Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1072 Software Deployment Tools |
GroupAPT32 | APT32 compromised McAfee ePO to move laterally by distributing malware as a software deployment task. |
| T1072 Software Deployment Tools |
GroupSandworm Team | Sandworm Team has used the commercially available tool RemoteExec for agentless remote code execution. |
| T1072 Software Deployment Tools |
GroupMustang Panda | Mustang Panda has leveraged legitimate software tools such as AntiVirus Agents, Security Services, and App Development tools to execute scripts and to side-load dlls. |
| T1072 Software Deployment Tools |
GroupMedusa Group | Medusa Group has utilized software deployment and management solutions to deploy their encryption payload to include BigFix and PDQ Deploy. |
| T1072 Software Deployment Tools |
GroupSilence | Silence has used RAdmin, a remote software tool used to remotely control workstations and ATMs. |
| T1072 Software Deployment Tools |
GroupThreat Group-1314 | Threat Group-1314 actors used a victim's endpoint management platform, Altiris, for lateral movement. |
| T1072 Software Deployment Tools |
GroupVOID MANTICORE | VOID MANTICORE has leveraged legitimate built-in features of cloud-based management platforms to include mobile device management (MDM) and Remote Monitoring and Management (RMM) solutions. VOID MANTICORE has also initiated built-in remote wipe instructions using a privileged account within Microsoft Intune. |
| T1072 Software Deployment Tools |
MalwareWiper | It is believed that a patch management system for an anti-virus product commonly installed among targeted companies was used to distribute the Wiper malware. |
| T1072 Software Deployment Tools |
GroupShinyHunters | ShinyHunters has abused software deployment tools for lateral movement. |
| T1074 Data Staged |
GroupVolt Typhoon | Volt Typhoon has staged collected data in password-protected archives. |
| T1074 Data Staged |
GroupScattered Spider | Scattered Spider stages data in a centralized database prior to exfiltration. |
| T1074 Data Staged |
GroupINC Ransom | INC Ransom has staged data on compromised hosts prior to exfiltration. |
| T1074 Data Staged |
GroupWizard Spider | Wizard Spider has collected and staged credentials and network enumeration information, using the networkdll and psfin TrickBot modules. |
| T1074 Data Staged |
GroupVOID MANTICORE | VOID MANTICORE has staged compressed files in specified locations prior to exfiltration over C2. |
| T1074 Data Staged |
MalwareQUIETCANARY | QUIETCANARY has the ability to stage data prior to exfiltration. |
| T1074 Data Staged |
MalwareShark | Shark has stored information in folders named `U1` and `U2` prior to exfiltration. |
| T1074 Data Staged |
MalwareKobalos | Kobalos can write captured SSH connection credentials to a file under the |
| T1074 Data Staged |
MalwareKevin | Kevin can create directories to store logs and other collected data. |
| T1074.001 Local Data Staging |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors staged stolen data from web.config files to debug_dev.js. |
| T1074.001 Local Data Staging |
CampaignOperation Honeybee | During Operation Honeybee, stolen data was copied into a text file using the format `From <COMPUTER-NAME> (<Month>-<Day> <Hour>-<Minute>-<Second>).txt` prior to compression, encoding, and exfiltration. |
| T1074.001 Local Data Staging |
CampaignOperation MidnightEclipse | During Operation MidnightEclipse, threat actors copied files to the web application folder on compromised devices for exfiltration. |
| T1074.001 Local Data Staging |
CampaignAnthropic AI-orchestrated Campaign | During the Anthropic AI-orchestrated Campaign, the adversary used Claude Code to stage extracted data and operational documentation in structured markdown files on local systems prior to exfiltration. |
| T1074.001 Local Data Staging |
CampaignC0015 | During C0015, PowerView's file share enumeration results were stored in the file `c:\ProgramData\found_shares.txt`. |
| T1074.001 Local Data Staging |
CampaignJuicy Mix | During Juicy Mix, OilRig used browser data and credential stealer tools to stage stolen files named Cupdate, Eupdate, and IUpdate in the %TEMP% directory. |
| T1074.001 Local Data Staging |
CampaignC0032 | During the C0032 campaign, TEMP.Veles used staging folders that are infrequently used by legitimate users or processes to store data for exfiltration and tool deployment. |
| T1074.001 Local Data Staging |
CampaignAPT28 Nearest Neighbor Campaign | During APT28 Nearest Neighbor Campaign, APT28 staged captured credential information in the |
| T1074.001 Local Data Staging |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries compiled discovery data locally on the victim host in a file located within `C:\Windows\TEMP\outlog.txt`. |
| T1074.001 Local Data Staging |
CampaignAPT41 DUST | APT41 DUST involved exporting data from Oracle databases to local CSV files prior to exfiltration. |
| T1074.001 Local Data Staging |
CampaignOperation Wocao | During Operation Wocao, threat actors staged archived files in a temporary directory prior to exfiltration. |
| T1074.001 Local Data Staging |
CampaignLeviathan Australian Intrusions | Leviathan stored captured credential material on local log files on victim systems during Leviathan Australian Intrusions. |
| T1074.001 Local Data Staging |
CampaignC0017 | During C0017, APT41 copied the local `SAM` and `SYSTEM` Registry hives to a staging directory. |
| T1074.001 Local Data Staging |
GroupIndrik Spider | Indrik Spider has stored collected data in a .tmp file. |
| T1074.001 Local Data Staging |
GroupGALLIUM | GALLIUM compressed and staged files in multi-part archives in the Recycle Bin prior to exfiltration. |
| T1074.001 Local Data Staging |
GroupAPT3 | APT3 has been known to stage files for exfiltration in a single location. |
| T1074.001 Local Data Staging |
GroupKimsuky | Kimsuky has staged collected data files under |
| T1074.001 Local Data Staging |
GroupVolt Typhoon | Volt Typhoon has saved stolen files including the `ntds.dit` database and the `SYSTEM` and `SECURITY` Registry hives locally to the `C:\Windows\Temp\` directory. |
| T1074.001 Local Data Staging |
GroupPatchwork | Patchwork copied all targeted files to a directory called index that was eventually uploaded to the C&C server. |
| T1074.001 Local Data Staging |
GroupDragonfly | Dragonfly has created a directory named "out" in the user's %AppData% folder and copied files to it. |
| T1074.001 Local Data Staging |
GroupmenuPass | menuPass stages data prior to exfiltration in multi-part archives, often saved in the Recycle Bin. |
| T1074.001 Local Data Staging |
GroupMuddyWater | MuddyWater has stored a decoy PDF file within a victim's `%temp%` folder. |
| T1074.001 Local Data Staging |
GroupStorm-1811 | Storm-1811 has locally staged captured credentials for subsequent manual exfiltration. |
| T1074.001 Local Data Staging |
GroupTeamTNT | TeamTNT has aggregated collected credentials in text files before exfiltrating. |
| T1074.001 Local Data Staging |
GroupSidewinder | Sidewinder has collected stolen files in a temporary folder in preparation for exfiltration. |
| T1074.001 Local Data Staging |
GroupMustang Panda | Mustang Panda has stored collected credential files in |
| T1074.001 Local Data Staging |
GroupAPT39 | APT39 has utilized tools to aggregate data prior to exfiltration. |
| T1074.001 Local Data Staging |
GroupUNC3886 | UNC3886 has staged captured credentials in `var/log/ldapd<unique_keyword>.2.gz`. |
| T1074.001 Local Data Staging |
GroupLeviathan | Leviathan has used C:\Windows\Debug and C:\Perflogs as staging directories. |
| T1074.001 Local Data Staging |
GroupFIN5 | FIN5 scripts save memory dump data into a specific directory on hosts in the victim environment. |
| T1074.001 Local Data Staging |
GroupLotus Blossom | Lotus Blossom has locally staged compressed and archived data for follow-on exfiltration. |
| T1074.001 Local Data Staging |
GroupChimera | Chimera has staged stolen data locally on compromised hosts. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.