ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1113
Screen Capture
MalwareAgent Tesla

Agent Tesla can capture screenshots of the victim’s desktop.

T1113
Screen Capture
MalwarePOWERSTATS

POWERSTATS can retrieve screenshots from compromised hosts.

T1113
Screen Capture
MalwareECCENTRICBANDWAGON

ECCENTRICBANDWAGON can capture screenshots and store them locally.

T1113
Screen Capture
MalwareBADNEWS

BADNEWS has a command to take a screenshot and send it to the C2 server.

T1113
Screen Capture
MalwareRemexi

Remexi takes screenshots of windows of interest.

T1113
Screen Capture
MalwarejRAT

jRAT has the capability to take screenshots of the victim’s machine.

T1113
Screen Capture
MalwareMacSpy

MacSpy can capture screenshots of the desktop over multiple monitors.

T1113
Screen Capture
MalwareLizar

Lizar can take JPEG screenshots of an infected system. Lizar has also used a plugin to take a screenshot of the infected system.

T1113
Screen Capture
MalwareAzorult

Azorult can capture screenshots of the victim’s machines.

T1113
Screen Capture
MalwareUPPERCUT

UPPERCUT can capture desktop screenshots in the PNG format and send them to the C2 server.

T1113
Screen Capture
MalwareStrifeWater

StrifeWater has the ability to take screen captures.

T1113
Screen Capture
MalwareSLOTHFULMEDIA

SLOTHFULMEDIA has taken a screenshot of a victim's desktop, named it "Filter3.jpg", and stored it in the local directory.

T1113
Screen Capture
ToolRemoteUtilities

RemoteUtilities can take screenshots on a compromised host.

T1113
Screen Capture
ToolSliver

Sliver can take screenshots of the victim’s active display.

T1113
Screen Capture
ToolSILENTTRINITY

SILENTTRINITY can take a screenshot of the current desktop.

T1113
Screen Capture
ToolPowerSploit

PowerSploit's Get-TimedScreenshot Exfiltration module can take screenshots at regular intervals.

T1113
Screen Capture
ToolEmpire

Empire is capable of capturing screenshots on Windows and macOS systems.

T1113
Screen Capture
ToolPcShare

PcShare can take screen shots of a compromised machine.

T1113
Screen Capture
ToolAsyncRAT

AsyncRAT has the ability to view the screen on compromised hosts.

T1113
Screen Capture
ToolBrute Ratel C4

Brute Ratel C4 can take screenshots on compromised hosts.

T1113
Screen Capture
ToolRemcos

Remcos takes automated screenshots of the infected machine.

T1113
Screen Capture
ToolConnectWise

ConnectWise can take screenshots on remote hosts.

T1113
Screen Capture
ToolPupy

Pupy can drop a mouse-logger that will take small screenshots around at each click and then send back to the server.

T1113
Screen Capture
ToolQuick Assist

Quick Assist allows for the remote administrator to take screenshots of the running system.

T1113
Screen Capture
MalwareFlame

Flame can take regular screenshots when certain applications are open that are sent to the command and control server.

T1114
Email Collection
GroupScattered Spider

Scattered Spider searched the victim’s Microsoft Exchange for emails about the intrusion and incident response.

T1114
Email Collection
GroupSilent Librarian

Silent Librarian has exfiltrated entire mailboxes from compromised accounts.

T1114
Email Collection
GroupEmber Bear

Ember Bear attempts to collect mail from accessed systems and servers.

T1114
Email Collection
GroupMagic Hound

Magic Hound has compromised email credentials in order to steal sensitive data.

T1114
Email Collection
MalwareEmotet

Emotet has been observed leveraging a module that can scrape email addresses from Outlook.

T1114
Email Collection
MalwareTRANSLATEXT

TRANSLATEXT has exfiltrated collected email addresses to the C2 server.

T1114.001
Local Email Collection
CampaignNight Dragon

During Night Dragon, threat actors used RAT malware to exfiltrate email archives.

T1114.001
Local Email Collection
GroupSea Turtle

Sea Turtle collected email archives from victim environments.

T1114.001
Local Email Collection
GroupAPT1

APT1 uses two utilities, GETMAIL and MAPIGET, to steal email. GETMAIL extracts emails from archived Outlook .pst files.

T1114.001
Local Email Collection
GroupWinter Vivern

Winter Vivern delivered malicious JavaScript payloads capable of exfiltrating email messages from exploited email servers.

T1114.001
Local Email Collection
GroupRedCurl

RedCurl has collected emails to use in future phishing campaigns.

T1114.001
Local Email Collection
GroupChimera

Chimera has harvested data from victim's e-mail including through execution of wmic /node:<ip> process call create "cmd /c copy c:\Users\<username>\<path>\backup.pst c:\windows\temp\backup.pst" copy "i:\<path>\<username>\My Documents\<filename>.pst"
copy
.

T1114.001
Local Email Collection
GroupMirrorFace

MirrorFace has exfiltrated stored emails from compromised hosts.

T1114.001
Local Email Collection
GroupWIRTE

WIRTE has collected documents from victims' email accounts.

T1114.001
Local Email Collection
GroupMagic Hound

Magic Hound has collected .PST archives.

T1114.001
Local Email Collection
MalwareSmoke Loader

Smoke Loader searches through Outlook files and directories (e.g., inbox, sent, templates, drafts, archives, etc.).

T1114.001
Local Email Collection
MalwareCosmicDuke

CosmicDuke searches for Microsoft Outlook data files with extensions .pst and .ost for collection and exfiltration.

T1114.001
Local Email Collection
MalwareEmotet

Emotet has been observed leveraging a module that scrapes email data from Outlook.

T1114.001
Local Email Collection
MalwareCrimson

Crimson contains a command to collect and exfiltrate emails from Outlook.

T1114.001
Local Email Collection
MalwareCarbanak

Carbanak searches recursively for Outlook personal storage tables (PST) files within user directories and sends them back to the C2 server.

T1114.001
Local Email Collection
MalwareKGH_SPY

KGH_SPY can harvest data from mail clients.

T1114.001
Local Email Collection
MalwareLunarMail

LunarMail can capture the recipients of sent email messages from compromised accounts.

T1114.001
Local Email Collection
MalwareQakBot

QakBot can target and steal locally stored emails to support thread hijacking phishing campaigns.

T1114.001
Local Email Collection
ToolEmpire

Empire has the ability to collect emails on a target system.

T1114.001
Local Email Collection
ToolOut1

Out1 can parse e-mails on a target machine.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.