ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

1146 examples

TechniqueUsed byProcedure example
T1105
Ingress Tool Transfer
CampaignC0026

During C0026, the threat actors downloaded malicious payloads onto select compromised hosts.

T1105
Ingress Tool Transfer
CampaignC0027

During C0027, Scattered Spider downloaded tools using victim organization systems.

T1105
Ingress Tool Transfer
CampaignQuad7 Activity

Quad7 Activity has downloaded additional binaries from a remote File Transfer Protocol (FTP) server to compromised devices.

T1105
Ingress Tool Transfer
CampaignCostaRicto

During CostaRicto, the threat actors downloaded malware and tools onto a compromised host.

T1106
Native API
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group used Windows API `ObtainUserAgentString` to obtain the victim's User-Agent and used the value to connect to their C2 server.

T1106
Native API
CampaignOperation Sharpshooter

During Operation Sharpshooter, the first stage downloader resolved various Windows libraries and APIs, including `LoadLibraryA()`, `GetProcAddress()`, and `CreateProcessA()`.

T1106
Native API
CampaignOperation Honeybee

During Operation Honeybee, the threat actors deployed malware that used API calls, including `CreateProcessAsUser`.

T1106
Native API
CampaignOperation Digital Eye

During Operation Digital Eye, threat actors used native API such as `GetUserInfo`.

T1106
Native API
CampaignOperation Wocao

During Operation Wocao, threat actors used the `CreateProcessA` and `ShellExecute` API functions to launch commands after being injected into a selected process.

T1110
Brute Force
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group performed brute force attacks against administrator accounts.

T1110
Brute Force
Campaign2016 Ukraine Electric Power Attack

During the 2016 Ukraine Electric Power Attack, Sandworm Team used a script to attempt RPC authentication against a number of hosts.

T1110.002
Password Cracking
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries attempted to crack user passwords.

T1110.002
Password Cracking
CampaignNight Dragon

During Night Dragon, threat actors used Cain & Abel to crack password hashes.

T1110.003
Password Spraying
CampaignAPT28 Nearest Neighbor Campaign

During APT28 Nearest Neighbor Campaign, APT28 performed password-spray attacks against public facing services to validate credentials.

T1110.003
Password Spraying
CampaignQuad7 Activity

Quad7 Activity has conducted a throttled variant of password spraying techniques that only utilized a single attempt to sign in within a 24-hour time period, eluding brute force detection thresholds.

T1111
Multi-Factor Authentication Interception
CampaignOperation Wocao

During Operation Wocao, threat actors used a custom collection method to intercept two-factor authentication soft tokens.

T1111
Multi-Factor Authentication Interception
CampaignLeviathan Australian Intrusions

Leviathan abused compromised appliance access to collect multifactor authentication token values during Leviathan Australian Intrusions.

T1112
Modify Registry
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors, including Storm-2603, disabled security services via Registry modifications.

T1112
Modify Registry
CampaignOperation Honeybee

During Operation Honeybee, the threat actors used batch files that modified registry keys.

T1112
Modify Registry
Campaign2015 Ukraine Electric Power Attack

During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching `rundll32.exe`, which in-turn launches the malware and communicates with C2 servers over the Internet. .

T1112
Modify Registry
CampaignNight Dragon

During Night Dragon, threat actors used zwShell to establish full remote control of the connected machine and manipulate the Registry.

T1112
Modify Registry
CampaignOperation Wocao

During Operation Wocao, the threat actors enabled Wdigest by changing the `HKLM\SYSTEM\\ControlSet001\\Control\\SecurityProviders\\WDigest` registry value from 0 (disabled) to 1 (enabled).

T1113
Screen Capture
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries captured screenshots of devices using nircmd console through the command nircmd.exe “savescreenshot C:\Windows\Temp\imagetmp.png.

T1114.001
Local Email Collection
CampaignNight Dragon

During Night Dragon, threat actors used RAT malware to exfiltrate email archives.

T1114.002
Remote Email Collection
CampaignHomeLand Justice

During HomeLand Justice, threat actors made multiple HTTP POST requests to the Exchange servers of the victim organization to transfer data.

T1114.002
Remote Email Collection
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 collected emails from specific individuals, such as executives and IT staff, using `New-MailboxExportRequest` followed by `Get-MailboxExportRequest`.

T1114.002
Remote Email Collection
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries leveraged stolen credentials within cloud services to gather data and email messages from Exchange services related to OT topics and technical work carried out within organizations.

T1115
Clipboard Data
CampaignOperation Wocao

During Operation Wocao, threat actors collected clipboard data in plaintext.

T1119
Automated Collection
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors used a command shell to automatically iterate through web.config files to expose and collect machineKey settings.

T1119
Automated Collection
CampaignFrankenstein

During Frankenstein, the threat actors used Empire to automatically gather the username, domain name, machine name, and other system information.

T1119
Automated Collection
CampaignAnthropic AI-orchestrated Campaign

During the Anthropic AI-orchestrated Campaign, the adversary used Claude Code to automatically collect and process large volumes of data from without human direction.

T1119
Automated Collection
CampaignArcaneDoor

ArcaneDoor included collection of packet capture and system configuration information.

T1119
Automated Collection
CampaignAPT41 DUST

APT41 DUST used tools such as SQLULDR2 and PINEGROVE to gather local system and database information.

T1119
Automated Collection
CampaignOperation Wocao

During Operation Wocao, threat actors used a script to collect information about the infected system.

T1120
Peripheral Device Discovery
CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors used the `fsutil fsinfo drives` command as part of their advanced reconnaissance.

T1120
Peripheral Device Discovery
CampaignOperation Wocao

During Operation Wocao, threat actors discovered removable disks attached to a system.

T1124
System Time Discovery
CampaignC0015

During C0015, the threat actors used the command `net view /all time` to gather the local time of a compromised network.

T1124
System Time Discovery
CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors used the `net time` command as part of their advanced reconnaissance.

T1124
System Time Discovery
CampaignOperation Wocao

During Operation Wocao, threat actors used the `time` command to retrieve the current time of a compromised system.

T1127.001
MSBuild
CampaignFrankenstein

During Frankenstein, the threat actors used MSbuild to execute an actor-created file.

T1127.001
MSBuild
CampaignOperation AkaiRyū

During Operation AkaiRyū, MirrorFace used MSBuild to compile and execute its FaceXInjector injection tool.

T1132.001
Standard Encoding
CampaignJuicy Mix

During Juicy Mix, OilRig used a VBS script to send the Base64-encoded name of the compromised computer to C2.

T1133
External Remote Services
Campaign2015 Ukraine Electric Power Attack

During the 2015 Ukraine Electric Power Attack, Sandworm Team installed a modified Dropbear SSH client as the backdoor to target systems.

T1133
External Remote Services
CampaignC0032

During the C0032 campaign, TEMP.Veles used VPN access to persist in the victim environment.

T1133
External Remote Services
CampaignSolarWinds Compromise

For the SolarWinds Compromise, APT29 used compromised identities to access networks via SSH, VPNs, and other remote access tools.

T1133
External Remote Services
CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors enabled WinRM over HTTP/HTTPS as a backup persistence mechanism using the following command: `cscript //nologo "C:\Windows\System32\winrm.vbs" set winrm/config/service@{EnableCompatibilityHttpsListener="true"}`.

T1133
External Remote Services
CampaignArcaneDoor

ArcaneDoor used WebVPN sessions commonly associated with Clientless SSLVPN services to communicate to compromised devices.

T1133
External Remote Services
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, threat actors leveraged the FortiGate VPN interface that was exposed to the internet to gain access to the victim environment.

T1133
External Remote Services
CampaignNight Dragon

During Night Dragon, threat actors used compromised VPN accounts to gain access to victim systems.

T1133
External Remote Services
CampaignOperation Wocao

During Operation Wocao, threat actors used stolen credentials to connect to the victim's network via VPN.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.