ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1072
Software Deployment Tools
GroupAPT32

APT32 compromised McAfee ePO to move laterally by distributing malware as a software deployment task.

T1072
Software Deployment Tools
GroupSandworm Team

Sandworm Team has used the commercially available tool RemoteExec for agentless remote code execution.

T1072
Software Deployment Tools
GroupMustang Panda

Mustang Panda has leveraged legitimate software tools such as AntiVirus Agents, Security Services, and App Development tools to execute scripts and to side-load dlls.

T1072
Software Deployment Tools
GroupMedusa Group

Medusa Group has utilized software deployment and management solutions to deploy their encryption payload to include BigFix and PDQ Deploy.

T1072
Software Deployment Tools
GroupSilence

Silence has used RAdmin, a remote software tool used to remotely control workstations and ATMs.

T1072
Software Deployment Tools
GroupThreat Group-1314

Threat Group-1314 actors used a victim's endpoint management platform, Altiris, for lateral movement.

T1072
Software Deployment Tools
GroupVOID MANTICORE

VOID MANTICORE has leveraged legitimate built-in features of cloud-based management platforms to include mobile device management (MDM) and Remote Monitoring and Management (RMM) solutions. VOID MANTICORE has also initiated built-in remote wipe instructions using a privileged account within Microsoft Intune.

T1072
Software Deployment Tools
MalwareWiper

It is believed that a patch management system for an anti-virus product commonly installed among targeted companies was used to distribute the Wiper malware.

T1072
Software Deployment Tools
GroupShinyHunters

ShinyHunters has abused software deployment tools for lateral movement.

T1074
Data Staged
GroupVolt Typhoon

Volt Typhoon has staged collected data in password-protected archives.

T1074
Data Staged
GroupScattered Spider

Scattered Spider stages data in a centralized database prior to exfiltration.

T1074
Data Staged
GroupINC Ransom

INC Ransom has staged data on compromised hosts prior to exfiltration.

T1074
Data Staged
GroupWizard Spider

Wizard Spider has collected and staged credentials and network enumeration information, using the networkdll and psfin TrickBot modules.

T1074
Data Staged
GroupVOID MANTICORE

VOID MANTICORE has staged compressed files in specified locations prior to exfiltration over C2.

T1074
Data Staged
MalwareQUIETCANARY

QUIETCANARY has the ability to stage data prior to exfiltration.

T1074
Data Staged
MalwareShark

Shark has stored information in folders named `U1` and `U2` prior to exfiltration.

T1074
Data Staged
MalwareKobalos

Kobalos can write captured SSH connection credentials to a file under the /var/run directory with a .pid extension for exfiltration.

T1074
Data Staged
MalwareKevin

Kevin can create directories to store logs and other collected data.

T1074.001
Local Data Staging
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors staged stolen data from web.config files to debug_dev.js.

T1074.001
Local Data Staging
CampaignOperation Honeybee

During Operation Honeybee, stolen data was copied into a text file using the format `From <COMPUTER-NAME> (<Month>-<Day> <Hour>-<Minute>-<Second>).txt` prior to compression, encoding, and exfiltration.

T1074.001
Local Data Staging
CampaignOperation MidnightEclipse

During Operation MidnightEclipse, threat actors copied files to the web application folder on compromised devices for exfiltration.

T1074.001
Local Data Staging
CampaignAnthropic AI-orchestrated Campaign

During the Anthropic AI-orchestrated Campaign, the adversary used Claude Code to stage extracted data and operational documentation in structured markdown files on local systems prior to exfiltration.

T1074.001
Local Data Staging
CampaignC0015

During C0015, PowerView's file share enumeration results were stored in the file `c:\ProgramData\found_shares.txt`.

T1074.001
Local Data Staging
CampaignJuicy Mix

During Juicy Mix, OilRig used browser data and credential stealer tools to stage stolen files named Cupdate, Eupdate, and IUpdate in the %TEMP% directory.

T1074.001
Local Data Staging
CampaignC0032

During the C0032 campaign, TEMP.Veles used staging folders that are infrequently used by legitimate users or processes to store data for exfiltration and tool deployment.

T1074.001
Local Data Staging
CampaignAPT28 Nearest Neighbor Campaign

During APT28 Nearest Neighbor Campaign, APT28 staged captured credential information in the C:\ProgramData directory.

T1074.001
Local Data Staging
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries compiled discovery data locally on the victim host in a file located within `C:\Windows\TEMP\outlog.txt`.

T1074.001
Local Data Staging
CampaignAPT41 DUST

APT41 DUST involved exporting data from Oracle databases to local CSV files prior to exfiltration.

T1074.001
Local Data Staging
CampaignOperation Wocao

During Operation Wocao, threat actors staged archived files in a temporary directory prior to exfiltration.

T1074.001
Local Data Staging
CampaignLeviathan Australian Intrusions

Leviathan stored captured credential material on local log files on victim systems during Leviathan Australian Intrusions.

T1074.001
Local Data Staging
CampaignC0017

During C0017, APT41 copied the local `SAM` and `SYSTEM` Registry hives to a staging directory.

T1074.001
Local Data Staging
GroupIndrik Spider

Indrik Spider has stored collected data in a .tmp file.

T1074.001
Local Data Staging
GroupGALLIUM

GALLIUM compressed and staged files in multi-part archives in the Recycle Bin prior to exfiltration.

T1074.001
Local Data Staging
GroupAPT3

APT3 has been known to stage files for exfiltration in a single location.

T1074.001
Local Data Staging
GroupKimsuky

Kimsuky has staged collected data files under C:\Program Files\Common Files\System\Ole DB\. Kimsuky has also gathered data in structured directories prior to exfiltration under the %TEMP% environment variable.

T1074.001
Local Data Staging
GroupVolt Typhoon

Volt Typhoon has saved stolen files including the `ntds.dit` database and the `SYSTEM` and `SECURITY` Registry hives locally to the `C:\Windows\Temp\` directory.

T1074.001
Local Data Staging
GroupPatchwork

Patchwork copied all targeted files to a directory called index that was eventually uploaded to the C&C server.

T1074.001
Local Data Staging
GroupDragonfly

Dragonfly has created a directory named "out" in the user's %AppData% folder and copied files to it.

T1074.001
Local Data Staging
GroupmenuPass

menuPass stages data prior to exfiltration in multi-part archives, often saved in the Recycle Bin.

T1074.001
Local Data Staging
GroupMuddyWater

MuddyWater has stored a decoy PDF file within a victim's `%temp%` folder.

T1074.001
Local Data Staging
GroupStorm-1811

Storm-1811 has locally staged captured credentials for subsequent manual exfiltration.

T1074.001
Local Data Staging
GroupTeamTNT

TeamTNT has aggregated collected credentials in text files before exfiltrating.

T1074.001
Local Data Staging
GroupSidewinder

Sidewinder has collected stolen files in a temporary folder in preparation for exfiltration.

T1074.001
Local Data Staging
GroupMustang Panda

Mustang Panda has stored collected credential files in c:\windows\temp prior to exfiltration. Mustang Panda has also stored documents for exfiltration in a hidden folder on USB drives.

T1074.001
Local Data Staging
GroupAPT39

APT39 has utilized tools to aggregate data prior to exfiltration.

T1074.001
Local Data Staging
GroupUNC3886

UNC3886 has staged captured credentials in `var/log/ldapd<unique_keyword>.2.gz`.

T1074.001
Local Data Staging
GroupLeviathan

Leviathan has used C:\Windows\Debug and C:\Perflogs as staging directories.

T1074.001
Local Data Staging
GroupFIN5

FIN5 scripts save memory dump data into a specific directory on hosts in the victim environment.

T1074.001
Local Data Staging
GroupLotus Blossom

Lotus Blossom has locally staged compressed and archived data for follow-on exfiltration.

T1074.001
Local Data Staging
GroupChimera

Chimera has staged stolen data locally on compromised hosts.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.