ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1106
Native API
ToolSILENTTRINITY

SILENTTRINITY has the ability to leverage API including `GetProcAddress` and `LoadLibrary`.

T1106
Native API
ToolEmpire

Empire contains a variety of enumeration modules that have an option to use API calls to carry out tasks.

T1106
Native API
ToolPcShare

PcShare has used a variety of Windows API functions.

T1106
Native API
ToolAsyncRAT

AsyncRAT has the ability to use OS APIs including `CheckRemoteDebuggerPresent`.

T1106
Native API
ToolBrute Ratel C4

Brute Ratel C4 can call multiple Windows APIs for execution, to share memory, and defense evasion.

T1106
Native API
ToolImminent Monitor

Imminent Monitor has leveraged CreateProcessW() call to execute the debugger.

T1106
Native API
ToolDonut

Donut code modules use various API functions to load and inject code.

T1106
Native API
MalwareZeroCleare

ZeroCleare can call the `GetSystemDirectoryW` API to locate the system directory.

T1110
Brute Force
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group performed brute force attacks against administrator accounts.

T1110
Brute Force
Campaign2016 Ukraine Electric Power Attack

During the 2016 Ukraine Electric Power Attack, Sandworm Team used a script to attempt RPC authentication against a number of hosts.

T1110
Brute Force
GroupAPT38

APT38 has used brute force techniques to attempt account access when passwords are unknown or when password hashes are unavailable.

T1110
Brute Force
GroupAPT41

APT41 performed password brute-force attacks on the local admin account.

T1110
Brute Force
GroupDragonfly

Dragonfly has attempted to brute force credentials to gain access.

T1110
Brute Force
GroupAPT39

APT39 has used Ncrack to reveal credentials.

T1110
Brute Force
GroupOilRig

OilRig has used brute force techniques to obtain credentials.

T1110
Brute Force
GroupTurla

Turla may attempt to connect to systems within a victim's network using net use commands and a predefined list or collection of passwords.

T1110
Brute Force
GroupStorm-0501

Storm-0501 has leveraged brute force attacks to obtain credentials.

T1110
Brute Force
GroupDarkVishnya

DarkVishnya used brute-force attack to obtain login data.

T1110
Brute Force
GroupFIN5

FIN5 has has used the tool GET2 Penetrator to look for remote login and hard-coded credentials.

T1110
Brute Force
GroupEmber Bear

Ember Bear used the `su-bruteforce` tool to brute force specific users using the `su` command.

T1110
Brute Force
GroupAgrius

Agrius engaged in various brute forcing activities via SMB in victim environments.

T1110
Brute Force
GroupAPT28

APT28 can perform brute force attacks to obtain credentials.

T1110
Brute Force
GroupFox Kitten

Fox Kitten has brute forced RDP credentials.

T1110
Brute Force
GroupVOID MANTICORE

VOID MANTICORE has conducted brute-force attempts against organizational VPN infrastructure.

T1110
Brute Force
GroupHEXANE

HEXANE has used brute force attacks to compromise valid credentials.

T1110
Brute Force
MalwareChaos

Chaos conducts brute force attacks against SSH services to gain initial access.

T1110
Brute Force
MalwareCaterpillar WebShell

Caterpillar WebShell has a module to perform brute force attacks on a system.

T1110
Brute Force
MalwarePysa

Pysa has used brute force attempts against a central management console, as well as some Active Directory accounts.

T1110
Brute Force
MalwareKinsing

Kinsing has attempted to brute force hosts over SSH.

T1110
Brute Force
MalwareQakBot

QakBot can conduct brute force attacks to capture credentials.

T1110
Brute Force
ToolPoshC2

PoshC2 has modules for brute forcing local administrator and AD user accounts.

T1110
Brute Force
ToolCrackMapExec

CrackMapExec can brute force supplied user credentials across a network range.

T1110
Brute Force
GroupShinyHunters

ShinyHunters has performed brute force attacks against edge devices, such as VPNs or firewall solutions.

T1110.001
Password Guessing
GroupAPT29

APT29 has successfully conducted password guessing attacks against a list of mailboxes.

T1110.001
Password Guessing
GroupAPT28

APT28 has used a brute-force/password-spray tooling that operated in two modes: in brute-force mode it typically sent over 300 authentication attempts per hour per targeted account over the course of several hours or days. APT28 has also used a Kubernetes cluster to conduct distributed, large-scale password guessing attacks.

T1110.001
Password Guessing
GroupVOID MANTICORE

VOID MANTICORE has conducted password guessing to gain initial access.

T1110.001
Password Guessing
MalwarePony

Pony has used a small dictionary of common passwords against a collected list of local accounts.

T1110.001
Password Guessing
MalwareEmotet

Emotet has been observed using a hard coded list of passwords to brute force user accounts.

T1110.001
Password Guessing
MalwareP.A.S. Webshell

P.A.S. Webshell can use predefined users and passwords to execute brute force attacks against SSH, FTP, POP3, MySQL, MSSQL, and PostgreSQL services.

T1110.001
Password Guessing
MalwareLucifer

Lucifer has attempted to brute force TCP ports 135 (RPC) and 1433 (MSSQL) with the default username or list of usernames and passwords.

T1110.001
Password Guessing
MalwareChina Chopper

China Chopper's server component can perform brute force password guessing against authentication portals.

T1110.001
Password Guessing
MalwareXbash

Xbash can obtain a list of weak passwords from the C2 server to use for brute forcing as well as attempt to brute force services with open ports.

T1110.001
Password Guessing
MalwareSpeakUp

SpeakUp can perform brute forcing using a pre-defined list of usernames and passwords in an attempt to log in to administrative panels.

T1110.001
Password Guessing
MalwareHermeticWizard

HermeticWizard can use a list of hardcoded credentials in attempt to authenticate to SMB shares.

T1110.001
Password Guessing
ToolCrackMapExec

CrackMapExec can brute force passwords for a specified user on a single target system or across an entire network.

T1110.002
Password Cracking
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries attempted to crack user passwords.

T1110.002
Password Cracking
CampaignNight Dragon

During Night Dragon, threat actors used Cain & Abel to crack password hashes.

T1110.002
Password Cracking
GroupAPT3

APT3 has been known to brute force password hashes to be able to leverage plain text credentials.

T1110.002
Password Cracking
GroupSalt Typhoon

Salt Typhoon has cracked passwords for accounts with weak encryption obtained from the configuration files of compromised network devices.

T1110.002
Password Cracking
GroupDragonfly

Dragonfly has dropped and executed tools used for password cracking, including Hydra and CrackMapExec.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.