ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1087.002
Domain Account
MalwareBoomBox

BoomBox has the ability to execute an LDAP query to enumerate the distinguished name, SAM account name, and display name for all domain users.

T1087.002
Domain Account
MalwareLAMEHUG

LAMEHUG can use dsquery to enumerate domain user information.

T1087.002
Domain Account
MalwareIceApple

The IceApple Active Directory Querier module can perform authenticated requests against an Active Directory server.

T1087.002
Domain Account
MalwareQilin

Qilin can use PowerShell cmdlets to enumerate domain users.

T1087.002
Domain Account
MalwareSoreFang

SoreFang can enumerate domain accounts via net.exe user /domain.

T1087.002
Domain Account
MalwareOSInfo

OSInfo enumerates local and domain users

T1087.002
Domain Account
ToolNet

Net commands used with the /domain flag can be used to gather information about and manipulate user accounts on the current domain.

T1087.002
Domain Account
ToolBloodHound

BloodHound can collect information about domain users, including identification of domain admin accounts.

T1087.002
Domain Account
ToolSILENTTRINITY

SILENTTRINITY can use `System.Security.AccessControl` namespaces to retrieve domain user information.

T1087.002
Domain Account
ToolEmpire

Empire can acquire local and domain user account information.

T1087.002
Domain Account
Tooldsquery

dsquery can be used to gather information on user accounts within a domain.

T1087.002
Domain Account
ToolPoshC2

PoshC2 can enumerate local and domain user account information.

T1087.002
Domain Account
ToolBrute Ratel C4

Brute Ratel C4 can use LDAP queries, `net group "Domain Admins" /domain` and `net user /domain` for discovery.

T1087.002
Domain Account
ToolCrackMapExec

CrackMapExec can enumerate the domain user accounts on a targeted system.

T1087.002
Domain Account
ToolAdFind

AdFind can enumerate domain users.

T1087.003
Email Account
CampaignHomeLand Justice

During HomeLand Justice, threat actors used compromised Exchange accounts to search mailboxes for administrator accounts.

T1087.003
Email Account
CampaignC0027

During C0027, Scattered Spider accessed Azure AD to identify email addresses.

T1087.003
Email Account
GroupSandworm Team

Sandworm Team used malware to enumerate email settings, including usernames and passwords, from the M.E.Doc application.

T1087.003
Email Account
GroupTA505

TA505 has used the tool EmailStealer to steal and send lists of e-mail addresses to a remote server.

T1087.003
Email Account
GroupRedCurl

RedCurl has collected information about email accounts.

T1087.003
Email Account
GroupMagic Hound

Magic Hound has used Powershell to discover email accounts.

T1087.003
Email Account
MalwareTrickBot

TrickBot collects email addresses from Outlook.

T1087.003
Email Account
MalwareBackdoor.Oldrea

Backdoor.Oldrea collects address book information from Outlook.

T1087.003
Email Account
MalwareEmotet

Emotet has been observed leveraging a module that can scrape email addresses from Outlook.

T1087.003
Email Account
MalwareGrandoreiro

Grandoreiro can parse Outlook .pst files to extract e-mail addresses.

T1087.003
Email Account
MalwareBoomBox

BoomBox can execute an LDAP query to discover e-mail accounts for domain users.

T1087.003
Email Account
MalwareLizar

Lizar can collect email accounts from Microsoft Outlook and Mozilla Thunderbird.

T1087.003
Email Account
ToolRuler

Ruler can be used to enumerate Exchange users and dump the GAL.

T1087.003
Email Account
ToolMailSniper

MailSniper can be used to obtain account names from Exchange and Office 365 using the Get-GlobalAddressList cmdlet.

T1087.003
Email Account
MalwareKali365

Kali365 has leveraged an Exchange Admin module that utilizes Graph to enumerate mailboxes in victim environments.

T1087.004
Cloud Account
CampaignC0027

During C0027, Scattered Spider accessed Azure AD to download bulk lists of group members and to identify privileged users, along with the email addresses and AD attributes.

T1087.004
Cloud Account
GroupStorm-0501

Storm-0501 has conducted enumeration of users, roles, and resources within victim Azure tenants using the tool Azurehound.

T1087.004
Cloud Account
GroupAPT29

APT29 has conducted enumeration of Azure AD accounts.

T1087.004
Cloud Account
ToolPacu

Pacu can enumerate IAM users, roles, and groups.

T1087.004
Cloud Account
ToolAADInternals

AADInternals can enumerate Azure AD users.

T1087.004
Cloud Account
ToolROADTools

ROADTools can enumerate Azure AD users.

T1087.004
Cloud Account
MalwareMini Shai-Hulud

Mini Shai-Hulud has enumerated cloud accounts and subscriptions accessible to the targeted identity.

T1090
Proxy
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors used Fast Reverse Proxy to communicate with C2.

T1090
Proxy
CampaignRedDelta Modified PlugX Infection Chain Operations

Mustang Panda proxied communication through the Cloudflare CDN service during RedDelta Modified PlugX Infection Chain Operations.

T1090
Proxy
CampaignRedPenguin

During RedPenguin, UNC3886 used malware capable of establishing a SOCKS proxy connection to a specified IP and port.

T1090
Proxy
CampaignOperation Sharpshooter

For Operation Sharpshooter, the threat actors used the ExpressVPN service to hide their location.

T1090
Proxy
CampaignOperation MidnightEclipse

During Operation MidnightEclipse, threat actors used the GO Simple Tunnel reverse proxy tool.

T1090
Proxy
CampaignSalesforce Data Exfiltration

During Salesforce Data Exfiltration, threat actors used Mullvad VPN IPs to proxy voice phishing calls.

T1090
Proxy
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries utilized the rsocx tool identified as `r.exe` and `rsocx.exe` to tunnel within the internal infrastructure using a Reverse SOCKS Proxy.

T1090
Proxy
CampaignOperation Wocao

During Operation Wocao, threat actors used a custom proxy tool called "Agent" which has support for multiple hops.

T1090
Proxy
CampaignC0017

During C0017, APT41 used the Cloudflare CDN to proxy C2 traffic.

T1090
Proxy
CampaignC0027

During C0027, Scattered Spider installed the open-source rsocx reverse proxy tool on a targeted ESXi appliance.

T1090
Proxy
GroupVolt Typhoon

Volt Typhoon has used compromised devices and customized versions of open source tools such as FRP (Fast Reverse Proxy), Earthworm, and Impacket to proxy network traffic.

T1090
Proxy
GroupAPT41

APT41 used a tool called CLASSFON to covertly proxy network communications.

T1090
Proxy
GroupMuddyWater

MuddyWater has used NordVPN to proxy phishing emails, making them appear to originate from France.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.