servers.

T1102.002
Bidirectional Communication
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries had communicated to both Dropbox and Pastebin.

T1102.003
One-Way Communication
CampaignArcaneDoor

ArcaneDoor utilized HTTP command and control traffic where commands are intercepted from HTTP traffic to the device, parsed for appropriate identifiers and commands, and then executed.

T1104
Multi-Stage Channels
CampaignRedPenguin

During RedPenguin, UNC3886 used malware with separate channels to request and carry out tasks from C2.

T1105
Ingress Tool Transfer
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group downloaded multistage malware and tools onto a compromised host.

T1105
Ingress Tool Transfer
CampaignKV Botnet Activity

KV Botnet Activity included the use of scripts to download additional payloads when compromising network nodes.

T1105
Ingress Tool Transfer
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors used a loader to download and execute ransomware.

T1105
Ingress Tool Transfer
CampaignFrankenstein

During Frankenstein, the threat actors downloaded files and tools onto a victim machine.

T1105
Ingress Tool Transfer
CampaignRedPenguin

During RedPenguin, UNC3886 used backdoor malware capable of downloading files to compromised infrastructure.

T1105
Ingress Tool Transfer
CampaignOperation Sharpshooter

During Operation Sharpshooter, additional payloads were downloaded after a target was infected with a first-stage downloader.

T1105
Ingress Tool Transfer
CampaignOperation Honeybee

During Operation Honeybee, the threat actors downloaded additional malware and malicious scripts onto a compromised host.

T1105
Ingress Tool Transfer
CampaignOperation MidnightEclipse

During Operation MidnightEclipse, threat actors downloaded additional payloads on compromised devices.

T1105
Ingress Tool Transfer
Campaign2015 Ukraine Electric Power Attack

During the 2015 Ukraine Electric Power Attack, Sandworm Team pushed additional malicious tools onto an infected system to steal user credentials, move laterally, and destroy data.

T1105
Ingress Tool Transfer
CampaignCutting Edge

During Cutting Edge, threat actors leveraged exploits to download remote files to Ivanti Connect Secure VPNs.

T1105
Ingress Tool Transfer
CampaignC0018

During C0018, the threat actors downloaded additional tools, such as Mimikatz and Sliver, as well as Cobalt Strike and AvosLocker ransomware onto the victim network.

T1105
Ingress Tool Transfer
CampaignWater Curupira Pikabot Distribution

Water Curupira Pikabot Distribution used Curl.exe to download the Pikabot payload from an external server, saving the file to the victim machine's temporary directory.

T1105
Ingress Tool Transfer
CampaignShadowRay

During ShadowRay, threat actors downloaded and executed the XMRig miner on targeted hosts.

T1105
Ingress Tool Transfer
CampaignC0021

During C0021, the threat actors downloaded additional tools and files onto victim machines.

T1105
Ingress Tool Transfer
CampaignC0015

During C0015, the threat actors downloaded additional tools and files onto a compromised network.

T1105
Ingress Tool Transfer
CampaignHomeLand Justice

During HomeLand Justice, threat actors used web shells to download files to compromised infrastructure.

T1105
Ingress Tool Transfer
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 downloaded additional malware, such as TEARDROP and Cobalt Strike, onto a compromised host following initial access.

T1105
Ingress Tool Transfer
CampaignFunnyDream

During FunnyDream, the threat actors downloaded additional droppers and backdoors onto a compromised system.

T1105
Ingress Tool Transfer
CampaignOuter Space

During Outer Space, OilRig downloaded additional tools to comrpomised infrastructure.

T1105
Ingress Tool Transfer
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries downloaded malicious payloads to the victim server.

T1105
Ingress Tool Transfer
CampaignC0010

During C0010, UNC3890 actors downloaded tools and malware onto a compromised host.

T1105
Ingress Tool Transfer
CampaignAPT41 DUST

APT41 DUST involved execution of `certutil.exe` via web shell to download the DUSTPAN dropper.

T1105
Ingress Tool Transfer
CampaignNight Dragon

During Night Dragon, threat actors used administrative utilities to deliver Trojan components to remote systems.

T1105
Ingress Tool Transfer
CampaignOperation Wocao

During Operation Wocao, threat actors downloaded additional files to the infected system.

T1105
Ingress Tool Transfer
CampaignC0017

During C0017, APT41 downloaded malicious payloads onto compromised systems.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.