ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1059.008
Network Device CLI
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries leveraged the native CLI of the targeted FortiGate device.

T1059.008
Network Device CLI
MalwareLine Dancer

Line Dancer can execute native commands in networking device command line interfaces.

T1059.008
Network Device CLI
MalwarePHASEJAM

PHASEJAM has leveraged native commands associated with the compromised network appliance to execute code.

T1059.008
Network Device CLI
MalwareDRYHOOK

DRYHOOK has the ability to interact with Ivanti Connect Secure environments and to modify system components.

T1059.009
Cloud API
GroupTeamTNT

TeamTNT has leveraged AWS CLI to enumerate cloud environments with compromised credentials.

T1059.009
Cloud API
GroupStorm-0501

Storm-0501 has leveraged Cloud CLI to execute commands and exfiltrate data from compromised environments.

T1059.009
Cloud API
GroupAPT29

APT29 has leveraged the Microsoft Graph API to perform various actions across Azure and M365 environments. They have also utilized AADInternals PowerShell Modules to access the API

T1059.009
Cloud API
ToolPacu

Pacu leverages the AWS CLI for its operations.

T1059.009
Cloud API
ToolTruffleHog

TruffleHog has leveraged Cloud CLI in order to enumerate and gather credentials.

T1059.009
Cloud API
GroupShinyHunters

ShinyHunters has used the AWS Command Line Interface (CLI) for operations to include a variety of API calls, such as `ListBuckets`, `CreateBucket` and `DeleteBucket`.

T1059.010
AutoHotKey & AutoIT
GroupAPT39

APT39 has utilized AutoIt malware scripts embedded in Microsoft Office documents or malicious links.

T1059.010
AutoHotKey & AutoIT
MalwareLumma Stealer

Lumma Stealer has utilized AutoIt malware scripts and AutoIt executables.

T1059.010
AutoHotKey & AutoIT
MalwareDarkGate

DarkGate uses AutoIt scripts dropped to a hidden directory during initial installation phases, such as `test.au3`.

T1059.010
AutoHotKey & AutoIT
MalwareXLoader

XLoader can use an AutoIT script to decrypt a payload file, load it into victim memory, then execute it on the victim machine.

T1059.010
AutoHotKey & AutoIT
MalwareOutSteel

OutSteel was developed using the AutoIT scripting language.

T1059.010
AutoHotKey & AutoIT
MalwareMelcoz

Melcoz has been distributed through an AutoIt loader script.

T1059.011
Lua
MalwareLine Runner

Line Runner utilizes Lua scripts for command execution.

T1059.011
Lua
MalwareRemsec

Remsec can use modules written in Lua for execution.

T1059.011
Lua
MalwareRedLine Stealer

RedLine Stealer malware has leveraged Lua bytecode to perform malicious behavior.

T1059.011
Lua
MalwareEvilBunny

EvilBunny has used Lua scripts to execute payloads.

T1059.011
Lua
MalwarePoetRAT

PoetRAT has executed a Lua script through a Lua interpreter for Windows.

T1059.012
Hypervisor CLI
GroupUNC3886

UNC3886 has used the esxcli command line utility to modify firewall rules, install malware, and for artifact removal.

T1059.012
Hypervisor CLI
MalwareCheerscrypt

Cheerscrypt has leveraged `esxcli` in order to terminate running virtual machines.

T1059.012
Hypervisor CLI
MalwareVIRTUALPIE

VIRTUALPIE is capable of command line execution on compromised ESXi servers.

T1059.012
Hypervisor CLI
MalwareRoyal

Royal ransomware uses `esxcli` to gather a list of running VMs and terminate them.

T1059.013
Container CLI/API
GroupTeamTNT

TeamTNT targeted misconfigured containers and used container CLI tools.

T1059.013
Container CLI/API
MalwareMini Shai-Hulud

Mini Shai-Hulud has utilized the Docker command-line tool to gather details of the victim environment and collect credentials.

T1059.013
Container CLI/API
GroupTeamPCP

TeamPCP has queried the Kubernetes API for local service account tokens and has used `kubectl` for lateral movement.

T1068
Exploitation for Privilege Escalation
CampaignShadowRay

During ShadowRay, threat actors downloaded a privilege escalation payload to gain root access.

T1068
Exploitation for Privilege Escalation
CampaignLeviathan Australian Intrusions

Leviathan exploited software vulnerabilities in victim environments to escalate privileges during Leviathan Australian Intrusions.

T1068
Exploitation for Privilege Escalation
GroupBlackByte

BlackByte has exploited CVE-2024-37085 in VMWare ESXi software for authentication bypass and subsequent privilege escalation.

T1068
Exploitation for Privilege Escalation
GroupVolt Typhoon

Volt Typhoon has gained initial access by exploiting privilege escalation vulnerabilities in the operating system or network services.

T1068
Exploitation for Privilege Escalation
GroupAPT32

APT32 has used CVE-2016-7255 to escalate privileges.

T1068
Exploitation for Privilege Escalation
GroupHAFNIUM

HAFNIUM has targeted unpatched applications to elevate access in targeted organizations.

T1068
Exploitation for Privilege Escalation
GroupFIN6

FIN6 has used tools to exploit Windows vulnerabilities in order to escalate privileges. The tools targeted CVE-2013-3660, CVE-2011-2005, and CVE-2010-4398, all of which could allow local users to access kernel-level privileges.

T1068
Exploitation for Privilege Escalation
GroupZIRCONIUM

ZIRCONIUM has exploited CVE-2017-0005 for local privilege escalation.

T1068
Exploitation for Privilege Escalation
GroupScattered Spider

Scattered Spider has deployed a malicious kernel driver through exploitation of CVE-2015-2291 in the Intel Ethernet diagnostics driver for Windows (iqvw64.sys).

T1068
Exploitation for Privilege Escalation
GroupUNC3886

UNC3886 has exploited zero-day vulnerability CVE-2023-20867 to enable execution of privileged commands across Windows, Linux, and PhotonOS (vCenter) guest VMs.

T1068
Exploitation for Privilege Escalation
GroupOilRig

OilRig has exploited the Windows Kernel Elevation of Privilege vulnerability, CVE-2024-30088.

T1068
Exploitation for Privilege Escalation
GroupMoustachedBouncer

MoustachedBouncer has exploited CVE-2021-1732 to execute malware components with elevated rights.

T1068
Exploitation for Privilege Escalation
GroupTurla

Turla has exploited vulnerabilities in the VBoxDrv.sys driver to obtain kernel mode privileges.

T1068
Exploitation for Privilege Escalation
GroupBITTER

BITTER has exploited CVE-2021-1732 for privilege escalation.

T1068
Exploitation for Privilege Escalation
GroupAPT29

APT29 has exploited CVE-2021-36934 to escalate privileges on a compromised host.

T1068
Exploitation for Privilege Escalation
GroupWhitefly

Whitefly has used an open-source tool to exploit a known Windows privilege escalation vulnerability (CVE-2016-0051) on unpatched computers.

T1068
Exploitation for Privilege Escalation
GroupAPT28

APT28 has exploited CVE-2014-4076, CVE-2015-2387, CVE-2015-1701, CVE-2017-0263, and CVE-2022-38028 to escalate privileges.

T1068
Exploitation for Privilege Escalation
GroupTonto Team

Tonto Team has exploited CVE-2019-0803 and MS16-032 to escalate privileges.

T1068
Exploitation for Privilege Escalation
GroupLAPSUS$

LAPSUS$ has exploited unpatched vulnerabilities on internally accessible servers including JIRA, GitLab, and Confluence for privilege escalation.

T1068
Exploitation for Privilege Escalation
GroupCobalt Group

Cobalt Group has used exploits to increase their levels of rights and privileges.

T1068
Exploitation for Privilege Escalation
GroupPLATINUM

PLATINUM has leveraged a zero-day vulnerability to escalate privileges.

T1068
Exploitation for Privilege Escalation
GroupThreat Group-3390

Threat Group-3390 has used CVE-2014-6324 and CVE-2017-0213 to escalate privileges.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.