ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

1146 examples

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
CampaignKV Botnet Activity

KV Botnet Activity gathers victim IP information during initial installation stages.

T1016
System Network Configuration Discovery
CampaignFrankenstein

During Frankenstein, the threat actors used Empire to find the public IP address of a compromised system.

T1016
System Network Configuration Discovery
CampaignRedPenguin

During RedPenguin, UNC3886 leveraged JunoOS CLI queries to obtain the interface index which contains system and network details.

T1016
System Network Configuration Discovery
CampaignC0018

During C0018, the threat actors ran `nslookup` and Advanced IP Scanner on the target network.

T1016
System Network Configuration Discovery
CampaignShadowRay

During ShadowRay, threat actors invoked DNS queries from targeted machines to identify their IP addresses.

T1016
System Network Configuration Discovery
CampaignAnthropic AI-orchestrated Campaign

During the Anthropic AI-orchestrated Campaign, the adversary configured Claude Code to identify and gather system configurations of discovered devices.

T1016
System Network Configuration Discovery
CampaignC0015

During C0015, the threat actors used code to obtain the external public-facing IPv4 address of the compromised host.

T1016
System Network Configuration Discovery
CampaignOperation AkaiRyū

During Operation AkaiRyū, MirrorFace used Arp and `dir` for discovery in compromised environments.

T1016
System Network Configuration Discovery
CampaignFunnyDream

During FunnyDream, the threat actors used ipconfig for discovery on remote systems.

T1016
System Network Configuration Discovery
CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors used `ipconfig`, `nbtstat`, `tracert`, `route print`, and `cat /etc/hosts` commands.

T1016
System Network Configuration Discovery
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries gathered network configuration details utilizing `arp -a` and `nslookup` commands.

T1016
System Network Configuration Discovery
CampaignOperation Wocao

During Operation Wocao, threat actors discovered the local network configuration with `ipconfig`.

T1016
System Network Configuration Discovery
CampaignC0017

During C0017, APT41 used `cmd.exe /c ping %userdomain%` for discovery.

T1016.001
Internet Connection Discovery
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used GoldFinder to perform HTTP GET requests to check internet connectivity and identify HTTP proxy servers and other redirectors that an HTTP request travels through.

T1016.001
Internet Connection Discovery
CampaignOperation Wocao

During Operation Wocao, threat actors used a Visual Basic script that checked for internet connectivity.

T1016.002
Wi-Fi Discovery
CampaignAPT28 Nearest Neighbor Campaign

During APT28 Nearest Neighbor Campaign, APT28 collected information on wireless interfaces within range of a compromised system.

T1018
Remote System Discovery
Campaign2015 Ukraine Electric Power Attack

During the 2015 Ukraine Electric Power Attack, Sandworm Team remotely discovered systems over LAN connections. OT systems were visible from the IT network as well, giving adversaries the ability to discover operational assets.

T1018
Remote System Discovery
CampaignOperation Digital Eye

During Operation Digital Eye, threat actors used Ping for reconnaissance.

T1018
Remote System Discovery
CampaignC0015

During C0015, the threat actors used the commands `net view /all /domain` and `ping` to discover remote systems. They also used PowerView's PowerShell Invoke-ShareFinder script for file share enumeration.

T1018
Remote System Discovery
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used AdFind to enumerate remote systems.

T1018
Remote System Discovery
CampaignFunnyDream

During FunnyDream, the threat actors used several tools and batch files to map victims' internal networks.

T1018
Remote System Discovery
CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors used the `net view` and `ping` commands as part of their advanced reconnaissance.

T1018
Remote System Discovery
Campaign2016 Ukraine Electric Power Attack

During the 2016 Ukraine Electric Power Attack, Sandworm Team checked for connectivity to resources within the network and used LDAP to query Active Directory, discovering information about computers listed in AD.

T1018
Remote System Discovery
CampaignOperation Wocao

During Operation Wocao, threat actors used `nbtscan` and `ping` to discover remote systems, as well as `dsquery subnet` on a domain controller to retrieve all subnets in the Active Directory.

T1018
Remote System Discovery
CampaignLeviathan Australian Intrusions

Leviathan performed extensive remote host enumeration to build their own map of victim networks during Leviathan Australian Intrusions.

T1020
Automated Exfiltration
CampaignFrankenstein

During Frankenstein, the threat actors collected information via Empire, which was automatically sent back to the adversary's C2.

T1020
Automated Exfiltration
CampaignSalesforce Data Exfiltration

During Salesforce Data Exfiltration, threat actors used API queries to automatically exfiltrate large volumes of data.

T1020
Automated Exfiltration
CampaignArcaneDoor

ArcaneDoor included scripted exfiltration of collected data.

T1021.001
Remote Desktop Protocol
CampaignCutting Edge

During Cutting Edge, threat actors used RDP with compromised credentials for lateral movement.

T1021.001
Remote Desktop Protocol
CampaignC0018

During C0018, the threat actors opened a variety of ports to establish RDP connections, including ports 28035, 32467, 41578, and 46892.

T1021.001
Remote Desktop Protocol
CampaignOperation Digital Eye

During Operation Digital Eye, threat actors moved laterally using RDP.

T1021.001
Remote Desktop Protocol
CampaignC0015

During C0015, the threat actors used RDP to access specific network hosts of interest.

T1021.001
Remote Desktop Protocol
CampaignHomeLand Justice

During HomeLand Justice, threat actors primarily used RDP for lateral movement in the victim environment.

T1021.001
Remote Desktop Protocol
CampaignC0032

During the C0032 campaign, TEMP.Veles utilized RDP throughout an operation.

T1021.001
Remote Desktop Protocol
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used RDP sessions from public-facing systems to internal servers.

T1021.001
Remote Desktop Protocol
CampaignAPT28 Nearest Neighbor Campaign

During APT28 Nearest Neighbor Campaign, APT28 used RDP for lateral movement.

T1021.001
Remote Desktop Protocol
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, adversaries utilized RDP to log into jump hosts and then moved laterally to other victim devices to include a domain controller.

T1021.002
SMB/Windows Admin Shares
CampaignOperation MidnightEclipse

During Operation MidnightEclipse, threat actors used SMB to pivot internally in victim networks.

T1021.002
SMB/Windows Admin Shares
CampaignCutting Edge

During Cutting Edge, threat actors moved laterally using compromised credentials to connect to internal Windows systems with SMB.

T1021.002
SMB/Windows Admin Shares
CampaignHomeLand Justice

During HomeLand Justice, threat actors used SMB for lateral movement.

T1021.002
SMB/Windows Admin Shares
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used administrative accounts to connect over SMB to targeted users.

T1021.002
SMB/Windows Admin Shares
CampaignAPT28 Nearest Neighbor Campaign

During APT28 Nearest Neighbor Campaign, APT28 leveraged SMB to transfer files and move laterally.

T1021.002
SMB/Windows Admin Shares
Campaign2016 Ukraine Electric Power Attack

During the 2016 Ukraine Electric Power Attack, Sandworm Team utilized `net use` to connect to network shares.

T1021.002
SMB/Windows Admin Shares
CampaignOperation Wocao

During Operation Wocao, threat actors used Impacket's smbexec.py as well as accessing the C$ and IPC$ shares to move laterally.

T1021.002
SMB/Windows Admin Shares
CampaignLeviathan Australian Intrusions

Leviathan used remote shares to move laterally through victim networks during Leviathan Australian Intrusions.

T1021.004
SSH
CampaignCutting Edge

During Cutting Edge, threat actors used SSH for lateral movement.

T1021.004
SSH
CampaignC0032

During the C0032 campaign, TEMP.Veles relied on encrypted SSH-based tunnels to transfer tools and for remote command/program execution.

T1021.004
SSH
CampaignLeviathan Australian Intrusions

Leviathan used SSH brute force techniques to move laterally within victim environments during Leviathan Australian Intrusions.

T1021.006
Windows Remote Management
CampaignOperation MidnightEclipse

During Operation MidnightEclipse, threat actors used WinRM to move laterally in targeted networks.

T1021.006
Windows Remote Management
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used WinRM via PowerShell to execute commands and payloads on remote hosts.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.