Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1078.004 Cloud Accounts |
GroupScattered Spider | Scattered Spider has used compromised Microsoft Entra ID accounts to pivot in victim environments. |
| T1078.004 Cloud Accounts |
GroupKe3chang | Ke3chang has used compromised credentials to sign into victims’ Microsoft 365 accounts. |
| T1078.004 Cloud Accounts |
GroupStorm-0501 | Storm-0501 has leveraged compromised accounts to access Microsoft Entra Connect, which was used to synchronize on-premises identities and Microsoft Entra identities, allowing users to sign into both environments with the same password. Storm-0501 has also used the victim Global Administrator account that lacked any registered MFA method to access victim cloud environments. Storm-0501 has leveraged Storage Account Access Keys within the victim environment. |
| T1078.004 Cloud Accounts |
GroupAPT29 | APT29 has gained access to a global administrator account in Azure AD and has used `Service Principal` credentials in Exchange. |
| T1078.004 Cloud Accounts |
GroupAPT28 | APT28 has used compromised Office 365 service accounts with Global Administrator privileges to collect email from user inboxes. |
| T1078.004 Cloud Accounts |
GroupAPT5 | APT5 has accessed Microsoft M365 cloud environments using stolen credentials. |
| T1078.004 Cloud Accounts |
GroupLAPSUS$ | LAPSUS$ has used compromised credentials to access cloud assets within a target organization. |
| T1078.004 Cloud Accounts |
GroupVOID MANTICORE | VOID MANTICORE has leveraged privileged cloud accounts to access cloud-based management consoles to include Microsoft Intune. VOID MANTICORE has also compromised existing accounts within the Microsoft Entra ID environment. |
| T1078.004 Cloud Accounts |
GroupAPT33 | APT33 has used compromised Office 365 accounts in tandem with Ruler in an attempt to gain control of endpoints. |
| T1078.004 Cloud Accounts |
MalwareShai-Hulud | Shai-Hulud has leveraged compromised accounts to log into cloud services to access cloud hosted repositories. |
| T1078.004 Cloud Accounts |
ToolPacu | Pacu leverages valid cloud accounts to perform most of its operations. |
| T1078.004 Cloud Accounts |
ToolROADTools | ROADTools leverages valid cloud credentials to perform enumeration operations using the internal Azure AD Graph API. |
| T1078.004 Cloud Accounts |
ToolTruffleHog | TruffleHog has used stolen credentials to log into cloud services to access cloud hosted repositories and other cloud storage solutions to discover sensitive data to include API Keys, tokens and credentials. |
| T1078.004 Cloud Accounts |
ToolPeirates | Peirates can use stolen service account tokens to perform its operations. |
| T1078.004 Cloud Accounts |
MalwareMini Shai-Hulud | Mini Shai-Hulud has used compromised accounts for Docker Hub and GitHub to publish malicious software packages. |
| T1078.004 Cloud Accounts |
GroupTeamPCP | TeamPCP has used compromised credentials for GitHub and software package repositories, including privileged service accounts, to inject malicious code into CI/CD pipelines. |
| T1078.004 Cloud Accounts |
GroupShinyHunters | ShinyHunters has used valid cloud accounts to gain initial access or to escalate privileges within cloud environments. Additionally, ShinyHunters has also used valid credentials from public repositories to include access keys to gain access to the victim organization’s AWS environment. |
| T1080 Taint Shared Content |
GroupGamaredon Group | Gamaredon Group has injected malicious macros into all Word and Excel documents on mapped network drives. |
| T1080 Taint Shared Content |
GroupRedCurl | RedCurl has placed modified LNK files on network drives for lateral movement. |
| T1080 Taint Shared Content |
GroupCinnamon Tempest | Cinnamon Tempest has deployed ransomware from a batch file in a network share. |
| T1080 Taint Shared Content |
GroupBRONZE BUTLER | BRONZE BUTLER has placed malware on file shares and given it the same name as legitimate documents on the share. |
| T1080 Taint Shared Content |
GroupDarkhotel | Darkhotel used a virus that propagates by infecting executables stored on shared drives. |
| T1080 Taint Shared Content |
MalwareStuxnet | Stuxnet infects remote servers via network shares and by infecting WinCC database views with malicious code. |
| T1080 Taint Shared Content |
MalwareUrsnif | Ursnif has copied itself to and infected files in network drives for propagation. |
| T1080 Taint Shared Content |
MalwareMiner-C | Miner-C copies itself into the public folder of Network Attached Storage (NAS) devices and infects new victims who open the file. |
| T1080 Taint Shared Content |
MalwareInvisiMole | InvisiMole can replace legitimate software or documents in the compromised network with their trojanized versions, in an attempt to propagate itself within the network. |
| T1080 Taint Shared Content |
MalwareConti | Conti can spread itself by infecting other remote machines via network shared drives. |
| T1080 Taint Shared Content |
MalwareRamsay | Ramsay can spread itself by infecting other portable executable files on networks shared drives. |
| T1080 Taint Shared Content |
MalwareH1N1 | H1N1 has functionality to copy itself to network shares. |
| T1082 System Information Discovery |
CampaignKV Botnet Activity | KV Botnet Activity includes use of native system tools, such as |
| T1082 System Information Discovery |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors fingerprinted targeted SharePoint servers to identify OS version and running processes. |
| T1082 System Information Discovery |
CampaignFrankenstein | During Frankenstein, the threat actors used Empire to obtain the compromised machine's name. |
| T1082 System Information Discovery |
CampaignRedDelta Modified PlugX Infection Chain Operations | Mustang Panda captured victim operating system type via User Agent analysis during RedDelta Modified PlugX Infection Chain Operations. |
| T1082 System Information Discovery |
CampaignOperation Honeybee | During Operation Honeybee, the threat actors collected the computer name, OS, and other system information using `cmd /c systeminfo > %temp%\ temp.ini`. |
| T1082 System Information Discovery |
CampaignCutting Edge | During Cutting Edge, threat actors used the ENUM4LINUX Perl script for discovery on Windows and Samba hosts. |
| T1082 System Information Discovery |
CampaignAnthropic AI-orchestrated Campaign | During the Anthropic AI-orchestrated Campaign, the adversary tasked Claude Code to query databases and systems in order to identify proprietary information, including system configurations and database types. |
| T1082 System Information Discovery |
CampaignJuicy Mix | During Juicy Mix, OilRig used a script to send the name of the compromised host via HTTP `POST` to register it with C2. |
| T1082 System Information Discovery |
CampaignOperation AkaiRyū | During Operation AkaiRyū, MirrorFace collected system information. |
| T1082 System Information Discovery |
CampaignFunnyDream | During FunnyDream, the threat actors used Systeminfo to collect information on targeted hosts. |
| T1082 System Information Discovery |
CampaignOperation CuckooBees | During Operation CuckooBees, the threat actors used the `systeminfo` command to gather details about a compromised system. |
| T1082 System Information Discovery |
CampaignArcaneDoor | ArcaneDoor included collection of victim device configuration information. |
| T1082 System Information Discovery |
CampaignOperation Wocao | During Operation Wocao, threat actors discovered the OS versions of systems connected to a targeted network. |
| T1082 System Information Discovery |
CampaignLeviathan Australian Intrusions | Leviathan performed host enumeration and data gathering operations on victim machines during Leviathan Australian Intrusions. |
| T1082 System Information Discovery |
GroupAPT38 | APT38 has attempted to get detailed information about a compromised host, including the operating system, version, patches, hotfixes, and service packs. |
| T1082 System Information Discovery |
GroupBlackByte | BlackByte used various system commands and tools to pull system information during operations. |
| T1082 System Information Discovery |
GroupSideCopy | SideCopy has identified the OS version of a compromised host. |
| T1082 System Information Discovery |
GroupAPT3 | APT3 has a tool that can obtain information about the local system. |
| T1082 System Information Discovery |
GroupMustard Tempest | Mustard Tempest has used implants to perform system reconnaissance on targeted systems. |
| T1082 System Information Discovery |
GroupKimsuky | Kimsuky has enumerated OS type, OS version, and other information using a script or the "systeminfo" command. Kimsuky has also obtained system information such as OS type, OS version, and system type through querying various Windows Management Instrumentation (WMI) classes including `Win32_OperatingSystem`. |
| T1082 System Information Discovery |
Groupadmin@338 | admin@338 actors used the following commands after exploiting a machine with LOWBALL malware to obtain information about the OS: |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.