ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1071.001×

57 examples

TechniqueUsed byProcedure example
T1071.001
Web Protocols
GroupWIRTE

WIRTE has used HTTP for network communication.

T1071.001
Web Protocols
GroupMagic Hound

Magic Hound has used HTTP for C2.

T1071.001
Web Protocols
GroupThreat Group-3390

Threat Group-3390 malware has used HTTP for C2.

T1071.001
Web Protocols
GroupAPT33

APT33 has used HTTP for command and control.

T1071.001
Web Protocols
GroupFIN8

FIN8 has used HTTPS for command and control.

T1071.001
Web Protocols
GroupFIN13

FIN13 has used HTTP requests to chain multiple web shells and to contact actor-controlled C2 servers prior to exfiltrating stolen data.

T1071.001
Web Protocols
GroupAPT19

APT19 used HTTP for C2 communications. APT19 also used an HTTP malware variant to communicate over HTTP for C2.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.