Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1210 Exploitation of Remote Services |
MalwareLucifer | Lucifer can exploit multiple vulnerabilities including EternalBlue (CVE-2017-0144) and EternalRomance (CVE-2017-0144). |
| T1210 Exploitation of Remote Services |
MalwareNotPetya | NotPetya can use two exploits in SMBv1, EternalBlue and EternalRomance, to spread itself to other remote systems on the network. |
| T1210 Exploitation of Remote Services |
MalwareConficker | Conficker exploited the MS08-067 Windows vulnerability for remote code execution through a crafted RPC request. |
| T1210 Exploitation of Remote Services |
MalwareWannaCry | WannaCry uses an exploit in SMBv1 to spread itself to other remote systems on a network. |
| T1210 Exploitation of Remote Services |
MalwareQakBot | QakBot can move laterally using worm-like functionality through exploitation of SMB. |
| T1210 Exploitation of Remote Services |
ToolEmpire | Empire has a limited number of built-in modules for exploiting remote SMB, JBoss, and Jenkins servers. |
| T1210 Exploitation of Remote Services |
ToolPoshC2 | PoshC2 contains a module for exploiting SMB via EternalBlue. |
| T1210 Exploitation of Remote Services |
MalwareFlame | Flame can use MS10-061 to exploit a print spooler vulnerability in a remote system with a shared printer in order to move laterally. |
| T1213 Data from Information Repositories |
MalwareRaccoon Stealer | Raccoon Stealer gathers information from repositories associated with cryptocurrency wallets and the Telegram messaging service. |
| T1213 Data from Information Repositories |
MalwareTroll Stealer | Troll Stealer gathers information from the Government Public Key Infrastructure (GPKI) folder, associated with South Korean government public key infrastructure, on infected systems. |
| T1213.001 Confluence |
ToolTruffleHog | TruffleHog has collected credentials and data associated with Confluence. |
| T1213.002 Sharepoint |
Toolspwebmember | spwebmember is used to enumerate and dump information from Microsoft SharePoint. |
| T1213.002 Sharepoint |
ToolTruffleHog | TruffleHog has searched SharePoint for data and credentials. |
| T1213.003 Code Repositories |
MalwareGlassWorm | GlassWorm has gathered code repository authentication materials for NPM and GitHub. GlassWorm has collected details pertaining to the npm configuration data for `_authToken`. |
| T1213.003 Code Repositories |
MalwareShai-Hulud | Shai-Hulud has downloaded existing packages from code repositories and extracted data stored within them. |
| T1213.003 Code Repositories |
ToolTruffleHog | TruffleHog has gathered data and credentials from code repositories. |
| T1213.003 Code Repositories |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer can target sensitive file paths in Git repos to extract credentials. |
| T1213.003 Code Repositories |
MalwareMini Shai-Hulud | Mini Shai-Hulud has gathered and downloaded data stored on both compromised and publicly accessible code repositories. |
| T1213.005 Messaging Applications |
ToolTruffleHog | TruffleHog has obtained data and credentials associated with messaging applications to include Slack. |
| T1213.006 Databases |
MalwareP.A.S. Webshell | P.A.S. Webshell has the ability to list and extract data from SQL databases. |
| T1213.006 Databases |
MalwareGlassWorm | GlassWorm has collected data from macOS devices through the gathering of Apple Notes related files by targeting `/Library/Group Containers/group.com.apple.notes/NoteStore.sqlite`, `/Library/Group Containers/group.com.apple.notes/NoteStore.sqlite-wal`, and `/Library/Group Containers/group.com.apple.notes/NoteStore.sqlite-shm`. |
| T1213.006 Databases |
MalwareMgBot | MgBot includes a module capable of stealing content from the Tencent QQ database storing user QQ message history on infected devices. |
| T1213.006 Databases |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer can extract credentials from multiple database configuration files including ~/.pgpass, ~/.my.cnf, ~/.mongorc.js, and /etc/mysql/my.cnf. |
| T1217 Browser Information Discovery |
MalwareMachete | Machete retrieves the user profile data (e.g., browsers) from Chrome and Firefox browsers. |
| T1217 Browser Information Discovery |
MalwarePowerLess | PowerLess has a browser info stealer module that can read Chrome and Edge browser database files. |
| T1217 Browser Information Discovery |
MalwareMafalda | Mafalda can collect the contents of the `%USERPROFILE%\AppData\Local\Google\Chrome\User Data\LocalState` file. |
| T1217 Browser Information Discovery |
MalwareCuckoo Stealer | Cuckoo Stealer can collect bookmarks, cookies, and history from Safari. |
| T1217 Browser Information Discovery |
MalwareMobileOrder | MobileOrder has a command to upload to its C2 server victim browser bookmarks. |
| T1217 Browser Information Discovery |
MalwareMispadu | Mispadu can monitor browser activity for online banking actions and display full-screen overlay images to block user access to the intended site or present additional data fields. |
| T1217 Browser Information Discovery |
MalwareLightSpy | To collect data on the host's Wi-Fi connection history, LightSpy reads the `/Library/Preferences/SystemConfiguration/com.apple.airport.preferences.plist` file. It also utilizes Apple's `CWWiFiClient` API to scan for nearby Wi-Fi networks and obtain data on the SSID, security type, and RSSI (signal strength) values. |
| T1217 Browser Information Discovery |
MalwareBeaverTail | BeaverTail has searched the victim device for browser extensions including those commonly associated with cryptocurrency wallets. ESET Contagious Interview BeaverTail InvisibleFerret February 2025Esentire ContagiousInterview BeaverTail InvisibleFerret November 2024PaloAlto ContagiousInterview BeaverTail InvisibleFerret November 2023PaloAlto Unit42 ContagiousInterview BeaverTail InvisibileFerret October 2024Recorded Future Contagious Inteview BeaverTail InvisibleFerret OtterCookie February 2025Socket BeaverTail XORIndex HexEval Contagious Interview July 2025Socket HexEval BeaverTail Contagious Interview June 2025 |
| T1217 Browser Information Discovery |
MalwareDarkWatchman | DarkWatchman can retrieve browser history. |
| T1217 Browser Information Discovery |
MalwareLumma Stealer | Lumma Stealer has identified and gathered information from two-factor authentication extensions for multiple browsers. |
| T1217 Browser Information Discovery |
MalwareGlassWorm | GlassWorm has searched browser data for cookies, history, login databases, and cryptocurrency wallets. |
| T1217 Browser Information Discovery |
MalwareRedLine Stealer | RedLine Stealer can collect information from browsers and browser extensions. |
| T1217 Browser Information Discovery |
MalwareSUGARDUMP | SUGARDUMP has collected browser bookmark and history information. |
| T1217 Browser Information Discovery |
MalwareCalisto | Calisto collects information on bookmarks from Google Chrome. |
| T1217 Browser Information Discovery |
MalwareTroll Stealer | Troll Stealer collects information from Chromium-based browsers and Firefox such as cookies, history, downloads, and extensions. |
| T1217 Browser Information Discovery |
MalwareLizar | Lizar can retrieve browser history and database files. |
| T1217 Browser Information Discovery |
MalwareDtrack | Dtrack can retrieve browser history. |
| T1217 Browser Information Discovery |
ToolEmpire | Empire has the ability to gather browser data such as bookmarks and visited sites. |
| T1218.001 Compiled HTML File |
MalwareAstaroth | Astaroth uses ActiveX objects for file execution and manipulation. |
| T1218.002 Control Panel |
MalwareInvisiMole | InvisiMole can register itself for execution and persistence via the Control Panel. |
| T1218.002 Control Panel |
MalwareReaver | Reaver drops and executes a malicious CPL file as its payload. |
| T1218.003 CMSTP |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP can use CMSTP.exe to install a malicious Microsoft Connection Manager Profile. |
| T1218.003 CMSTP |
MalwareLockBit 3.0 | LockBit 3.0 can attempt a CMSTP UAC bypass if it does not have administrative privileges. |
| T1218.004 InstallUtil |
MalwareWhisperGate | WhisperGate has used `InstallUtil.exe` as part of its process to disable Windows Defender. |
| T1218.004 InstallUtil |
MalwareSaint Bot | Saint Bot had used `InstallUtil.exe` to download and deploy executables. |
| T1218.004 InstallUtil |
MalwareChaes | Chaes has used Installutill to download content. |
| T1218.004 InstallUtil |
ToolCovenant | Covenant can create launchers via an InstallUtil XML file to install new Grunt listeners. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.