ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

1146 examples

TechniqueUsed byProcedure example
T1552.004
Private Keys
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 obtained PKI keys, certificate files, and the private encryption key from an Active Directory Federation Services (AD FS) container to decrypt corresponding SAML signing certificates.

T1552.004
Private Keys
CampaignOperation Wocao

During Operation Wocao, threat actors used Mimikatz to dump certificates and private keys from the Windows certificate store.

T1553.002
Code Signing
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group digitally signed their own malware to evade detection.

T1553.002
Code Signing
CampaignRedDelta Modified PlugX Infection Chain Operations

Mustang Panda used legitimate, signed binaries such as `inkform.exe` or `ExcelRepairToolboxLauncher.exe` for follow-on execution of malicious DLLs through DLL search order hijacking in RedDelta Modified PlugX Infection Chain Operations.

T1553.002
Code Signing
CampaignOperation Honeybee

During Operation Honeybee, the threat actors deployed the MaoCheng dropper with a stolen Adobe Systems digital signature.

T1553.002
Code Signing
Campaign3CX Supply Chain Attack

Although the X_TRADER platform was reportedly discontinued in 2020, it was still available for download from the legitimate Trading Technologies website in 2022. During the 3CX Supply Chain Attack, AppleJeus used a code signing certificate to digitally sign the malicious software with an expiration date set to October 2022. This file was signed with the subject “Trading Technologies International, Inc” and contained the executable file Setup.exe, also signed with the same digital certificate.

T1553.002
Code Signing
CampaignC0015

For C0015, the threat actors used DLL files that had invalid certificates.

T1553.002
Code Signing
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 was able to get SUNBURST signed by SolarWinds code signing certificates by injecting the malware into the SolarWinds Orion software lifecycle.

T1553.002
Code Signing
CampaignOperation AkaiRyū

During Operation AkaiRyū, MirrorFace abused a signed McAfee executable to load UPPERCUT.

T1553.002
Code Signing
CampaignAPT41 DUST

APT41 DUST used stolen code signing certificates for DUSTTRAP malware and subsequent payloads.

T1554
Compromise Host Software Binary
CampaignRedPenguin

During RedPenguin, UNC3886 peformed a local memory patching attack to modify the snmpd and mgd Junos OS daemons.

T1554
Compromise Host Software Binary
CampaignCutting Edge

During Cutting Edge, threat actors trojanized legitimate files in Ivanti Connect Secure appliances with malicious code.

T1554
Compromise Host Software Binary
Campaign2016 Ukraine Electric Power Attack

During the 2016 Ukraine Electric Power Attack, Sandworm Team used a trojanized version of Windows Notepad to add a layer of persistence for Industroyer.

T1555
Credentials from Password Stores
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used account credentials they obtained to attempt access to Group Managed Service Account (gMSA) passwords.

T1555
Credentials from Password Stores
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries configured a native CLI to gather a targeted elevated users password using `grep`.

T1555.003
Credentials from Web Browsers
CampaignJuicy Mix

During Juicy Mix, OilRig used the CDumper (Chrome browser) and EDumper (Edge browser) to collect credentials.

T1555.003
Credentials from Web Browsers
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 stole users' saved passwords from Chrome.

T1555.004
Windows Credential Manager
CampaignJuicy Mix

During Juicy Mix, OilRig used a Windows Credential Manager stealer for credential access.

T1555.005
Password Managers
CampaignOperation Wocao

During Operation Wocao, threat actors accessed and collected credentials from password managers.

T1556
Modify Authentication Process
CampaignArcaneDoor

ArcaneDoor included modification of the AAA process to bypass authentication mechanisms.

T1556.006
Multi-Factor Authentication
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries modified two-factor settings within the FortiGate solution to `unset`.

T1557
Adversary-in-the-Middle
CampaignArcaneDoor

ArcaneDoor included interception of HTTP traffic to victim devices to identify and parse command and control information sent to the device.

T1558
Steal or Forge Kerberos Tickets
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries used the Rubeus tool to forge a Diamond Ticket that is a modified legitimate Kerberos ticket.

T1558.003
Kerberoasting
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 obtained Ticket Granting Service (TGS) tickets for Active Directory Service Principle Names to crack offline.

T1558.003
Kerberoasting
CampaignOperation Wocao

During Operation Wocao, threat actors used PowerSploit's `Invoke-Kerberoast` module to request encrypted service tickets and bruteforce the passwords of Windows service accounts offline.

T1558.003
Kerberoasting
CampaignLeviathan Australian Intrusions

Leviathan used Kerberoasting techniques during Leviathan Australian Intrusions.

T1559
Inter-Process Communication
CampaignOperation MidnightEclipse

During Operation MidnightEclipse, threat actors wrote output to stdout then piped it to bash for execution.

T1559
Inter-Process Communication
Campaign3CX Supply Chain Attack

During the 3CX Supply Chain Attack, AppleJeus's VEILEDSIGNAL creates and listens on a Windows named pipe to exchange messages between modules.

T1559.002
Dynamic Data Exchange
CampaignOperation Sharpshooter

During Operation Sharpshooter, threat actors sent malicious Word OLE documents to victims.

T1560.001
Archive via Utility
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group archived victim's data into a RAR file.

T1560.001
Archive via Utility
CampaignOperation Honeybee

During Operation Honeybee, the threat actors uses zip to pack collected files before exfiltration.

T1560.001
Archive via Utility
CampaignCutting Edge

During Cutting Edge, threat actors saved collected data to a tar archive.

T1560.001
Archive via Utility
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used 7-Zip to compress stolen emails into password-protected archives prior to exfltration; APT29 also compressed text files into zipped archives.

T1560.001
Archive via Utility
CampaignFunnyDream

During FunnyDream, the threat actors used 7zr.exe to add collected files to an archive.

T1560.001
Archive via Utility
CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors used the Makecab utility to compress and a version of WinRAR to create password-protected archives of stolen data prior to exfiltration.

T1560.001
Archive via Utility
CampaignAPT28 Nearest Neighbor Campaign

During APT28 Nearest Neighbor Campaign, APT28 used built-in PowerShell capabilities (Compress-Archive cmdlet) to compress collected data.

T1560.001
Archive via Utility
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries compressed stolen files into a zip file prior to exfiltration.

T1560.001
Archive via Utility
CampaignAPT41 DUST

APT41 DUST used `rar` to compress data downloaded from internal Oracle databases prior to exfiltration.

T1560.001
Archive via Utility
CampaignOperation Wocao

During Operation Wocao, threat actors archived collected files with WinRAR, prior to exfiltration.

T1560.001
Archive via Utility
CampaignC0026

During C0026, the threat actors used WinRAR to collect documents on targeted systems. The threat actors appeared to only exfiltrate files created after January 1, 2021.

T1560.003
Archive via Custom Method
CampaignC0017

During C0017, APT41 hex-encoded PII data prior to exfiltration.

T1561.001
Disk Content Wipe
CampaignAPT28 Nearest Neighbor Campaign

During APT28 Nearest Neighbor Campaign, APT28 used the native Microsoft utility cipher.exe to securely wipe files and folders – overwriting the deleted data using cmd.exe /c cipher /W:C.

T1561.002
Disk Structure Wipe
CampaignHomeLand Justice

During HomeLand Justice, threat actors used a version of ZeroCleare to wipe disk drives on targeted hosts.

T1564.001
Hidden Files and Directories
CampaignRedDelta Modified PlugX Infection Chain Operations

Mustang Panda stored encrypted payloads associated with PlugX installation in hidden directories during RedDelta Modified PlugX Infection Chain Operations.

T1564.013
Bind Mounts
CampaignKV Botnet Activity

KV Botnet Activity leveraged a bind mount to bind itself to the `/proc/` file path before deleting its files from the `/tmp/` directory.

T1566.001
Spearphishing Attachment
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group sent emails with malicious attachments to gain unauthorized access to targets' computers.

T1566.001
Spearphishing Attachment
CampaignFrankenstein

During Frankenstein, the threat actors likely used spearphishing emails to send malicious Microsoft Word documents.

T1566.001
Spearphishing Attachment
CampaignRedDelta Modified PlugX Infection Chain Operations

Mustang Panda leveraged malicious attachments in spearphishing emails for initial access to victim environments in RedDelta Modified PlugX Infection Chain Operations.

T1566.001
Spearphishing Attachment
CampaignOperation Dust Storm

During Operation Dust Storm, the threat actors sent spearphishing emails that contained a malicious Microsoft Word document.

T1566.001
Spearphishing Attachment
Campaign2015 Ukraine Electric Power Attack

During the 2015 Ukraine Electric Power Attack, Sandworm Team obtained their initial foothold into many IT systems using Microsoft Office attachments delivered through phishing emails.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.