ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

4628 examples

TechniqueUsed byProcedure example
T1041
Exfiltration Over C2 Channel
GroupLeviathan

Leviathan has exfiltrated data over its C2 channel.

T1041
Exfiltration Over C2 Channel
GroupWinter Vivern

Winter Vivern delivered a PowerShell script capable of recursively scanning victim machines looking for various file types before exfiltrating identified files via HTTP.

T1041
Exfiltration Over C2 Channel
GroupStealth Falcon

After data is collected by Stealth Falcon malware, it is exfiltrated over the existing C2 channel.

T1041
Exfiltration Over C2 Channel
GroupChimera

Chimera has used Cobalt Strike C2 beacons for data exfiltration.

T1041
Exfiltration Over C2 Channel
GroupLuminousMoth

LuminousMoth has used malware that exfiltrates stolen data to its C2 server.

T1041
Exfiltration Over C2 Channel
GroupAgrius

Agrius exfiltrated staged data using tools such as Putty and WinSCP, communicating with command and control servers.

T1041
Exfiltration Over C2 Channel
GroupLazarus Group

Lazarus Group has exfiltrated data and files over a C2 channel through its various tools and malware.

T1041
Exfiltration Over C2 Channel
GroupWizard Spider

Wizard Spider has exfiltrated domain credentials and network enumeration information over command and control (C2) channels.

T1041
Exfiltration Over C2 Channel
GroupVOID MANTICORE

VOID MANTICORE malware has exfiltrated collected data via Telegram bot C2 channels using encrypted communications.

T1041
Exfiltration Over C2 Channel
GroupWIRTE

WIRTE has exfiltrated collected victim data to C2 infrastructure.

T1046
Network Service Discovery
GroupBlackByte

BlackByte has used tools such as NetScan to enumerate network services in victim environments.

T1046
Network Service Discovery
GroupVolt Typhoon

Volt Typhoon has used commercial tools, LOTL utilities, and appliances already present on the system for network service discovery.

T1046
Network Service Discovery
GroupAPT41

APT41 used a malware variant called WIDETONE to conduct port scans on specified subnets.

T1046
Network Service Discovery
GroupmenuPass

menuPass has used tcping.exe, similar to Ping, to probe port status on systems of interest.

T1046
Network Service Discovery
GroupAPT32

APT32 performed network scanning on the network to search for open ports, services, OS finger-printing, and other vulnerabilities.

T1046
Network Service Discovery
GroupNaikon

Naikon has used the LadonGo scanner to scan target networks.

T1046
Network Service Discovery
GroupFIN6

FIN6 used publicly available tools (including Microsoft's built-in SQL querying tool, osql.exe) to map the internal network and conduct reconnaissance against Active Directory, Structured Query Language (SQL) servers, and NetBIOS.

T1046
Network Service Discovery
GroupLeafminer

Leafminer scanned network services to search for vulnerabilities in the victim system.

T1046
Network Service Discovery
GroupTeamTNT

TeamTNT has used masscan to search for open Docker API ports and Kubernetes clusters. TeamTNT has also used malware that utilizes zmap and zgrab to search for vulnerable services in cloud environments.

T1046
Network Service Discovery
GroupMustang Panda

Mustang Panda has leveraged NBTscan to scan IP networks.

T1046
Network Service Discovery
GroupRocke

Rocke conducted scanning for exposed TCP port 7001 as well as SSH and Redis servers.

T1046
Network Service Discovery
GroupAPT39

APT39 has used CrackMapExec and a custom port scanner known as BLUETORCH for network scanning.

T1046
Network Service Discovery
GroupOilRig

OilRig has used the publicly available tool SoftPerfect Network Scanner as well as a custom tool called GOLDIRONY to conduct network scanning.

T1046
Network Service Discovery
GroupTropic Trooper

Tropic Trooper used pr and an openly available tool to scan for open ports on target systems.

T1046
Network Service Discovery
GroupSuckfly

Suckfly the victim's internal network for hosts with ports 8080, 5900, and 40 open.

T1046
Network Service Discovery
GroupBlackTech

BlackTech has used the SNScan tool to find other potential targets on victim networks.

T1046
Network Service Discovery
GroupDarkVishnya

DarkVishnya performed port scanning to obtain the list of active services.

T1046
Network Service Discovery
GroupRedCurl

RedCurl has used netstat to check if port 4119 is open.

T1046
Network Service Discovery
GroupLotus Blossom

Lotus Blossom has used port scanners to enumerate services on remote hosts.

T1046
Network Service Discovery
GroupChimera

Chimera has used the get -b <start ip> -e <end ip> -p command for network scanning as well as a custom Python tool packed into a Windows executable named Get.exe to scan IP ranges for HTTP.

T1046
Network Service Discovery
GroupMedusa Group

Medusa Group has the capability to use living off the land (LOTL) binaries to perform network enumeration. Medusa Group has also utilized the publicly available scanning tool SoftPerfect Network Scanner (`netscan.exe`) to discover device hostnames and network services.

T1046
Network Service Discovery
GroupBackdoorDiplomacy

BackdoorDiplomacy has used SMBTouch, a vulnerability scanner, to determine whether a target is vulnerable to EternalBlue malware.

T1046
Network Service Discovery
GroupEmber Bear

Ember Bear has used tools such as NMAP for remote system discovery and enumeration in victim environments.

T1046
Network Service Discovery
GroupAgrius

Agrius used the open-source port scanner WinEggDrop to perform detailed scans of hosts of interest in victim networks.

T1046
Network Service Discovery
GroupFox Kitten

Fox Kitten has used tools including NMAP to conduct broad scanning to identify open ports.

T1046
Network Service Discovery
GroupLazarus Group

Lazarus Group has used nmap from a router VM to scan ports on systems within the restricted segment of an enterprise network.

T1046
Network Service Discovery
GroupINC Ransom

INC Ransom has used NETSCAN.EXE for internal reconnaissance.

T1046
Network Service Discovery
GroupCobalt Group

Cobalt Group leveraged an open-source tool called SoftPerfect Network Scanner to perform network scanning.

T1046
Network Service Discovery
GroupMagic Hound

Magic Hound has used KPortScan 3.0 to perform SMB, RDP, and LDAP scanning.

T1046
Network Service Discovery
GroupThreat Group-3390

Threat Group-3390 actors use the Hunter tool to conduct network service discovery for vulnerable systems.

T1046
Network Service Discovery
GroupFIN13

FIN13 has utilized `nmap` for reconnaissance efforts. FIN13 has also scanned for internal MS-SQL servers in a compromised network.

T1047
Windows Management Instrumentation
GroupIndrik Spider

Indrik Spider has used WMIC to execute commands on remote computers.

T1047
Windows Management Instrumentation
GroupBlackByte

BlackByte used WMI to delete Volume Shadow Copies on victim machines.

T1047
Windows Management Instrumentation
GroupGALLIUM

GALLIUM used WMI for execution to assist in lateral movement as well as for installing tools across multiple assets.

T1047
Windows Management Instrumentation
GroupVolt Typhoon

Volt Typhoon has leveraged WMIC for execution, remote system discovery, and to create and use temporary directories.

T1047
Windows Management Instrumentation
GroupAPT41

APT41 used WMI in several ways, including for execution of commands via WMIEXEC as well as for persistence via PowerSploit. APT41 has executed files through Windows Management Instrumentation (WMI).

T1047
Windows Management Instrumentation
GroupmenuPass

menuPass has used a modified version of pentesting script wmiexec.vbs, which logs into a remote machine using WMI.

T1047
Windows Management Instrumentation
GroupAPT32

APT32 used WMI to deploy their tools on remote machines and to gather information about the Outlook process.

T1047
Windows Management Instrumentation
GroupMuddyWater

MuddyWater has used malware that leveraged WMI for execution and querying host information.

T1047
Windows Management Instrumentation
GroupNaikon

Naikon has used WMIC.exe for lateral movement.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.