Real-world descriptions of how a group, tool or campaign used a technique.
1146 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1133 External Remote Services |
CampaignC0027 | During C0027, Scattered Spider used Citrix and VPNs to persist in compromised environments. |
| T1133 External Remote Services |
CampaignCostaRicto | During CostaRicto, the threat actors set up remote tunneling using an SSH tool to maintain access to a compromised environment. |
| T1134 Access Token Manipulation |
CampaignC0017 | During C0017, APT41 used a ConfuserEx obfuscated BADPOTATO exploit to abuse named-pipe impersonation for local `NT AUTHORITY\SYSTEM` privilege escalation. |
| T1134.001 Token Impersonation/Theft |
CampaignHomeLand Justice | During HomeLand Justice, threat actors used custom tooling to acquire tokens using `ImpersonateLoggedOnUser/SetThreadToken`. |
| T1135 Network Share Discovery |
CampaignC0015 | During C0015, the threat actors executed the PowerView ShareFinder module to identify open shares. |
| T1135 Network Share Discovery |
CampaignOperation CuckooBees | During Operation CuckooBees, the threat actors used the `net share` command as part of their advanced reconnaissance. |
| T1135 Network Share Discovery |
CampaignOperation Wocao | During Operation Wocao, threat actors discovered network disks mounted to the system using netstat. |
| T1135 Network Share Discovery |
CampaignLeviathan Australian Intrusions | Leviathan scanned and enumerated remote network shares in victim environments during Leviathan Australian Intrusions. |
| T1136 Create Account |
Campaign2016 Ukraine Electric Power Attack | During the 2016 Ukraine Electric Power Attack, Sandworm Team added a login to a SQL Server with `sp_addlinkedsrvlogin`. |
| T1136.001 Local Account |
CampaignAnthropic AI-orchestrated Campaign | During the Anthropic AI-orchestrated Campaign, the adversary used Claude Code to create a local backdoor account to maintain access. |
| T1136.002 Domain Account |
Campaign2015 Ukraine Electric Power Attack | During the 2015 Ukraine Electric Power Attack, Sandworm Team created privileged domain accounts to be used for further exploitation and lateral movement. |
| T1136.002 Domain Account |
Campaign2016 Ukraine Electric Power Attack | During the 2016 Ukraine Electric Power Attack, Sandworm Team created two new accounts, “admin” and “система” (System). The accounts were then assigned to a domain matching local operation and were delegated new privileges. |
| T1137.001 Office Template Macros |
CampaignOperation AkaiRyū | During Operation AkaiRyū, MirrorFace loaded malicious Word templates containing VBA code leading to installation of UPPERCUT. |
| T1140 Deobfuscate/Decode Files or Information |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors decrypted scripts prior to execution. |
| T1140 Deobfuscate/Decode Files or Information |
CampaignFrankenstein | During Frankenstein, the threat actors deobfuscated Base64-encoded commands following the execution of a malicious script, which revealed a small script designed to obtain an additional payload. |
| T1140 Deobfuscate/Decode Files or Information |
CampaignRedPenguin | During RedPenguin, UNC3886 used malware implants to deobfuscate incoming C2 messages and encoded archives. |
| T1140 Deobfuscate/Decode Files or Information |
CampaignOperation Honeybee | During Operation Honeybee, malicious files were decoded prior to execution. |
| T1140 Deobfuscate/Decode Files or Information |
CampaignOperation Dust Storm | During Operation Dust Storm, attackers used VBS code to decode payloads. |
| T1140 Deobfuscate/Decode Files or Information |
CampaignOperation Spalax | For Operation Spalax, the threat actors used a variety of packers and droppers to decrypt malicious payloads. |
| T1140 Deobfuscate/Decode Files or Information |
CampaignWater Curupira Pikabot Distribution | Water Curupira Pikabot Distribution used highly obfuscated JavaScript files as one initial installer for Pikabot. |
| T1140 Deobfuscate/Decode Files or Information |
CampaignC0021 | During C0021, the threat actors deobfuscated encoded PowerShell commands including use of the specific string `'FromBase'+0x40+'String'`, in place of `FromBase64String` which is normally used to decode base64. |
| T1140 Deobfuscate/Decode Files or Information |
CampaignJuicy Mix | During Juicy Mix, OilRig used a script to concatenate and deobfuscate encoded strings in Mango. |
| T1140 Deobfuscate/Decode Files or Information |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used 7-Zip to decode their Raindrop malware. |
| T1140 Deobfuscate/Decode Files or Information |
CampaignAPT28 Nearest Neighbor Campaign | During APT28 Nearest Neighbor Campaign, APT28 unarchived data using the GUI version of WinRAR. |
| T1140 Deobfuscate/Decode Files or Information |
CampaignArcaneDoor | ArcaneDoor involved the use of Base64 obfuscated scripts and commands. |
| T1140 Deobfuscate/Decode Files or Information |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries decoded a Base64-encoded ZIP archive using the built-in certutil. |
| T1140 Deobfuscate/Decode Files or Information |
CampaignC0017 | During C0017, APT41 used the DUSTPAN loader to decrypt embedded payloads. |
| T1189 Drive-by Compromise |
CampaignOperation Dust Storm | During Operation Dust Storm, the threat actors used a watering hole attack on a popular software reseller to exploit the then-zero-day Internet Explorer vulnerability CVE-2014-0322. |
| T1189 Drive-by Compromise |
Campaign3CX Supply Chain Attack | During the 3CX Supply Chain Attack, AppleJeus compromised the `www.tradingtechnologies[.]com` website hosting a hidden IFRAME to exploit visitors, two months before the site was known to deliver a compromised version of the X_TRADER software package. |
| T1189 Drive-by Compromise |
CampaignC0010 | During C0010, UNC3890 actors likely established a watering hole that was hosted on a login page of a legitimate Israeli shipping company that was active until at least November 2021. |
| T1190 Exploit Public-Facing Application |
CampaignFrostyGoop Incident | FrostyGoop Incident was likely enabled by the adversary exploiting an unknown vulnerability in an external-facing router. |
| T1190 Exploit Public-Facing Application |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors exploited authentication bypass and remote code execution vulnerabilities (CVE-2025-49706 and CVE-2025-49704) against on-premises SharePoint servers. This activity was characterized by crafted `POST` requests to the ToolPane endpoint `/_layouts/15/ToolPane.aspx`. |
| T1190 Exploit Public-Facing Application |
CampaignOperation MidnightEclipse | During Operation MidnightEclipse, threat actors exploited CVE-2024-3400 in Palo Alto Networks GlobalProtect. |
| T1190 Exploit Public-Facing Application |
CampaignCutting Edge | During Cutting Edge, threat actors exploited CVE-2023-46805 and CVE-2024-21887 in Ivanti Connect Secure VPN appliances to enable authentication bypass and command injection. A server-side request forgery (SSRF) vulnerability, CVE-2024-21893, was identified later and used to bypass mitigations for the initial two vulnerabilities by chaining with CVE-2024-21887. |
| T1190 Exploit Public-Facing Application |
CampaignC0018 | During C0018, the threat actors exploited VMWare Horizon Unified Access Gateways that were vulnerable to several Log4Shell vulnerabilities, including CVE-2021-44228, CVE-2021-45046, CVE-2021-45105, and CVE-2021-44832. |
| T1190 Exploit Public-Facing Application |
CampaignShadowRay | During ShadowRay, threat actors exploited CVE-2023-48022 on publicly exposed Ray servers to steal computing power and to expose sensitive data. |
| T1190 Exploit Public-Facing Application |
CampaignAnthropic AI-orchestrated Campaign | During the Anthropic AI-orchestrated Campaign, the adversary used Claude Code to deploy a custom exploit payload targeting an identified SSRF vulnerability to gain initial access to a targeted environment. |
| T1190 Exploit Public-Facing Application |
CampaignOperation Digital Eye | During Operation Digital Eye, threat actors used SQL injection to compromise publicly exposed web and database servers. |
| T1190 Exploit Public-Facing Application |
CampaignHomeLand Justice | For HomeLand Justice, threat actors exploited CVE-2019-0604 in Microsoft SharePoint for initial access. |
| T1190 Exploit Public-Facing Application |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 exploited CVE-2020-0688 against the Microsoft Exchange Control Panel to regain access to a network. |
| T1190 Exploit Public-Facing Application |
CampaignSPACEHOP Activity | SPACEHOP Activity has enabled the exploitation of CVE-2022-27518 and CVE-2022-27518 for illegitimate access. |
| T1190 Exploit Public-Facing Application |
CampaignOperation CuckooBees | During Operation CuckooBees, the threat actors exploited multiple vulnerabilities in externally facing servers. |
| T1190 Exploit Public-Facing Application |
CampaignArcaneDoor | ArcaneDoor abused WebVPN traffic to targeted devices to achieve unauthorized remote code execution. |
| T1190 Exploit Public-Facing Application |
CampaignNight Dragon | During Night Dragon, threat actors used SQL injection exploits against extranet web servers to gain access. |
| T1190 Exploit Public-Facing Application |
CampaignVersa Director Zero Day Exploitation | Versa Director Zero Day Exploitation involved exploitation of a vulnerability in Versa Director servers, since identified as CVE-2024-39717, for initial access and code execution. |
| T1190 Exploit Public-Facing Application |
CampaignOperation Wocao | During Operation Wocao, threat actors gained initial access by exploiting vulnerabilities in JBoss webservers. |
| T1190 Exploit Public-Facing Application |
CampaignLeviathan Australian Intrusions | Leviathan exploited public-facing web applications and appliances for initial access during Leviathan Australian Intrusions. |
| T1190 Exploit Public-Facing Application |
CampaignC0017 | During C0017, APT41 exploited CVE-2021-44207 in the USAHerds application and CVE-2021-44228 in Log4j, as well as other .NET deserialization, SQL injection, and directory traversal vulnerabilities to gain initial access. |
| T1190 Exploit Public-Facing Application |
CampaignC0027 | During C0027, Scattered Spider exploited CVE-2021-35464 in the ForgeRock Open Access Management (OpenAM) application server to gain initial access. |
| T1190 Exploit Public-Facing Application |
CampaignQuad7 Activity | Quad7 Activity has enabled the exploitation of vulnerabilities for remote code execution capabilities in SOHO routers including CVE-2023-50224 and CVE-2025-9377 in TP-Link devices. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.