Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1106 Native API |
ToolSILENTTRINITY | SILENTTRINITY has the ability to leverage API including `GetProcAddress` and `LoadLibrary`. |
| T1106 Native API |
ToolEmpire | Empire contains a variety of enumeration modules that have an option to use API calls to carry out tasks. |
| T1106 Native API |
ToolPcShare | PcShare has used a variety of Windows API functions. |
| T1106 Native API |
ToolAsyncRAT | AsyncRAT has the ability to use OS APIs including `CheckRemoteDebuggerPresent`. |
| T1106 Native API |
ToolBrute Ratel C4 | Brute Ratel C4 can call multiple Windows APIs for execution, to share memory, and defense evasion. |
| T1106 Native API |
ToolImminent Monitor | Imminent Monitor has leveraged CreateProcessW() call to execute the debugger. |
| T1106 Native API |
ToolDonut | Donut code modules use various API functions to load and inject code. |
| T1106 Native API |
MalwareZeroCleare | ZeroCleare can call the `GetSystemDirectoryW` API to locate the system directory. |
| T1110 Brute Force |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group performed brute force attacks against administrator accounts. |
| T1110 Brute Force |
Campaign2016 Ukraine Electric Power Attack | During the 2016 Ukraine Electric Power Attack, Sandworm Team used a script to attempt RPC authentication against a number of hosts. |
| T1110 Brute Force |
GroupAPT38 | APT38 has used brute force techniques to attempt account access when passwords are unknown or when password hashes are unavailable. |
| T1110 Brute Force |
GroupAPT41 | APT41 performed password brute-force attacks on the local admin account. |
| T1110 Brute Force |
GroupDragonfly | Dragonfly has attempted to brute force credentials to gain access. |
| T1110 Brute Force |
GroupAPT39 | APT39 has used Ncrack to reveal credentials. |
| T1110 Brute Force |
GroupOilRig | OilRig has used brute force techniques to obtain credentials. |
| T1110 Brute Force |
GroupTurla | Turla may attempt to connect to systems within a victim's network using |
| T1110 Brute Force |
GroupStorm-0501 | Storm-0501 has leveraged brute force attacks to obtain credentials. |
| T1110 Brute Force |
GroupDarkVishnya | DarkVishnya used brute-force attack to obtain login data. |
| T1110 Brute Force |
GroupFIN5 | FIN5 has has used the tool GET2 Penetrator to look for remote login and hard-coded credentials. |
| T1110 Brute Force |
GroupEmber Bear | Ember Bear used the `su-bruteforce` tool to brute force specific users using the `su` command. |
| T1110 Brute Force |
GroupAgrius | Agrius engaged in various brute forcing activities via SMB in victim environments. |
| T1110 Brute Force |
GroupAPT28 | APT28 can perform brute force attacks to obtain credentials. |
| T1110 Brute Force |
GroupFox Kitten | Fox Kitten has brute forced RDP credentials. |
| T1110 Brute Force |
GroupVOID MANTICORE | VOID MANTICORE has conducted brute-force attempts against organizational VPN infrastructure. |
| T1110 Brute Force |
GroupHEXANE | HEXANE has used brute force attacks to compromise valid credentials. |
| T1110 Brute Force |
MalwareChaos | Chaos conducts brute force attacks against SSH services to gain initial access. |
| T1110 Brute Force |
MalwareCaterpillar WebShell | Caterpillar WebShell has a module to perform brute force attacks on a system. |
| T1110 Brute Force |
MalwarePysa | Pysa has used brute force attempts against a central management console, as well as some Active Directory accounts. |
| T1110 Brute Force |
MalwareKinsing | Kinsing has attempted to brute force hosts over SSH. |
| T1110 Brute Force |
MalwareQakBot | QakBot can conduct brute force attacks to capture credentials. |
| T1110 Brute Force |
ToolPoshC2 | PoshC2 has modules for brute forcing local administrator and AD user accounts. |
| T1110 Brute Force |
ToolCrackMapExec | CrackMapExec can brute force supplied user credentials across a network range. |
| T1110 Brute Force |
GroupShinyHunters | ShinyHunters has performed brute force attacks against edge devices, such as VPNs or firewall solutions. |
| T1110.001 Password Guessing |
GroupAPT29 | APT29 has successfully conducted password guessing attacks against a list of mailboxes. |
| T1110.001 Password Guessing |
GroupAPT28 | APT28 has used a brute-force/password-spray tooling that operated in two modes: in brute-force mode it typically sent over 300 authentication attempts per hour per targeted account over the course of several hours or days. APT28 has also used a Kubernetes cluster to conduct distributed, large-scale password guessing attacks. |
| T1110.001 Password Guessing |
GroupVOID MANTICORE | VOID MANTICORE has conducted password guessing to gain initial access. |
| T1110.001 Password Guessing |
MalwarePony | Pony has used a small dictionary of common passwords against a collected list of local accounts. |
| T1110.001 Password Guessing |
MalwareEmotet | Emotet has been observed using a hard coded list of passwords to brute force user accounts. |
| T1110.001 Password Guessing |
MalwareP.A.S. Webshell | P.A.S. Webshell can use predefined users and passwords to execute brute force attacks against SSH, FTP, POP3, MySQL, MSSQL, and PostgreSQL services. |
| T1110.001 Password Guessing |
MalwareLucifer | Lucifer has attempted to brute force TCP ports 135 (RPC) and 1433 (MSSQL) with the default username or list of usernames and passwords. |
| T1110.001 Password Guessing |
MalwareChina Chopper | China Chopper's server component can perform brute force password guessing against authentication portals. |
| T1110.001 Password Guessing |
MalwareXbash | Xbash can obtain a list of weak passwords from the C2 server to use for brute forcing as well as attempt to brute force services with open ports. |
| T1110.001 Password Guessing |
MalwareSpeakUp | SpeakUp can perform brute forcing using a pre-defined list of usernames and passwords in an attempt to log in to administrative panels. |
| T1110.001 Password Guessing |
MalwareHermeticWizard | HermeticWizard can use a list of hardcoded credentials in attempt to authenticate to SMB shares. |
| T1110.001 Password Guessing |
ToolCrackMapExec | CrackMapExec can brute force passwords for a specified user on a single target system or across an entire network. |
| T1110.002 Password Cracking |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries attempted to crack user passwords. |
| T1110.002 Password Cracking |
CampaignNight Dragon | During Night Dragon, threat actors used Cain & Abel to crack password hashes. |
| T1110.002 Password Cracking |
GroupAPT3 | APT3 has been known to brute force password hashes to be able to leverage plain text credentials. |
| T1110.002 Password Cracking |
GroupSalt Typhoon | Salt Typhoon has cracked passwords for accounts with weak encryption obtained from the configuration files of compromised network devices. |
| T1110.002 Password Cracking |
GroupDragonfly | Dragonfly has dropped and executed tools used for password cracking, including Hydra and CrackMapExec. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.