Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1199 Trusted Relationship |
GroupRedCurl | RedCurl has gained access to a contractor to pivot to the victim’s infrastructure. |
| T1199 Trusted Relationship |
GroupAPT29 | APT29 has compromised IT, cloud services, and managed services providers to gain broad access to multiple customers for subsequent operations. |
| T1199 Trusted Relationship |
GroupAPT28 | Once APT28 gained access to the DCCC network, the group then proceeded to use that access to compromise the DNC network. |
| T1199 Trusted Relationship |
GroupGOLD SOUTHFIELD | GOLD SOUTHFIELD has breached Managed Service Providers (MSP's) to deliver malware to MSP customers. |
| T1199 Trusted Relationship |
GroupLAPSUS$ | LAPSUS$ has accessed internet-facing identity providers such as Azure Active Directory and Okta to target specific organizations. |
| T1199 Trusted Relationship |
GroupVOID MANTICORE | VOID MANTICORE has targeted IT and service providers in an effort to obtain credentials, relying largely on compromised VPN accounts for initial access. |
| T1199 Trusted Relationship |
GroupThreat Group-3390 | Threat Group-3390 has compromised third party service providers to gain access to victim's environments. |
| T1200 Hardware Additions |
GroupDarkVishnya | DarkVishnya physically connected Bash Bunny, Raspberry Pi, netbooks, and inexpensive laptops to the target organization's environment to access the company’s local network. |
| T1201 Password Policy Discovery |
CampaignOperation CuckooBees | During Operation CuckooBees, the threat actors used the `net accounts` command as part of their advanced reconnaissance. |
| T1201 Password Policy Discovery |
GroupOilRig | OilRig has used net.exe in a script with |
| T1201 Password Policy Discovery |
GroupTurla | Turla has used |
| T1201 Password Policy Discovery |
GroupChimera | Chimera has used the NtdsAudit utility to collect information related to accounts and passwords. |
| T1201 Password Policy Discovery |
MalwareKwampirs | Kwampirs collects password policy information with the command |
| T1201 Password Policy Discovery |
ToolNet | The |
| T1201 Password Policy Discovery |
ToolPoshC2 | PoshC2 can use |
| T1201 Password Policy Discovery |
ToolCrackMapExec | CrackMapExec can discover the password policies applied to the target system. |
| T1202 Indirect Command Execution |
GroupRedCurl | RedCurl has used pcalua.exe to obfuscate binary execution and remote connections. |
| T1202 Indirect Command Execution |
GroupLazarus Group | Lazarus Group persistence mechanisms have used |
| T1202 Indirect Command Execution |
MalwareRevenge RAT | Revenge RAT uses the Forfiles utility to execute commands on the system. |
| T1202 Indirect Command Execution |
ToolForfiles | Forfiles can be used to subvert controls and possibly conceal command execution by not directly invoking cmd. |
| T1203 Exploitation for Client Execution |
CampaignFrankenstein | During Frankenstein, the threat actors exploited CVE-2017-11882 to execute code on the victim's machine. |
| T1203 Exploitation for Client Execution |
CampaignRedDelta Modified PlugX Infection Chain Operations | Mustang Panda used the GrimResource exploitation technique via specially crafted MSC files for arbitrary code execution during RedDelta Modified PlugX Infection Chain Operations. |
| T1203 Exploitation for Client Execution |
CampaignRedPenguin | During RedPenguin, UNC3886 exploited CVE-2025-21590 to bypass Veriexec protections in Junos OS designed to prevent unauthorized binary execution. |
| T1203 Exploitation for Client Execution |
CampaignOperation Dust Storm | During Operation Dust Storm, the threat actors exploited Adobe Flash vulnerability CVE-2011-0611, Microsoft Windows Help vulnerability CVE-2010-1885, and several Internet Explorer vulnerabilities, including CVE-2011-1255, CVE-2012-1889, and CVE-2014-0322. |
| T1203 Exploitation for Client Execution |
Campaign3CX Supply Chain Attack | During the 3CX Supply Chain Attack, AppleJeus leveraged the Chrome vulnerability, CVE-2022-0609, in combination with a Drive-by Compromise website. |
| T1203 Exploitation for Client Execution |
GroupElderwood | Elderwood has used exploitation of endpoint software, including Microsoft Internet Explorer Adobe Flash vulnerabilities, to gain execution. They have also used zero-day exploits. |
| T1203 Exploitation for Client Execution |
GroupAPT3 | APT3 has exploited the Adobe Flash Player vulnerability CVE-2015-3113 and Internet Explorer vulnerability CVE-2014-1776. |
| T1203 Exploitation for Client Execution |
GroupEXOTIC LILY | EXOTIC LILY has used malicious documents containing exploits for CVE-2021-40444 affecting Microsoft MSHTML. |
| T1203 Exploitation for Client Execution |
Groupadmin@338 | admin@338 has exploited client software vulnerabilities for execution, such as Microsoft Word CVE-2012-0158. |
| T1203 Exploitation for Client Execution |
GroupPatchwork | Patchwork uses malicious documents to deliver remote execution exploits as part of. The group has previously exploited CVE-2017-8570, CVE-2012-1856, CVE-2014-4114, CVE-2017-0199, CVE-2017-11882, and CVE-2015-1641. |
| T1203 Exploitation for Client Execution |
GroupAPT41 | APT41 leveraged the follow exploits in their operations: CVE-2012-0158, CVE-2015-1641, CVE-2017-0199, CVE-2017-11882, and CVE-2019-3396. |
| T1203 Exploitation for Client Execution |
GroupDragonfly | Dragonfly has exploited CVE-2011-0611 in Adobe Flash Player to gain execution on a targeted system. |
| T1203 Exploitation for Client Execution |
GroupAPT32 | APT32 has used RTF document that includes an exploit to execute malicious code. (CVE-2017-11882) |
| T1203 Exploitation for Client Execution |
GroupMuddyWater | MuddyWater has exploited the Office vulnerability CVE-2017-0199 for execution. |
| T1203 Exploitation for Client Execution |
GroupSandworm Team | Sandworm Team has exploited vulnerabilities in Microsoft PowerPoint via OLE objects (CVE-2014-4114) and Microsoft Word via crafted TIFF images (CVE-2013-3906). |
| T1203 Exploitation for Client Execution |
GroupAndariel | Andariel has exploited numerous ActiveX vulnerabilities, including zero-days. |
| T1203 Exploitation for Client Execution |
GroupSidewinder | Sidewinder has exploited vulnerabilities to gain execution including CVE-2017-11882 and CVE-2020-0674. |
| T1203 Exploitation for Client Execution |
GroupMustang Panda | Mustang Panda has exploited CVE-2017-0199 in Microsoft Word to execute code. |
| T1203 Exploitation for Client Execution |
GroupUNC3886 | UNC3886 has exoloited CVE-2023-34048 to enable command execution on vCenter servers and CVE-2023-20867 in VMware Tools to execute unauthenticated Guest Operations from ESXi hosts to guest VMs. |
| T1203 Exploitation for Client Execution |
GroupAPT37 | APT37 has used exploits for Flash Player (CVE-2016-4117, CVE-2018-4878), Word (CVE-2017-0199), Internet Explorer (CVE-2020-1380 and CVE-2020-26411), and Microsoft Edge (CVE-2021-26411) for execution. |
| T1203 Exploitation for Client Execution |
GroupOilRig | OilRig has exploited CVE-2024-30088 to run arbitrary code in the context of `SYSTEM`. |
| T1203 Exploitation for Client Execution |
GroupHigaisa | Higaisa has exploited CVE-2018-0798 for execution. |
| T1203 Exploitation for Client Execution |
GroupTropic Trooper | Tropic Trooper has executed commands through Microsoft security vulnerabilities, including CVE-2017-11882, CVE-2018-0802, and CVE-2012-0158. |
| T1203 Exploitation for Client Execution |
GroupSea Turtle | Sea Turtle has used exploits for vulnerabilities such as CVE-2021-44228, CVE-2021-21974, and CVE-2022-0847 to achieve client code execution. |
| T1203 Exploitation for Client Execution |
GroupTA459 | TA459 has exploited Microsoft Word vulnerability CVE-2017-0199 for execution. |
| T1203 Exploitation for Client Execution |
GroupAoqin Dragon | Aoqin Dragon has exploited CVE-2012-0158 and CVE-2010-3333 for execution against targeted systems. |
| T1203 Exploitation for Client Execution |
GroupThe White Company | The White Company has taken advantage of a known vulnerability in Microsoft Word (CVE 2012-0158) to execute code. |
| T1203 Exploitation for Client Execution |
GroupSaint Bear | Saint Bear has leveraged vulnerabilities in client applications such as CVE-2017-11882 in Microsoft Office to enable code execution in victim environments. |
| T1203 Exploitation for Client Execution |
GroupConfucius | Confucius has exploited Microsoft Office vulnerabilities, including CVE-2015-1641, CVE-2017-11882, and CVE-2018-0802. |
| T1203 Exploitation for Client Execution |
GroupBlackTech | BlackTech has exploited multiple vulnerabilities for execution, including Microsoft Office vulnerabilities CVE-2012-0158, CVE-2014-6352, CVE-2017-0199, and Adobe Flash CVE-2015-5119. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.