ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1078.002
Domain Accounts
GroupIndrik Spider

Indrik Spider has collected credentials from infected systems, including domain accounts.

T1078.002
Domain Accounts
GroupBlackByte

BlackByte captured credentials for or impersonated domain administration users.

T1078.002
Domain Accounts
GroupAPT3

APT3 leverages valid accounts after gaining credentials for use within the victim domain.

T1078.002
Domain Accounts
GroupVolt Typhoon

Volt Typhoon has used compromised domain accounts to authenticate to devices on compromised networks.

T1078.002
Domain Accounts
GroupNaikon

Naikon has used administrator credentials for lateral movement in compromised networks.

T1078.002
Domain Accounts
GroupSandworm Team

Sandworm Team has used stolen credentials to access administrative accounts within the domain.

T1078.002
Domain Accounts
GroupOilRig

OilRig has used an exfiltration tool named STEALHOOK to retreive valid domain credentials.

T1078.002
Domain Accounts
GroupAquatic Panda

Aquatic Panda used multiple mechanisms to capture valid user accounts for victim domains to enable lateral movement and access to additional hosts in victim environments.

T1078.002
Domain Accounts
GroupTA505

TA505 has used stolen domain admin accounts to compromise additional hosts.

T1078.002
Domain Accounts
GroupCinnamon Tempest

Cinnamon Tempest has obtained highly privileged credentials such as domain administrator in order to deploy malware.

T1078.002
Domain Accounts
GroupChimera

Chimera has used compromised domain accounts to gain access to the target environment.

T1078.002
Domain Accounts
GroupToddyCat

ToddyCat has used compromised domain admin credentials to mount local network shares.

T1078.002
Domain Accounts
GroupAgrius

Agrius attempted to acquire valid credentials for victim environments through various means to enable follow-on lateral movement.

T1078.002
Domain Accounts
GroupAPT5

APT5 has used legitimate account credentials to move laterally through compromised environments.

T1078.002
Domain Accounts
GroupThreat Group-1314

Threat Group-1314 actors used compromised domain credentials for the victim's endpoint management platform, Altiris, to move laterally.

T1078.002
Domain Accounts
GroupWizard Spider

Wizard Spider has used administrative accounts, including Domain Admin, to move laterally within a victim network.

T1078.002
Domain Accounts
GroupVOID MANTICORE

VOID MANTICORE has used previously compromised Domain Administrator credentials to maintain persistent access.

T1078.002
Domain Accounts
GroupPlay

Play has used valid domain accounts for access.

T1078.002
Domain Accounts
GroupMagic Hound

Magic Hound has used domain administrator accounts after dumping LSASS process memory.

T1078.002
Domain Accounts
MalwareStuxnet

Stuxnet attempts to access network resources with a domain account’s credentials.

T1078.002
Domain Accounts
MalwareShamoon

If Shamoon cannot access shares using current privileges, it attempts access using hard coded, domain-specific credentials gathered earlier in the intrusion.

T1078.002
Domain Accounts
MalwareRyuk

Ryuk can use stolen domain admin accounts to move laterally within a victim domain.

T1078.002
Domain Accounts
MalwareCobalt Strike

Cobalt Strike can use known credentials to run commands and spawn processes as a domain user account.

T1078.002
Domain Accounts
MalwareCreepySnail

CreepySnail can use stolen credentials to authenticate on target networks.

T1078.002
Domain Accounts
GroupShinyHunters

ShinyHunters has used valid domain accounts to gain initial access or to escalate privileges within environments.

T1078.003
Local Accounts
CampaignAnthropic AI-orchestrated Campaign

During the Anthropic AI-orchestrated Campaign, the adversary used Claude Code to test credentials harvested against discovered devices.

T1078.003
Local Accounts
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used compromised local accounts to access victims' networks.

T1078.003
Local Accounts
CampaignOperation Wocao

During Operation Wocao, threat actors used local account credentials found during the intrusion for lateral movement and privilege escalation.

T1078.003
Local Accounts
CampaignLeviathan Australian Intrusions

Leviathan used captured local account information, such as service accounts, for actions during Leviathan Australian Intrusions.

T1078.003
Local Accounts
GroupKimsuky

Kimsuky has used a tool called GREASE to add a Windows admin account in order to allow them continued access via RDP.

T1078.003
Local Accounts
GroupAPT32

APT32 has used legitimate local admin account credentials.

T1078.003
Local Accounts
GroupHAFNIUM

HAFNIUM has used the NT AUTHORITY\SYSTEM account to create files on Exchange servers.

T1078.003
Local Accounts
GroupFIN7

FIN7 has used compromised credentials for access as SYSTEM on Exchange servers.

T1078.003
Local Accounts
GroupTropic Trooper

Tropic Trooper has used known administrator account credentials to execute the backdoor directly.

T1078.003
Local Accounts
GroupSea Turtle

Sea Turtle compromised cPanel accounts in victim environments.

T1078.003
Local Accounts
GroupTurla

Turla has abused local accounts that have the same password across the victim’s network.

T1078.003
Local Accounts
GroupAPT29

APT29 targets dormant or inactive user accounts, accounts belonging to individuals no longer at the organization but whose accounts remain on the system, for access and persistence.

T1078.003
Local Accounts
GroupVelvet Ant

Velvet Ant accessed vulnerable Cisco switch devices using accounts with administrator privileges.

T1078.003
Local Accounts
GroupPlay

Play has used valid local accounts to gain initial access.

T1078.003
Local Accounts
GroupPROMETHIUM

PROMETHIUM has created admin accounts on a compromised host.

T1078.003
Local Accounts
GroupFIN10

FIN10 has moved laterally using the Local Administrator account.

T1078.003
Local Accounts
MalwareEmotet

Emotet can brute force a local admin password, then use it to facilitate lateral movement.

T1078.003
Local Accounts
MalwareUmbreon

Umbreon creates valid local users to provide access to the system.

T1078.003
Local Accounts
MalwareNotPetya

NotPetya can use valid credentials with PsExec or wmic to spread itself to remote systems.

T1078.003
Local Accounts
MalwareLockBit 3.0

LockBit 3.0 can use a compromised local account for lateral movement.

T1078.003
Local Accounts
MalwareCobalt Strike

Cobalt Strike can use known credentials to run commands and spawn processes as a local user account.

T1078.004
Cloud Accounts
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used a compromised O365 administrator account to create a new Service Principal.

T1078.004
Cloud Accounts
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries leveraged stolen credentials from on-premises environments to access cloud services.

T1078.004
Cloud Accounts
CampaignC0027

During C0027, Scattered Spider leveraged compromised credentials from victim users to authenticate to Azure tenants.

T1078.004
Cloud Accounts
GroupHAFNIUM

HAFNIUM has abused service principals in compromised environments to enable data exfiltration.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.