Real-world descriptions of how a group, tool or campaign used a technique.
1146 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1105 Ingress Tool Transfer |
CampaignC0026 | During C0026, the threat actors downloaded malicious payloads onto select compromised hosts. |
| T1105 Ingress Tool Transfer |
CampaignC0027 | During C0027, Scattered Spider downloaded tools using victim organization systems. |
| T1105 Ingress Tool Transfer |
CampaignQuad7 Activity | Quad7 Activity has downloaded additional binaries from a remote File Transfer Protocol (FTP) server to compromised devices. |
| T1105 Ingress Tool Transfer |
CampaignCostaRicto | During CostaRicto, the threat actors downloaded malware and tools onto a compromised host. |
| T1106 Native API |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group used Windows API `ObtainUserAgentString` to obtain the victim's User-Agent and used the value to connect to their C2 server. |
| T1106 Native API |
CampaignOperation Sharpshooter | During Operation Sharpshooter, the first stage downloader resolved various Windows libraries and APIs, including `LoadLibraryA()`, `GetProcAddress()`, and `CreateProcessA()`. |
| T1106 Native API |
CampaignOperation Honeybee | During Operation Honeybee, the threat actors deployed malware that used API calls, including `CreateProcessAsUser`. |
| T1106 Native API |
CampaignOperation Digital Eye | During Operation Digital Eye, threat actors used native API such as `GetUserInfo`. |
| T1106 Native API |
CampaignOperation Wocao | During Operation Wocao, threat actors used the `CreateProcessA` and `ShellExecute` API functions to launch commands after being injected into a selected process. |
| T1110 Brute Force |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group performed brute force attacks against administrator accounts. |
| T1110 Brute Force |
Campaign2016 Ukraine Electric Power Attack | During the 2016 Ukraine Electric Power Attack, Sandworm Team used a script to attempt RPC authentication against a number of hosts. |
| T1110.002 Password Cracking |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries attempted to crack user passwords. |
| T1110.002 Password Cracking |
CampaignNight Dragon | During Night Dragon, threat actors used Cain & Abel to crack password hashes. |
| T1110.003 Password Spraying |
CampaignAPT28 Nearest Neighbor Campaign | During APT28 Nearest Neighbor Campaign, APT28 performed password-spray attacks against public facing services to validate credentials. |
| T1110.003 Password Spraying |
CampaignQuad7 Activity | Quad7 Activity has conducted a throttled variant of password spraying techniques that only utilized a single attempt to sign in within a 24-hour time period, eluding brute force detection thresholds. |
| T1111 Multi-Factor Authentication Interception |
CampaignOperation Wocao | During Operation Wocao, threat actors used a custom collection method to intercept two-factor authentication soft tokens. |
| T1111 Multi-Factor Authentication Interception |
CampaignLeviathan Australian Intrusions | Leviathan abused compromised appliance access to collect multifactor authentication token values during Leviathan Australian Intrusions. |
| T1112 Modify Registry |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors, including Storm-2603, disabled security services via Registry modifications. |
| T1112 Modify Registry |
CampaignOperation Honeybee | During Operation Honeybee, the threat actors used batch files that modified registry keys. |
| T1112 Modify Registry |
Campaign2015 Ukraine Electric Power Attack | During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching `rundll32.exe`, which in-turn launches the malware and communicates with C2 servers over the Internet. . |
| T1112 Modify Registry |
CampaignNight Dragon | During Night Dragon, threat actors used zwShell to establish full remote control of the connected machine and manipulate the Registry. |
| T1112 Modify Registry |
CampaignOperation Wocao | During Operation Wocao, the threat actors enabled Wdigest by changing the `HKLM\SYSTEM\\ControlSet001\\Control\\SecurityProviders\\WDigest` registry value from 0 (disabled) to 1 (enabled). |
| T1113 Screen Capture |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries captured screenshots of devices using |
| T1114.001 Local Email Collection |
CampaignNight Dragon | During Night Dragon, threat actors used RAT malware to exfiltrate email archives. |
| T1114.002 Remote Email Collection |
CampaignHomeLand Justice | During HomeLand Justice, threat actors made multiple HTTP POST requests to the Exchange servers of the victim organization to transfer data. |
| T1114.002 Remote Email Collection |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 collected emails from specific individuals, such as executives and IT staff, using `New-MailboxExportRequest` followed by `Get-MailboxExportRequest`. |
| T1114.002 Remote Email Collection |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries leveraged stolen credentials within cloud services to gather data and email messages from Exchange services related to OT topics and technical work carried out within organizations. |
| T1115 Clipboard Data |
CampaignOperation Wocao | During Operation Wocao, threat actors collected clipboard data in plaintext. |
| T1119 Automated Collection |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors used a command shell to automatically iterate through web.config files to expose and collect machineKey settings. |
| T1119 Automated Collection |
CampaignFrankenstein | During Frankenstein, the threat actors used Empire to automatically gather the username, domain name, machine name, and other system information. |
| T1119 Automated Collection |
CampaignAnthropic AI-orchestrated Campaign | During the Anthropic AI-orchestrated Campaign, the adversary used Claude Code to automatically collect and process large volumes of data from without human direction. |
| T1119 Automated Collection |
CampaignArcaneDoor | ArcaneDoor included collection of packet capture and system configuration information. |
| T1119 Automated Collection |
CampaignAPT41 DUST | APT41 DUST used tools such as SQLULDR2 and PINEGROVE to gather local system and database information. |
| T1119 Automated Collection |
CampaignOperation Wocao | During Operation Wocao, threat actors used a script to collect information about the infected system. |
| T1120 Peripheral Device Discovery |
CampaignOperation CuckooBees | During Operation CuckooBees, the threat actors used the `fsutil fsinfo drives` command as part of their advanced reconnaissance. |
| T1120 Peripheral Device Discovery |
CampaignOperation Wocao | During Operation Wocao, threat actors discovered removable disks attached to a system. |
| T1124 System Time Discovery |
CampaignC0015 | During C0015, the threat actors used the command `net view /all time` to gather the local time of a compromised network. |
| T1124 System Time Discovery |
CampaignOperation CuckooBees | During Operation CuckooBees, the threat actors used the `net time` command as part of their advanced reconnaissance. |
| T1124 System Time Discovery |
CampaignOperation Wocao | During Operation Wocao, threat actors used the `time` command to retrieve the current time of a compromised system. |
| T1127.001 MSBuild |
CampaignFrankenstein | During Frankenstein, the threat actors used MSbuild to execute an actor-created file. |
| T1127.001 MSBuild |
CampaignOperation AkaiRyū | During Operation AkaiRyū, MirrorFace used MSBuild to compile and execute its FaceXInjector injection tool. |
| T1132.001 Standard Encoding |
CampaignJuicy Mix | During Juicy Mix, OilRig used a VBS script to send the Base64-encoded name of the compromised computer to C2. |
| T1133 External Remote Services |
Campaign2015 Ukraine Electric Power Attack | During the 2015 Ukraine Electric Power Attack, Sandworm Team installed a modified Dropbear SSH client as the backdoor to target systems. |
| T1133 External Remote Services |
CampaignC0032 | During the C0032 campaign, TEMP.Veles used VPN access to persist in the victim environment. |
| T1133 External Remote Services |
CampaignSolarWinds Compromise | For the SolarWinds Compromise, APT29 used compromised identities to access networks via SSH, VPNs, and other remote access tools. |
| T1133 External Remote Services |
CampaignOperation CuckooBees | During Operation CuckooBees, the threat actors enabled WinRM over HTTP/HTTPS as a backup persistence mechanism using the following command: `cscript //nologo "C:\Windows\System32\winrm.vbs" set winrm/config/service@{EnableCompatibilityHttpsListener="true"}`. |
| T1133 External Remote Services |
CampaignArcaneDoor | ArcaneDoor used WebVPN sessions commonly associated with Clientless SSLVPN services to communicate to compromised devices. |
| T1133 External Remote Services |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, threat actors leveraged the FortiGate VPN interface that was exposed to the internet to gain access to the victim environment. |
| T1133 External Remote Services |
CampaignNight Dragon | During Night Dragon, threat actors used compromised VPN accounts to gain access to victim systems. |
| T1133 External Remote Services |
CampaignOperation Wocao | During Operation Wocao, threat actors used stolen credentials to connect to the victim's network via VPN. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.