ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

1146 examples

TechniqueUsed byProcedure example
T1133
External Remote Services
CampaignC0027

During C0027, Scattered Spider used Citrix and VPNs to persist in compromised environments.

T1133
External Remote Services
CampaignCostaRicto

During CostaRicto, the threat actors set up remote tunneling using an SSH tool to maintain access to a compromised environment.

T1134
Access Token Manipulation
CampaignC0017

During C0017, APT41 used a ConfuserEx obfuscated BADPOTATO exploit to abuse named-pipe impersonation for local `NT AUTHORITY\SYSTEM` privilege escalation.

T1134.001
Token Impersonation/Theft
CampaignHomeLand Justice

During HomeLand Justice, threat actors used custom tooling to acquire tokens using `ImpersonateLoggedOnUser/SetThreadToken`.

T1135
Network Share Discovery
CampaignC0015

During C0015, the threat actors executed the PowerView ShareFinder module to identify open shares.

T1135
Network Share Discovery
CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors used the `net share` command as part of their advanced reconnaissance.

T1135
Network Share Discovery
CampaignOperation Wocao

During Operation Wocao, threat actors discovered network disks mounted to the system using netstat.

T1135
Network Share Discovery
CampaignLeviathan Australian Intrusions

Leviathan scanned and enumerated remote network shares in victim environments during Leviathan Australian Intrusions.

T1136
Create Account
Campaign2016 Ukraine Electric Power Attack

During the 2016 Ukraine Electric Power Attack, Sandworm Team added a login to a SQL Server with `sp_addlinkedsrvlogin`.

T1136.001
Local Account
CampaignAnthropic AI-orchestrated Campaign

During the Anthropic AI-orchestrated Campaign, the adversary used Claude Code to create a local backdoor account to maintain access.

T1136.002
Domain Account
Campaign2015 Ukraine Electric Power Attack

During the 2015 Ukraine Electric Power Attack, Sandworm Team created privileged domain accounts to be used for further exploitation and lateral movement.

T1136.002
Domain Account
Campaign2016 Ukraine Electric Power Attack

During the 2016 Ukraine Electric Power Attack, Sandworm Team created two new accounts, “admin” and “система” (System). The accounts were then assigned to a domain matching local operation and were delegated new privileges.

T1137.001
Office Template Macros
CampaignOperation AkaiRyū

During Operation AkaiRyū, MirrorFace loaded malicious Word templates containing VBA code leading to installation of UPPERCUT.

T1140
Deobfuscate/Decode Files or Information
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors decrypted scripts prior to execution.

T1140
Deobfuscate/Decode Files or Information
CampaignFrankenstein

During Frankenstein, the threat actors deobfuscated Base64-encoded commands following the execution of a malicious script, which revealed a small script designed to obtain an additional payload.

T1140
Deobfuscate/Decode Files or Information
CampaignRedPenguin

During RedPenguin, UNC3886 used malware implants to deobfuscate incoming C2 messages and encoded archives.

T1140
Deobfuscate/Decode Files or Information
CampaignOperation Honeybee

During Operation Honeybee, malicious files were decoded prior to execution.

T1140
Deobfuscate/Decode Files or Information
CampaignOperation Dust Storm

During Operation Dust Storm, attackers used VBS code to decode payloads.

T1140
Deobfuscate/Decode Files or Information
CampaignOperation Spalax

For Operation Spalax, the threat actors used a variety of packers and droppers to decrypt malicious payloads.

T1140
Deobfuscate/Decode Files or Information
CampaignWater Curupira Pikabot Distribution

Water Curupira Pikabot Distribution used highly obfuscated JavaScript files as one initial installer for Pikabot.

T1140
Deobfuscate/Decode Files or Information
CampaignC0021

During C0021, the threat actors deobfuscated encoded PowerShell commands including use of the specific string `'FromBase'+0x40+'String'`, in place of `FromBase64String` which is normally used to decode base64.

T1140
Deobfuscate/Decode Files or Information
CampaignJuicy Mix

During Juicy Mix, OilRig used a script to concatenate and deobfuscate encoded strings in Mango.

T1140
Deobfuscate/Decode Files or Information
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used 7-Zip to decode their Raindrop malware.

T1140
Deobfuscate/Decode Files or Information
CampaignAPT28 Nearest Neighbor Campaign

During APT28 Nearest Neighbor Campaign, APT28 unarchived data using the GUI version of WinRAR.

T1140
Deobfuscate/Decode Files or Information
CampaignArcaneDoor

ArcaneDoor involved the use of Base64 obfuscated scripts and commands.

T1140
Deobfuscate/Decode Files or Information
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries decoded a Base64-encoded ZIP archive using the built-in certutil.

T1140
Deobfuscate/Decode Files or Information
CampaignC0017

During C0017, APT41 used the DUSTPAN loader to decrypt embedded payloads.

T1189
Drive-by Compromise
CampaignOperation Dust Storm

During Operation Dust Storm, the threat actors used a watering hole attack on a popular software reseller to exploit the then-zero-day Internet Explorer vulnerability CVE-2014-0322.

T1189
Drive-by Compromise
Campaign3CX Supply Chain Attack

During the 3CX Supply Chain Attack, AppleJeus compromised the `www.tradingtechnologies[.]com` website hosting a hidden IFRAME to exploit visitors, two months before the site was known to deliver a compromised version of the X_TRADER software package.

T1189
Drive-by Compromise
CampaignC0010

During C0010, UNC3890 actors likely established a watering hole that was hosted on a login page of a legitimate Israeli shipping company that was active until at least November 2021.

T1190
Exploit Public-Facing Application
CampaignFrostyGoop Incident

FrostyGoop Incident was likely enabled by the adversary exploiting an unknown vulnerability in an external-facing router.

T1190
Exploit Public-Facing Application
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors exploited authentication bypass and remote code execution vulnerabilities (CVE-2025-49706 and CVE-2025-49704) against on-premises SharePoint servers. This activity was characterized by crafted `POST` requests to the ToolPane endpoint `/_layouts/15/ToolPane.aspx`.

T1190
Exploit Public-Facing Application
CampaignOperation MidnightEclipse

During Operation MidnightEclipse, threat actors exploited CVE-2024-3400 in Palo Alto Networks GlobalProtect.

T1190
Exploit Public-Facing Application
CampaignCutting Edge

During Cutting Edge, threat actors exploited CVE-2023-46805 and CVE-2024-21887 in Ivanti Connect Secure VPN appliances to enable authentication bypass and command injection. A server-side request forgery (SSRF) vulnerability, CVE-2024-21893, was identified later and used to bypass mitigations for the initial two vulnerabilities by chaining with CVE-2024-21887.

T1190
Exploit Public-Facing Application
CampaignC0018

During C0018, the threat actors exploited VMWare Horizon Unified Access Gateways that were vulnerable to several Log4Shell vulnerabilities, including CVE-2021-44228, CVE-2021-45046, CVE-2021-45105, and CVE-2021-44832.

T1190
Exploit Public-Facing Application
CampaignShadowRay

During ShadowRay, threat actors exploited CVE-2023-48022 on publicly exposed Ray servers to steal computing power and to expose sensitive data.

T1190
Exploit Public-Facing Application
CampaignAnthropic AI-orchestrated Campaign

During the Anthropic AI-orchestrated Campaign, the adversary used Claude Code to deploy a custom exploit payload targeting an identified SSRF vulnerability to gain initial access to a targeted environment.

T1190
Exploit Public-Facing Application
CampaignOperation Digital Eye

During Operation Digital Eye, threat actors used SQL injection to compromise publicly exposed web and database servers.

T1190
Exploit Public-Facing Application
CampaignHomeLand Justice

For HomeLand Justice, threat actors exploited CVE-2019-0604 in Microsoft SharePoint for initial access.

T1190
Exploit Public-Facing Application
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 exploited CVE-2020-0688 against the Microsoft Exchange Control Panel to regain access to a network.

T1190
Exploit Public-Facing Application
CampaignSPACEHOP Activity

SPACEHOP Activity has enabled the exploitation of CVE-2022-27518 and CVE-2022-27518 for illegitimate access.

T1190
Exploit Public-Facing Application
CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors exploited multiple vulnerabilities in externally facing servers.

T1190
Exploit Public-Facing Application
CampaignArcaneDoor

ArcaneDoor abused WebVPN traffic to targeted devices to achieve unauthorized remote code execution.

T1190
Exploit Public-Facing Application
CampaignNight Dragon

During Night Dragon, threat actors used SQL injection exploits against extranet web servers to gain access.

T1190
Exploit Public-Facing Application
CampaignVersa Director Zero Day Exploitation

Versa Director Zero Day Exploitation involved exploitation of a vulnerability in Versa Director servers, since identified as CVE-2024-39717, for initial access and code execution.

T1190
Exploit Public-Facing Application
CampaignOperation Wocao

During Operation Wocao, threat actors gained initial access by exploiting vulnerabilities in JBoss webservers.

T1190
Exploit Public-Facing Application
CampaignLeviathan Australian Intrusions

Leviathan exploited public-facing web applications and appliances for initial access during Leviathan Australian Intrusions.

T1190
Exploit Public-Facing Application
CampaignC0017

During C0017, APT41 exploited CVE-2021-44207 in the USAHerds application and CVE-2021-44228 in Log4j, as well as other .NET deserialization, SQL injection, and directory traversal vulnerabilities to gain initial access.

T1190
Exploit Public-Facing Application
CampaignC0027

During C0027, Scattered Spider exploited CVE-2021-35464 in the ForgeRock Open Access Management (OpenAM) application server to gain initial access.

T1190
Exploit Public-Facing Application
CampaignQuad7 Activity

Quad7 Activity has enabled the exploitation of vulnerabilities for remote code execution capabilities in SOHO routers including CVE-2023-50224 and CVE-2025-9377 in TP-Link devices.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.