Real-world descriptions of how a group, tool or campaign used a technique.
1146 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1218.010 Regsvr32 |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group used `regsvr32` to execute malware. |
| T1218.010 Regsvr32 |
CampaignC0015 | During C0015, the threat actors employed code that used `regsvr32` for execution. |
| T1218.011 Rundll32 |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group executed malware with `C:\\windows\system32\rundll32.exe "C:\ProgramData\ThumbNail\thumbnail.db"`, `CtrlPanel S-6-81-3811-75432205-060098-6872 0 0 905`. |
| T1218.011 Rundll32 |
Campaign2015 Ukraine Electric Power Attack | During the 2015 Ukraine Electric Power Attack, Sandworm Team used a backdoor which could execute a supplied DLL using `rundll32.exe`. |
| T1218.011 Rundll32 |
CampaignOperation Spalax | During Operation Spalax, the threat actors used `rundll32.exe` to execute malicious installers. |
| T1218.011 Rundll32 |
CampaignC0018 | During C0018, the threat actors used `rundll32` to run Mimikatz. |
| T1218.011 Rundll32 |
CampaignWater Curupira Pikabot Distribution | Water Curupira Pikabot Distribution utilizes rundll32.exe to execute the final Pikabot payload, using the named exports `Crash` or `Limit` depending on the variant. |
| T1218.011 Rundll32 |
CampaignC0021 | During C0021, the threat actors used `rundll32.exe` to execute the Cobalt Strike Beacon loader DLL. |
| T1218.011 Rundll32 |
CampaignC0015 | During C0015, the threat actors loaded DLLs via `rundll32` using the `svchost` process. |
| T1218.011 Rundll32 |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used `Rundll32.exe` to execute payloads. |
| T1218.014 MMC |
CampaignRedDelta Modified PlugX Infection Chain Operations | Mustang Panda used Microsoft Management Console Snap-In Control files, or MSC files, executed via MMC to run follow-on PowerShell commands during RedDelta Modified PlugX Infection Chain Operations. |
| T1218.015 Electron Applications |
Campaign3CX Supply Chain Attack | During the 3CX Supply Chain Attack, AppleJeus leveraged the 3CX application's electron framework to execute its malicious libraries under the official 3CX electron application. |
| T1219 Remote Access Tools |
CampaignOperation AkaiRyū | During Operation AkaiRyū, MirrorFace used remote access tools including PuTTY. |
| T1219 Remote Access Tools |
CampaignNight Dragon | During Night Dragon, threat actors used several remote administration tools as persistent infiltration channels. |
| T1219.001 IDE Tunneling |
CampaignOperation Digital Eye | During Operation Digital Eye, threat actors created Visual Studio Code dev tunnels to access targeted endpoints through the browser-based version of Visual Studio Code. |
| T1219.001 IDE Tunneling |
CampaignOperation AkaiRyū | During Operation AkaiRyū, MirrorFace abused Visual Studio Code (VS Code) remote tunnels to gain access and execute code on compromised machines. |
| T1219.002 Remote Desktop Software |
CampaignC0018 | During C0018, the threat actors used AnyDesk to transfer tools between systems. |
| T1219.002 Remote Desktop Software |
CampaignC0015 | During C0015, the threat actors installed the AnyDesk remote desktop application onto the compromised network. |
| T1219.002 Remote Desktop Software |
CampaignC0027 | During C0027, Scattered Spider directed victims to run remote monitoring and management (RMM) tools. |
| T1220 XSL Script Processing |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group used a remote XSL script to download a Base64-encoded DLL custom downloader. |
| T1221 Template Injection |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group used DOCX files to retrieve a malicious document template/DOTM file. |
| T1221 Template Injection |
CampaignFrankenstein | During Frankenstein, the threat actors used trojanized documents that retrieved remote templates from an adversary-controlled website. |
| T1222.002 Linux and Mac Permissions |
CampaignKV Botnet Activity | KV Botnet Activity altered permissions on downloaded tools and payloads to enable execution on victim machines. |
| T1480 Execution Guardrails |
CampaignRedDelta Modified PlugX Infection Chain Operations | Mustang Panda included the use of Cloudflare geofencing mechanisms to limit payload download activity during RedDelta Modified PlugX Infection Chain Operations. |
| T1482 Domain Trust Discovery |
CampaignC0015 | During C0015, the threat actors used the command `nltest /domain_trusts /all_trusts` to enumerate domain trusts. |
| T1482 Domain Trust Discovery |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used the `Get-AcceptedDomain` PowerShell cmdlet to enumerate accepted domains through an Exchange Management Shell. They also used AdFind to enumerate domains and to discover trust between federated domains. |
| T1482 Domain Trust Discovery |
CampaignLeviathan Australian Intrusions | Leviathan performed Active Directory enumeration of victim environments during Leviathan Australian Intrusions. |
| T1484.001 Group Policy Modification |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors, including Storm-2603, modified group policy to enable ransomware distribution. |
| T1484.001 Group Policy Modification |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries had leveraged Group Policy Objects to distribute wiper malware to victim devices through a network share. |
| T1484.001 Group Policy Modification |
Campaign2022 Ukraine Electric Power Attack | During the 2022 Ukraine Electric Power Attack, Sandworm Team leveraged Group Policy Objects (GPOs) to deploy and execute malware. |
| T1484.002 Trust Modification |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 changed domain federation trust settings using Azure AD administrative permissions to configure the domain to accept authorization tokens signed by their own SAML signing certificate. |
| T1485 Data Destruction |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries utilized wiper malware to overwrite files using a 16-byte buffer that fully overwrites files 16 bytes or smaller or partially overwrites files greater than 16 bytes to speed up the process. |
| T1485 Data Destruction |
Campaign2022 Ukraine Electric Power Attack | During the 2022 Ukraine Electric Power Attack, Sandworm Team deployed CaddyWiper on the victim’s IT environment systems to wipe files related to the OT capabilities, along with mapped drives, and physical drive partitions. |
| T1486 Data Encrypted for Impact |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors deployed ransomware including 4L4MD4R and Warlock. |
| T1486 Data Encrypted for Impact |
CampaignC0018 | During C0018, the threat actors used AvosLocker ransomware to encrypt files on the compromised network. |
| T1486 Data Encrypted for Impact |
CampaignC0015 | During C0015, the threat actors used Conti ransomware to encrypt a compromised network. |
| T1486 Data Encrypted for Impact |
CampaignHomeLand Justice | During HomeLand Justice, threat actors used ROADSWEEP ransomware to encrypt files on targeted systems. |
| T1490 Inhibit System Recovery |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries deleted Windows Volume Shadow Copies using `vssadmin delete shadows`. |
| T1495 Firmware Corruption |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, adversaries performed a factory-reset on compromised devices that hampered forensic investigations. |
| T1496.001 Compute Hijacking |
CampaignShadowRay | During ShadowRay, threat actors leveraged graphics processing units (GPU) on compromised nodes for cryptocurrency mining. |
| T1497 Virtualization/Sandbox Evasion |
CampaignOperation Spalax | During Operation Spalax, the threat actors used droppers that would run anti-analysis checks before executing malware on a compromised host. |
| T1497.001 System Checks |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group used tools that conducted a variety of system checks to detect sandboxes or VMware services. |
| T1497.001 System Checks |
CampaignFrankenstein | During Frankenstein, the threat actors used a script that ran WMI queries to check if a VM or sandbox was running, including VMWare and Virtualbox. The script would also call WMI to determine the number of cores allocated to the system; if less than two the script would stop execution. |
| T1497.003 Time Based Checks |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group used tools that collected `GetTickCount` and `GetSystemTimeAsFileTime` data to detect sandbox or VMware services. |
| T1505.001 SQL Stored Procedures |
Campaign2016 Ukraine Electric Power Attack | During the 2016 Ukraine Electric Power Attack, Sandworm Team used various MS-SQL stored procedures. |
| T1505.003 Web Shell |
CampaignFrostyGoop Incident | FrostyGoop Incident deployed a ReGeorg variant web shell to impacted systems following initial access for persistence. |
| T1505.003 Web Shell |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors followed exploitation of SharePoint servers with installation of a malicious .aspx web shell (spinstall0.aspx) that was written to the `_layouts/15/` directory, granting persistent HTTP-based access. |
| T1505.003 Web Shell |
CampaignCutting Edge | During Cutting Edge, threat actors used multiple web shells to maintain presence on compromised Connect Secure appliances such as WIREFIRE, GLASSTOKEN, BUSHWALK, LIGHTWIRE, and FRAMESTING. |
| T1505.003 Web Shell |
CampaignOperation Digital Eye | During Operation Digital Eye, threat actors deployed a PHP-based webshell to maintain persistent access. |
| T1505.003 Web Shell |
CampaignHomeLand Justice | For HomeLand Justice, threat actors used .aspx webshells named pickers.aspx, error4.aspx, and ClientBin.aspx, to maintain persistence. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.