Real-world descriptions of how a group, tool or campaign used a technique.
1146 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1552.004 Private Keys |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 obtained PKI keys, certificate files, and the private encryption key from an Active Directory Federation Services (AD FS) container to decrypt corresponding SAML signing certificates. |
| T1552.004 Private Keys |
CampaignOperation Wocao | During Operation Wocao, threat actors used Mimikatz to dump certificates and private keys from the Windows certificate store. |
| T1553.002 Code Signing |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group digitally signed their own malware to evade detection. |
| T1553.002 Code Signing |
CampaignRedDelta Modified PlugX Infection Chain Operations | Mustang Panda used legitimate, signed binaries such as `inkform.exe` or `ExcelRepairToolboxLauncher.exe` for follow-on execution of malicious DLLs through DLL search order hijacking in RedDelta Modified PlugX Infection Chain Operations. |
| T1553.002 Code Signing |
CampaignOperation Honeybee | During Operation Honeybee, the threat actors deployed the MaoCheng dropper with a stolen Adobe Systems digital signature. |
| T1553.002 Code Signing |
Campaign3CX Supply Chain Attack | Although the X_TRADER platform was reportedly discontinued in 2020, it was still available for download from the legitimate Trading Technologies website in 2022. During the 3CX Supply Chain Attack, AppleJeus used a code signing certificate to digitally sign the malicious software with an expiration date set to October 2022. This file was signed with the subject “Trading Technologies International, Inc” and contained the executable file Setup.exe, also signed with the same digital certificate. |
| T1553.002 Code Signing |
CampaignC0015 | For C0015, the threat actors used DLL files that had invalid certificates. |
| T1553.002 Code Signing |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 was able to get SUNBURST signed by SolarWinds code signing certificates by injecting the malware into the SolarWinds Orion software lifecycle. |
| T1553.002 Code Signing |
CampaignOperation AkaiRyū | During Operation AkaiRyū, MirrorFace abused a signed McAfee executable to load UPPERCUT. |
| T1553.002 Code Signing |
CampaignAPT41 DUST | APT41 DUST used stolen code signing certificates for DUSTTRAP malware and subsequent payloads. |
| T1554 Compromise Host Software Binary |
CampaignRedPenguin | During RedPenguin, UNC3886 peformed a local memory patching attack to modify the snmpd and mgd Junos OS daemons. |
| T1554 Compromise Host Software Binary |
CampaignCutting Edge | During Cutting Edge, threat actors trojanized legitimate files in Ivanti Connect Secure appliances with malicious code. |
| T1554 Compromise Host Software Binary |
Campaign2016 Ukraine Electric Power Attack | During the 2016 Ukraine Electric Power Attack, Sandworm Team used a trojanized version of Windows Notepad to add a layer of persistence for Industroyer. |
| T1555 Credentials from Password Stores |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used account credentials they obtained to attempt access to Group Managed Service Account (gMSA) passwords. |
| T1555 Credentials from Password Stores |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries configured a native CLI to gather a targeted elevated users password using `grep`. |
| T1555.003 Credentials from Web Browsers |
CampaignJuicy Mix | During Juicy Mix, OilRig used the CDumper (Chrome browser) and EDumper (Edge browser) to collect credentials. |
| T1555.003 Credentials from Web Browsers |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 stole users' saved passwords from Chrome. |
| T1555.004 Windows Credential Manager |
CampaignJuicy Mix | During Juicy Mix, OilRig used a Windows Credential Manager stealer for credential access. |
| T1555.005 Password Managers |
CampaignOperation Wocao | During Operation Wocao, threat actors accessed and collected credentials from password managers. |
| T1556 Modify Authentication Process |
CampaignArcaneDoor | ArcaneDoor included modification of the AAA process to bypass authentication mechanisms. |
| T1556.006 Multi-Factor Authentication |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries modified two-factor settings within the FortiGate solution to `unset`. |
| T1557 Adversary-in-the-Middle |
CampaignArcaneDoor | ArcaneDoor included interception of HTTP traffic to victim devices to identify and parse command and control information sent to the device. |
| T1558 Steal or Forge Kerberos Tickets |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries used the Rubeus tool to forge a Diamond Ticket that is a modified legitimate Kerberos ticket. |
| T1558.003 Kerberoasting |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 obtained Ticket Granting Service (TGS) tickets for Active Directory Service Principle Names to crack offline. |
| T1558.003 Kerberoasting |
CampaignOperation Wocao | During Operation Wocao, threat actors used PowerSploit's `Invoke-Kerberoast` module to request encrypted service tickets and bruteforce the passwords of Windows service accounts offline. |
| T1558.003 Kerberoasting |
CampaignLeviathan Australian Intrusions | Leviathan used Kerberoasting techniques during Leviathan Australian Intrusions. |
| T1559 Inter-Process Communication |
CampaignOperation MidnightEclipse | During Operation MidnightEclipse, threat actors wrote output to stdout then piped it to bash for execution. |
| T1559 Inter-Process Communication |
Campaign3CX Supply Chain Attack | During the 3CX Supply Chain Attack, AppleJeus's VEILEDSIGNAL creates and listens on a Windows named pipe to exchange messages between modules. |
| T1559.002 Dynamic Data Exchange |
CampaignOperation Sharpshooter | During Operation Sharpshooter, threat actors sent malicious Word OLE documents to victims. |
| T1560.001 Archive via Utility |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group archived victim's data into a RAR file. |
| T1560.001 Archive via Utility |
CampaignOperation Honeybee | During Operation Honeybee, the threat actors uses zip to pack collected files before exfiltration. |
| T1560.001 Archive via Utility |
CampaignCutting Edge | During Cutting Edge, threat actors saved collected data to a tar archive. |
| T1560.001 Archive via Utility |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used 7-Zip to compress stolen emails into password-protected archives prior to exfltration; APT29 also compressed text files into zipped archives. |
| T1560.001 Archive via Utility |
CampaignFunnyDream | During FunnyDream, the threat actors used 7zr.exe to add collected files to an archive. |
| T1560.001 Archive via Utility |
CampaignOperation CuckooBees | During Operation CuckooBees, the threat actors used the Makecab utility to compress and a version of WinRAR to create password-protected archives of stolen data prior to exfiltration. |
| T1560.001 Archive via Utility |
CampaignAPT28 Nearest Neighbor Campaign | During APT28 Nearest Neighbor Campaign, APT28 used built-in PowerShell capabilities ( |
| T1560.001 Archive via Utility |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries compressed stolen files into a zip file prior to exfiltration. |
| T1560.001 Archive via Utility |
CampaignAPT41 DUST | APT41 DUST used `rar` to compress data downloaded from internal Oracle databases prior to exfiltration. |
| T1560.001 Archive via Utility |
CampaignOperation Wocao | During Operation Wocao, threat actors archived collected files with WinRAR, prior to exfiltration. |
| T1560.001 Archive via Utility |
CampaignC0026 | During C0026, the threat actors used WinRAR to collect documents on targeted systems. The threat actors appeared to only exfiltrate files created after January 1, 2021. |
| T1560.003 Archive via Custom Method |
CampaignC0017 | During C0017, APT41 hex-encoded PII data prior to exfiltration. |
| T1561.001 Disk Content Wipe |
CampaignAPT28 Nearest Neighbor Campaign | During APT28 Nearest Neighbor Campaign, APT28 used the native Microsoft utility cipher.exe to securely wipe files and folders – overwriting the deleted data using |
| T1561.002 Disk Structure Wipe |
CampaignHomeLand Justice | During HomeLand Justice, threat actors used a version of ZeroCleare to wipe disk drives on targeted hosts. |
| T1564.001 Hidden Files and Directories |
CampaignRedDelta Modified PlugX Infection Chain Operations | Mustang Panda stored encrypted payloads associated with PlugX installation in hidden directories during RedDelta Modified PlugX Infection Chain Operations. |
| T1564.013 Bind Mounts |
CampaignKV Botnet Activity | KV Botnet Activity leveraged a bind mount to bind itself to the `/proc/` file path before deleting its files from the `/tmp/` directory. |
| T1566.001 Spearphishing Attachment |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group sent emails with malicious attachments to gain unauthorized access to targets' computers. |
| T1566.001 Spearphishing Attachment |
CampaignFrankenstein | During Frankenstein, the threat actors likely used spearphishing emails to send malicious Microsoft Word documents. |
| T1566.001 Spearphishing Attachment |
CampaignRedDelta Modified PlugX Infection Chain Operations | Mustang Panda leveraged malicious attachments in spearphishing emails for initial access to victim environments in RedDelta Modified PlugX Infection Chain Operations. |
| T1566.001 Spearphishing Attachment |
CampaignOperation Dust Storm | During Operation Dust Storm, the threat actors sent spearphishing emails that contained a malicious Microsoft Word document. |
| T1566.001 Spearphishing Attachment |
Campaign2015 Ukraine Electric Power Attack | During the 2015 Ukraine Electric Power Attack, Sandworm Team obtained their initial foothold into many IT systems using Microsoft Office attachments delivered through phishing emails. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.