Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1087.002 Domain Account |
MalwareBoomBox | BoomBox has the ability to execute an LDAP query to enumerate the distinguished name, SAM account name, and display name for all domain users. |
| T1087.002 Domain Account |
MalwareLAMEHUG | LAMEHUG can use dsquery to enumerate domain user information. |
| T1087.002 Domain Account |
MalwareIceApple | The IceApple Active Directory Querier module can perform authenticated requests against an Active Directory server. |
| T1087.002 Domain Account |
MalwareQilin | Qilin can use PowerShell cmdlets to enumerate domain users. |
| T1087.002 Domain Account |
MalwareSoreFang | SoreFang can enumerate domain accounts via |
| T1087.002 Domain Account |
MalwareOSInfo | OSInfo enumerates local and domain users |
| T1087.002 Domain Account |
ToolNet | Net commands used with the |
| T1087.002 Domain Account |
ToolBloodHound | BloodHound can collect information about domain users, including identification of domain admin accounts. |
| T1087.002 Domain Account |
ToolSILENTTRINITY | SILENTTRINITY can use `System.Security.AccessControl` namespaces to retrieve domain user information. |
| T1087.002 Domain Account |
ToolEmpire | Empire can acquire local and domain user account information. |
| T1087.002 Domain Account |
Tooldsquery | dsquery can be used to gather information on user accounts within a domain. |
| T1087.002 Domain Account |
ToolPoshC2 | PoshC2 can enumerate local and domain user account information. |
| T1087.002 Domain Account |
ToolBrute Ratel C4 | Brute Ratel C4 can use LDAP queries, `net group "Domain Admins" /domain` and `net user /domain` for discovery. |
| T1087.002 Domain Account |
ToolCrackMapExec | CrackMapExec can enumerate the domain user accounts on a targeted system. |
| T1087.002 Domain Account |
ToolAdFind | AdFind can enumerate domain users. |
| T1087.003 Email Account |
CampaignHomeLand Justice | During HomeLand Justice, threat actors used compromised Exchange accounts to search mailboxes for administrator accounts. |
| T1087.003 Email Account |
CampaignC0027 | During C0027, Scattered Spider accessed Azure AD to identify email addresses. |
| T1087.003 Email Account |
GroupSandworm Team | Sandworm Team used malware to enumerate email settings, including usernames and passwords, from the M.E.Doc application. |
| T1087.003 Email Account |
GroupTA505 | TA505 has used the tool EmailStealer to steal and send lists of e-mail addresses to a remote server. |
| T1087.003 Email Account |
GroupRedCurl | RedCurl has collected information about email accounts. |
| T1087.003 Email Account |
GroupMagic Hound | Magic Hound has used Powershell to discover email accounts. |
| T1087.003 Email Account |
MalwareTrickBot | TrickBot collects email addresses from Outlook. |
| T1087.003 Email Account |
MalwareBackdoor.Oldrea | Backdoor.Oldrea collects address book information from Outlook. |
| T1087.003 Email Account |
MalwareEmotet | Emotet has been observed leveraging a module that can scrape email addresses from Outlook. |
| T1087.003 Email Account |
MalwareGrandoreiro | Grandoreiro can parse Outlook .pst files to extract e-mail addresses. |
| T1087.003 Email Account |
MalwareBoomBox | BoomBox can execute an LDAP query to discover e-mail accounts for domain users. |
| T1087.003 Email Account |
MalwareLizar | Lizar can collect email accounts from Microsoft Outlook and Mozilla Thunderbird. |
| T1087.003 Email Account |
ToolRuler | Ruler can be used to enumerate Exchange users and dump the GAL. |
| T1087.003 Email Account |
ToolMailSniper | MailSniper can be used to obtain account names from Exchange and Office 365 using the |
| T1087.003 Email Account |
MalwareKali365 | Kali365 has leveraged an Exchange Admin module that utilizes Graph to enumerate mailboxes in victim environments. |
| T1087.004 Cloud Account |
CampaignC0027 | During C0027, Scattered Spider accessed Azure AD to download bulk lists of group members and to identify privileged users, along with the email addresses and AD attributes. |
| T1087.004 Cloud Account |
GroupStorm-0501 | Storm-0501 has conducted enumeration of users, roles, and resources within victim Azure tenants using the tool Azurehound. |
| T1087.004 Cloud Account |
GroupAPT29 | APT29 has conducted enumeration of Azure AD accounts. |
| T1087.004 Cloud Account |
ToolPacu | Pacu can enumerate IAM users, roles, and groups. |
| T1087.004 Cloud Account |
ToolAADInternals | AADInternals can enumerate Azure AD users. |
| T1087.004 Cloud Account |
ToolROADTools | ROADTools can enumerate Azure AD users. |
| T1087.004 Cloud Account |
MalwareMini Shai-Hulud | Mini Shai-Hulud has enumerated cloud accounts and subscriptions accessible to the targeted identity. |
| T1090 Proxy |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors used Fast Reverse Proxy to communicate with C2. |
| T1090 Proxy |
CampaignRedDelta Modified PlugX Infection Chain Operations | Mustang Panda proxied communication through the Cloudflare CDN service during RedDelta Modified PlugX Infection Chain Operations. |
| T1090 Proxy |
CampaignRedPenguin | During RedPenguin, UNC3886 used malware capable of establishing a SOCKS proxy connection to a specified IP and port. |
| T1090 Proxy |
CampaignOperation Sharpshooter | For Operation Sharpshooter, the threat actors used the ExpressVPN service to hide their location. |
| T1090 Proxy |
CampaignOperation MidnightEclipse | During Operation MidnightEclipse, threat actors used the GO Simple Tunnel reverse proxy tool. |
| T1090 Proxy |
CampaignSalesforce Data Exfiltration | During Salesforce Data Exfiltration, threat actors used Mullvad VPN IPs to proxy voice phishing calls. |
| T1090 Proxy |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries utilized the rsocx tool identified as `r.exe` and `rsocx.exe` to tunnel within the internal infrastructure using a Reverse SOCKS Proxy. |
| T1090 Proxy |
CampaignOperation Wocao | During Operation Wocao, threat actors used a custom proxy tool called "Agent" which has support for multiple hops. |
| T1090 Proxy |
CampaignC0017 | During C0017, APT41 used the Cloudflare CDN to proxy C2 traffic. |
| T1090 Proxy |
CampaignC0027 | During C0027, Scattered Spider installed the open-source rsocx reverse proxy tool on a targeted ESXi appliance. |
| T1090 Proxy |
GroupVolt Typhoon | Volt Typhoon has used compromised devices and customized versions of open source tools such as FRP (Fast Reverse Proxy), Earthworm, and Impacket to proxy network traffic. |
| T1090 Proxy |
GroupAPT41 | APT41 used a tool called CLASSFON to covertly proxy network communications. |
| T1090 Proxy |
GroupMuddyWater | MuddyWater has used NordVPN to proxy phishing emails, making them appear to originate from France. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.