Real-world descriptions of how a group, tool or campaign used a technique.
1146 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1505.003 Web Shell |
CampaignC0032 | During the C0032 campaign, TEMP.Veles planted Web shells on Outlook Exchange servers. |
| T1505.003 Web Shell |
CampaignOperation CuckooBees | During Operation CuckooBees, the threat actors generated a web shell within a vulnerable Enterprise Resource Planning Web Application Server as a persistence mechanism. |
| T1505.003 Web Shell |
CampaignAPT41 DUST | APT41 DUST involved use of web shells such as ANTSWORD and BLUEBEAM for persistence. |
| T1505.003 Web Shell |
CampaignVersa Director Zero Day Exploitation | Versa Director Zero Day Exploitation resulted in the deployment of the VersaMem web shell for follow-on activity. |
| T1505.003 Web Shell |
CampaignOperation Wocao | During Operation Wocao, threat actors used their own web shells, as well as those previously placed on target systems by other threat actors, for reconnaissance and lateral movement. |
| T1505.003 Web Shell |
CampaignLeviathan Australian Intrusions | Leviathan relied extensively on web shell use following initial access for persistence and command execution purposes in victim environments during Leviathan Australian Intrusions. |
| T1505.003 Web Shell |
CampaignC0017 | During C0017, APT41 deployed JScript web shells through the creation of malicious ViewState objects. |
| T1505.003 Web Shell |
Campaign2022 Ukraine Electric Power Attack | During the 2022 Ukraine Electric Power Attack, Sandworm Team deployed the Neo-REGEORG webshell on an internet-facing server. |
| T1505.004 IIS Components |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group targeted Windows servers running Internet Information Systems (IIS) to install C2 components. |
| T1505.004 IIS Components |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors modified Internet Information Services (IIS) components to load suspicious .NET assemblies for persistence. |
| T1518 Software Discovery |
CampaignOperation Dust Storm | During Operation Dust Storm, the threat actors deployed a file called `DeployJava.js` to fingerprint installed software on a victim system prior to exploit delivery. |
| T1518 Software Discovery |
CampaignJuicy Mix | During Juicy Mix, OilRig used browser data dumper tools to create a list of users with Google Chrome installed. |
| T1518 Software Discovery |
CampaignOperation Wocao | During Operation Wocao, threat actors collected a list of installed software on the infected system. |
| T1518.001 Security Software Discovery |
CampaignKV Botnet Activity | KV Botnet Activity involved removal of security tools, as well as other identified IOT malware, from compromised devices. |
| T1518.001 Security Software Discovery |
CampaignFrankenstein | During Frankenstein, the threat actors used WMI queries to determine if analysis tools were running on a compromised system. |
| T1518.001 Security Software Discovery |
CampaignOperation Wocao | During Operation Wocao, threat actors used scripts to detect security software. |
| T1528 Steal Application Access Token |
CampaignLeviathan Australian Intrusions | Leviathan abused access to compromised appliances to collect JSON Web Tokens (JWTs), used for creating virtual desktop sessions, during Leviathan Australian Intrusions. |
| T1529 System Shutdown/Reboot |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries forced victim devices to reboot to finalize destruction of impacted systems. |
| T1530 Data from Cloud Storage |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries leveraged stolen credentials within cloud services to download targeted data from SharePoint, and Teams. |
| T1530 Data from Cloud Storage |
CampaignC0027 | During C0027, Scattered Spider accessed victim OneDrive environments to search for VPN and MFA enrollment information, help desk instructions, and new hire guides. |
| T1534 Internal Spearphishing |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group conducted internal spearphishing from within a compromised organization. |
| T1539 Steal Web Session Cookie |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 stole Chrome browser cookies by copying the Chrome profile directories of targeted users. |
| T1543.002 Systemd Service |
Campaign2022 Ukraine Electric Power Attack | During the 2022 Ukraine Electric Power Attack, Sandworm Team configured Systemd to maintain persistence of GOGETTER, specifying the `WantedBy=multi-user.target` configuration to run GOGETTER when the system begins accepting user logins. |
| T1543.003 Windows Service |
CampaignOperation Honeybee | During Operation Honeybee, threat actors installed DLLs and backdoors as Windows services. |
| T1543.003 Windows Service |
CampaignOperation Digital Eye | During Operation Digital Eye, threat actors created a service named Visual Studio Code Service to run Visual Studio code. |
| T1543.003 Windows Service |
CampaignOperation CuckooBees | During Operation CuckooBees, the threat actors modified the `IKEEXT` and `PrintNotify` Windows services for persistence. |
| T1543.003 Windows Service |
Campaign2016 Ukraine Electric Power Attack | During the 2016 Ukraine Electric Power Attack, Sandworm Team used an arbitrary system service to load at system boot for persistence for Industroyer. They also replaced the ImagePath registry value of a Windows service with a new backdoor binary. |
| T1543.003 Windows Service |
CampaignAPT41 DUST | APT41 DUST used Windows Services with names such as `Windows Defend` for persistence of DUSTPAN. |
| T1543.004 Launch Daemon |
Campaign3CX Supply Chain Attack | During the 3CX Supply Chain Attack, AppleJeus installs a Launch Daemon to execute the POOLRAT macOS backdoor software. |
| T1546 Event Triggered Execution |
CampaignKV Botnet Activity | KV Botnet Activity involves managing events on victim systems via |
| T1546.003 Windows Management Instrumentation Event Subscription |
CampaignOperation Ghost | During Operation Ghost, APT29 used WMI event subscriptions to establish persistence for malware. |
| T1546.003 Windows Management Instrumentation Event Subscription |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used a WMI event filter to invoke a command-line event consumer at system boot time to launch a backdoor with `rundll32.exe`. |
| T1546.004 Unix Shell Configuration Modification |
CampaignShadowRay | During ShadowRay, threat actors executed commands on interactive and reverse shells. |
| T1546.012 Image File Execution Options Injection |
CampaignC0032 | During the C0032 campaign, TEMP.Veles modified and added entries within |
| T1546.016 Installer Packages |
Campaign3CX Supply Chain Attack | During the 3CX Supply Chain Attack, AppleJeus added a malicious .dylib file to a .dmg installer package for the macOS 3CX application. |
| T1547.001 Registry Run Keys / Startup Folder |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group placed LNK files into the victims' startup folder for persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
CampaignRedDelta Modified PlugX Infection Chain Operations | Mustang Panda used Run registry keys with names such as `OneNote Update` to execute legitimate executables that would load through search-order hijacking malicious DLLS to ensure persistence during RedDelta Modified PlugX Infection Chain Operations. |
| T1547.001 Registry Run Keys / Startup Folder |
CampaignOperation Sharpshooter | During Operation Sharpshooter, a first-stage downloader installed Rising Sun to `%Startup%\mssync.exe` on a compromised host. |
| T1547.006 Kernel Modules and Extensions |
CampaignOperation CuckooBees | During Operation CuckooBees, attackers used a signed kernel rootkit to establish additional persistence. |
| T1548.002 Bypass User Account Control |
CampaignOperation Honeybee | During Operation Honeybee, the threat actors used the malicious NTWDBLIB.DLL and `cliconfig.exe` to bypass UAC protections. |
| T1550 Use Alternate Authentication Material |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used forged SAML tokens that allowed the actors to impersonate users and bypass MFA, enabling APT29 to access enterprise cloud applications and services. |
| T1550.001 Application Access Token |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used compromised service principals to make changes to the Office 365 environment. |
| T1550.002 Pass the Hash |
CampaignOperation Digital Eye | During Operation Digital Eye, threat actors used a pass-the-hash capability to move laterally. |
| T1550.002 Pass the Hash |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries attempted to reuse password hash values to gain access to other systems. |
| T1550.002 Pass the Hash |
CampaignNight Dragon | During Night Dragon, threat actors used pass-the-hash tools to obtain authenticated access to sensitive internal desktops and servers. |
| T1550.004 Web Session Cookie |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used stolen cookies to access cloud resources and a forged `duo-sid` cookie to bypass MFA set on an email account. |
| T1552 Unsecured Credentials |
CampaignLeviathan Australian Intrusions | Leviathan gathered credentials hardcoded in binaries located on victim devices during Leviathan Australian Intrusions. |
| T1552.001 Credentials In Files |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors accessed web.config and machine.config to extract MachineKey values, enabling them to forge legitimate VIEWSTATE tokens for future deserialization payloads. |
| T1552.001 Credentials In Files |
CampaignAnthropic AI-orchestrated Campaign | During the Anthropic AI-orchestrated Campaign, the adversary used Claude Code to extract authentication certificates stored in system configuration files across compromised environments. |
| T1552.001 Credentials In Files |
CampaignLeviathan Australian Intrusions | Leviathan gathered credentials stored in files related to Building Management System (BMS) operations during Leviathan Australian Intrusions. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.