ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1078.004
Cloud Accounts
GroupScattered Spider

Scattered Spider has used compromised Microsoft Entra ID accounts to pivot in victim environments.

T1078.004
Cloud Accounts
GroupKe3chang

Ke3chang has used compromised credentials to sign into victims’ Microsoft 365 accounts.

T1078.004
Cloud Accounts
GroupStorm-0501

Storm-0501 has leveraged compromised accounts to access Microsoft Entra Connect, which was used to synchronize on-premises identities and Microsoft Entra identities, allowing users to sign into both environments with the same password. Storm-0501 has also used the victim Global Administrator account that lacked any registered MFA method to access victim cloud environments. Storm-0501 has leveraged Storage Account Access Keys within the victim environment.

T1078.004
Cloud Accounts
GroupAPT29

APT29 has gained access to a global administrator account in Azure AD and has used `Service Principal` credentials in Exchange.

T1078.004
Cloud Accounts
GroupAPT28

APT28 has used compromised Office 365 service accounts with Global Administrator privileges to collect email from user inboxes.

T1078.004
Cloud Accounts
GroupAPT5

APT5 has accessed Microsoft M365 cloud environments using stolen credentials.

T1078.004
Cloud Accounts
GroupLAPSUS$

LAPSUS$ has used compromised credentials to access cloud assets within a target organization.

T1078.004
Cloud Accounts
GroupVOID MANTICORE

VOID MANTICORE has leveraged privileged cloud accounts to access cloud-based management consoles to include Microsoft Intune. VOID MANTICORE has also compromised existing accounts within the Microsoft Entra ID environment.

T1078.004
Cloud Accounts
GroupAPT33

APT33 has used compromised Office 365 accounts in tandem with Ruler in an attempt to gain control of endpoints.

T1078.004
Cloud Accounts
MalwareShai-Hulud

Shai-Hulud has leveraged compromised accounts to log into cloud services to access cloud hosted repositories.

T1078.004
Cloud Accounts
ToolPacu

Pacu leverages valid cloud accounts to perform most of its operations.

T1078.004
Cloud Accounts
ToolROADTools

ROADTools leverages valid cloud credentials to perform enumeration operations using the internal Azure AD Graph API.

T1078.004
Cloud Accounts
ToolTruffleHog

TruffleHog has used stolen credentials to log into cloud services to access cloud hosted repositories and other cloud storage solutions to discover sensitive data to include API Keys, tokens and credentials.

T1078.004
Cloud Accounts
ToolPeirates

Peirates can use stolen service account tokens to perform its operations.

T1078.004
Cloud Accounts
MalwareMini Shai-Hulud

Mini Shai-Hulud has used compromised accounts for Docker Hub and GitHub to publish malicious software packages.

T1078.004
Cloud Accounts
GroupTeamPCP

TeamPCP has used compromised credentials for GitHub and software package repositories, including privileged service accounts, to inject malicious code into CI/CD pipelines.

T1078.004
Cloud Accounts
GroupShinyHunters

ShinyHunters has used valid cloud accounts to gain initial access or to escalate privileges within cloud environments. Additionally, ShinyHunters has also used valid credentials from public repositories to include access keys to gain access to the victim organization’s AWS environment.

T1080
Taint Shared Content
GroupGamaredon Group

Gamaredon Group has injected malicious macros into all Word and Excel documents on mapped network drives.

T1080
Taint Shared Content
GroupRedCurl

RedCurl has placed modified LNK files on network drives for lateral movement.

T1080
Taint Shared Content
GroupCinnamon Tempest

Cinnamon Tempest has deployed ransomware from a batch file in a network share.

T1080
Taint Shared Content
GroupBRONZE BUTLER

BRONZE BUTLER has placed malware on file shares and given it the same name as legitimate documents on the share.

T1080
Taint Shared Content
GroupDarkhotel

Darkhotel used a virus that propagates by infecting executables stored on shared drives.

T1080
Taint Shared Content
MalwareStuxnet

Stuxnet infects remote servers via network shares and by infecting WinCC database views with malicious code.

T1080
Taint Shared Content
MalwareUrsnif

Ursnif has copied itself to and infected files in network drives for propagation.

T1080
Taint Shared Content
MalwareMiner-C

Miner-C copies itself into the public folder of Network Attached Storage (NAS) devices and infects new victims who open the file.

T1080
Taint Shared Content
MalwareInvisiMole

InvisiMole can replace legitimate software or documents in the compromised network with their trojanized versions, in an attempt to propagate itself within the network.

T1080
Taint Shared Content
MalwareConti

Conti can spread itself by infecting other remote machines via network shared drives.

T1080
Taint Shared Content
MalwareRamsay

Ramsay can spread itself by infecting other portable executable files on networks shared drives.

T1080
Taint Shared Content
MalwareH1N1

H1N1 has functionality to copy itself to network shares.

T1082
System Information Discovery
CampaignKV Botnet Activity

KV Botnet Activity includes use of native system tools, such as uname, to obtain information about victim device architecture, as well as gathering other system information such as the victim's hosts file and CPU utilization.

T1082
System Information Discovery
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors fingerprinted targeted SharePoint servers to identify OS version and running processes.

T1082
System Information Discovery
CampaignFrankenstein

During Frankenstein, the threat actors used Empire to obtain the compromised machine's name.

T1082
System Information Discovery
CampaignRedDelta Modified PlugX Infection Chain Operations

Mustang Panda captured victim operating system type via User Agent analysis during RedDelta Modified PlugX Infection Chain Operations.

T1082
System Information Discovery
CampaignOperation Honeybee

During Operation Honeybee, the threat actors collected the computer name, OS, and other system information using `cmd /c systeminfo > %temp%\ temp.ini`.

T1082
System Information Discovery
CampaignCutting Edge

During Cutting Edge, threat actors used the ENUM4LINUX Perl script for discovery on Windows and Samba hosts.

T1082
System Information Discovery
CampaignAnthropic AI-orchestrated Campaign

During the Anthropic AI-orchestrated Campaign, the adversary tasked Claude Code to query databases and systems in order to identify proprietary information, including system configurations and database types.

T1082
System Information Discovery
CampaignJuicy Mix

During Juicy Mix, OilRig used a script to send the name of the compromised host via HTTP `POST` to register it with C2.

T1082
System Information Discovery
CampaignOperation AkaiRyū

During Operation AkaiRyū, MirrorFace collected system information.

T1082
System Information Discovery
CampaignFunnyDream

During FunnyDream, the threat actors used Systeminfo to collect information on targeted hosts.

T1082
System Information Discovery
CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors used the `systeminfo` command to gather details about a compromised system.

T1082
System Information Discovery
CampaignArcaneDoor

ArcaneDoor included collection of victim device configuration information.

T1082
System Information Discovery
CampaignOperation Wocao

During Operation Wocao, threat actors discovered the OS versions of systems connected to a targeted network.

T1082
System Information Discovery
CampaignLeviathan Australian Intrusions

Leviathan performed host enumeration and data gathering operations on victim machines during Leviathan Australian Intrusions.

T1082
System Information Discovery
GroupAPT38

APT38 has attempted to get detailed information about a compromised host, including the operating system, version, patches, hotfixes, and service packs.

T1082
System Information Discovery
GroupBlackByte

BlackByte used various system commands and tools to pull system information during operations.

T1082
System Information Discovery
GroupSideCopy

SideCopy has identified the OS version of a compromised host.

T1082
System Information Discovery
GroupAPT3

APT3 has a tool that can obtain information about the local system.

T1082
System Information Discovery
GroupMustard Tempest

Mustard Tempest has used implants to perform system reconnaissance on targeted systems.

T1082
System Information Discovery
GroupKimsuky

Kimsuky has enumerated OS type, OS version, and other information using a script or the "systeminfo" command. Kimsuky has also obtained system information such as OS type, OS version, and system type through querying various Windows Management Instrumentation (WMI) classes including `Win32_OperatingSystem`.

T1082
System Information Discovery
Groupadmin@338

admin@338 actors used the following commands after exploiting a machine with LOWBALL malware to obtain information about the OS: ver >> %temp%\download systeminfo >> %temp%\download

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.