ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

1146 examples

TechniqueUsed byProcedure example
T1505.003
Web Shell
CampaignC0032

During the C0032 campaign, TEMP.Veles planted Web shells on Outlook Exchange servers.

T1505.003
Web Shell
CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors generated a web shell within a vulnerable Enterprise Resource Planning Web Application Server as a persistence mechanism.

T1505.003
Web Shell
CampaignAPT41 DUST

APT41 DUST involved use of web shells such as ANTSWORD and BLUEBEAM for persistence.

T1505.003
Web Shell
CampaignVersa Director Zero Day Exploitation

Versa Director Zero Day Exploitation resulted in the deployment of the VersaMem web shell for follow-on activity.

T1505.003
Web Shell
CampaignOperation Wocao

During Operation Wocao, threat actors used their own web shells, as well as those previously placed on target systems by other threat actors, for reconnaissance and lateral movement.

T1505.003
Web Shell
CampaignLeviathan Australian Intrusions

Leviathan relied extensively on web shell use following initial access for persistence and command execution purposes in victim environments during Leviathan Australian Intrusions.

T1505.003
Web Shell
CampaignC0017

During C0017, APT41 deployed JScript web shells through the creation of malicious ViewState objects.

T1505.003
Web Shell
Campaign2022 Ukraine Electric Power Attack

During the 2022 Ukraine Electric Power Attack, Sandworm Team deployed the Neo-REGEORG webshell on an internet-facing server.

T1505.004
IIS Components
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group targeted Windows servers running Internet Information Systems (IIS) to install C2 components.

T1505.004
IIS Components
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors modified Internet Information Services (IIS) components to load suspicious .NET assemblies for persistence.

T1518
Software Discovery
CampaignOperation Dust Storm

During Operation Dust Storm, the threat actors deployed a file called `DeployJava.js` to fingerprint installed software on a victim system prior to exploit delivery.

T1518
Software Discovery
CampaignJuicy Mix

During Juicy Mix, OilRig used browser data dumper tools to create a list of users with Google Chrome installed.

T1518
Software Discovery
CampaignOperation Wocao

During Operation Wocao, threat actors collected a list of installed software on the infected system.

T1518.001
Security Software Discovery
CampaignKV Botnet Activity

KV Botnet Activity involved removal of security tools, as well as other identified IOT malware, from compromised devices.

T1518.001
Security Software Discovery
CampaignFrankenstein

During Frankenstein, the threat actors used WMI queries to determine if analysis tools were running on a compromised system.

T1518.001
Security Software Discovery
CampaignOperation Wocao

During Operation Wocao, threat actors used scripts to detect security software.

T1528
Steal Application Access Token
CampaignLeviathan Australian Intrusions

Leviathan abused access to compromised appliances to collect JSON Web Tokens (JWTs), used for creating virtual desktop sessions, during Leviathan Australian Intrusions.

T1529
System Shutdown/Reboot
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries forced victim devices to reboot to finalize destruction of impacted systems.

T1530
Data from Cloud Storage
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries leveraged stolen credentials within cloud services to download targeted data from SharePoint, and Teams.

T1530
Data from Cloud Storage
CampaignC0027

During C0027, Scattered Spider accessed victim OneDrive environments to search for VPN and MFA enrollment information, help desk instructions, and new hire guides.

T1534
Internal Spearphishing
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group conducted internal spearphishing from within a compromised organization.

T1539
Steal Web Session Cookie
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 stole Chrome browser cookies by copying the Chrome profile directories of targeted users.

T1543.002
Systemd Service
Campaign2022 Ukraine Electric Power Attack

During the 2022 Ukraine Electric Power Attack, Sandworm Team configured Systemd to maintain persistence of GOGETTER, specifying the `WantedBy=multi-user.target` configuration to run GOGETTER when the system begins accepting user logins.

T1543.003
Windows Service
CampaignOperation Honeybee

During Operation Honeybee, threat actors installed DLLs and backdoors as Windows services.

T1543.003
Windows Service
CampaignOperation Digital Eye

During Operation Digital Eye, threat actors created a service named Visual Studio Code Service to run Visual Studio code.

T1543.003
Windows Service
CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors modified the `IKEEXT` and `PrintNotify` Windows services for persistence.

T1543.003
Windows Service
Campaign2016 Ukraine Electric Power Attack

During the 2016 Ukraine Electric Power Attack, Sandworm Team used an arbitrary system service to load at system boot for persistence for Industroyer. They also replaced the ImagePath registry value of a Windows service with a new backdoor binary.

T1543.003
Windows Service
CampaignAPT41 DUST

APT41 DUST used Windows Services with names such as `Windows Defend` for persistence of DUSTPAN.

T1543.004
Launch Daemon
Campaign3CX Supply Chain Attack

During the 3CX Supply Chain Attack, AppleJeus installs a Launch Daemon to execute the POOLRAT macOS backdoor software.

T1546
Event Triggered Execution
CampaignKV Botnet Activity

KV Botnet Activity involves managing events on victim systems via libevent to execute a callback function when any running process contains the following references in their path without also having a reference to bioset: busybox, wget, curl, tftp, telnetd, or lua. If the bioset string is not found, the related process is terminated.

T1546.003
Windows Management Instrumentation Event Subscription
CampaignOperation Ghost

During Operation Ghost, APT29 used WMI event subscriptions to establish persistence for malware.

T1546.003
Windows Management Instrumentation Event Subscription
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used a WMI event filter to invoke a command-line event consumer at system boot time to launch a backdoor with `rundll32.exe`.

T1546.004
Unix Shell Configuration Modification
CampaignShadowRay

During ShadowRay, threat actors executed commands on interactive and reverse shells.

T1546.012
Image File Execution Options Injection
CampaignC0032

During the C0032 campaign, TEMP.Veles modified and added entries within HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options to maintain persistence.

T1546.016
Installer Packages
Campaign3CX Supply Chain Attack

During the 3CX Supply Chain Attack, AppleJeus added a malicious .dylib file to a .dmg installer package for the macOS 3CX application.

T1547.001
Registry Run Keys / Startup Folder
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group placed LNK files into the victims' startup folder for persistence.

T1547.001
Registry Run Keys / Startup Folder
CampaignRedDelta Modified PlugX Infection Chain Operations

Mustang Panda used Run registry keys with names such as `OneNote Update` to execute legitimate executables that would load through search-order hijacking malicious DLLS to ensure persistence during RedDelta Modified PlugX Infection Chain Operations.

T1547.001
Registry Run Keys / Startup Folder
CampaignOperation Sharpshooter

During Operation Sharpshooter, a first-stage downloader installed Rising Sun to `%Startup%\mssync.exe` on a compromised host.

T1547.006
Kernel Modules and Extensions
CampaignOperation CuckooBees

During Operation CuckooBees, attackers used a signed kernel rootkit to establish additional persistence.

T1548.002
Bypass User Account Control
CampaignOperation Honeybee

During Operation Honeybee, the threat actors used the malicious NTWDBLIB.DLL and `cliconfig.exe` to bypass UAC protections.

T1550
Use Alternate Authentication Material
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used forged SAML tokens that allowed the actors to impersonate users and bypass MFA, enabling APT29 to access enterprise cloud applications and services.

T1550.001
Application Access Token
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used compromised service principals to make changes to the Office 365 environment.

T1550.002
Pass the Hash
CampaignOperation Digital Eye

During Operation Digital Eye, threat actors used a pass-the-hash capability to move laterally.

T1550.002
Pass the Hash
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries attempted to reuse password hash values to gain access to other systems.

T1550.002
Pass the Hash
CampaignNight Dragon

During Night Dragon, threat actors used pass-the-hash tools to obtain authenticated access to sensitive internal desktops and servers.

T1550.004
Web Session Cookie
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used stolen cookies to access cloud resources and a forged `duo-sid` cookie to bypass MFA set on an email account.

T1552
Unsecured Credentials
CampaignLeviathan Australian Intrusions

Leviathan gathered credentials hardcoded in binaries located on victim devices during Leviathan Australian Intrusions.

T1552.001
Credentials In Files
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors accessed web.config and machine.config to extract MachineKey values, enabling them to forge legitimate VIEWSTATE tokens for future deserialization payloads.

T1552.001
Credentials In Files
CampaignAnthropic AI-orchestrated Campaign

During the Anthropic AI-orchestrated Campaign, the adversary used Claude Code to extract authentication certificates stored in system configuration files across compromised environments.

T1552.001
Credentials In Files
CampaignLeviathan Australian Intrusions

Leviathan gathered credentials stored in files related to Building Management System (BMS) operations during Leviathan Australian Intrusions.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.