ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1199
Trusted Relationship
GroupRedCurl

RedCurl has gained access to a contractor to pivot to the victim’s infrastructure.

T1199
Trusted Relationship
GroupAPT29

APT29 has compromised IT, cloud services, and managed services providers to gain broad access to multiple customers for subsequent operations.

T1199
Trusted Relationship
GroupAPT28

Once APT28 gained access to the DCCC network, the group then proceeded to use that access to compromise the DNC network.

T1199
Trusted Relationship
GroupGOLD SOUTHFIELD

GOLD SOUTHFIELD has breached Managed Service Providers (MSP's) to deliver malware to MSP customers.

T1199
Trusted Relationship
GroupLAPSUS$

LAPSUS$ has accessed internet-facing identity providers such as Azure Active Directory and Okta to target specific organizations.

T1199
Trusted Relationship
GroupVOID MANTICORE

VOID MANTICORE has targeted IT and service providers in an effort to obtain credentials, relying largely on compromised VPN accounts for initial access.

T1199
Trusted Relationship
GroupThreat Group-3390

Threat Group-3390 has compromised third party service providers to gain access to victim's environments.

T1200
Hardware Additions
GroupDarkVishnya

DarkVishnya physically connected Bash Bunny, Raspberry Pi, netbooks, and inexpensive laptops to the target organization's environment to access the company’s local network.

T1201
Password Policy Discovery
CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors used the `net accounts` command as part of their advanced reconnaissance.

T1201
Password Policy Discovery
GroupOilRig

OilRig has used net.exe in a script with net accounts /domain to find the password policy of a domain.

T1201
Password Policy Discovery
GroupTurla

Turla has used net accounts and net accounts /domain to acquire password policy information.

T1201
Password Policy Discovery
GroupChimera

Chimera has used the NtdsAudit utility to collect information related to accounts and passwords.

T1201
Password Policy Discovery
MalwareKwampirs

Kwampirs collects password policy information with the command net accounts.

T1201
Password Policy Discovery
ToolNet

The net accounts and net accounts /domain commands with Net can be used to obtain password policy information.

T1201
Password Policy Discovery
ToolPoshC2

PoshC2 can use Get-PassPol to enumerate the domain password policy.

T1201
Password Policy Discovery
ToolCrackMapExec

CrackMapExec can discover the password policies applied to the target system.

T1202
Indirect Command Execution
GroupRedCurl

RedCurl has used pcalua.exe to obfuscate binary execution and remote connections.

T1202
Indirect Command Execution
GroupLazarus Group

Lazarus Group persistence mechanisms have used forfiles.exe to execute .htm files.

T1202
Indirect Command Execution
MalwareRevenge RAT

Revenge RAT uses the Forfiles utility to execute commands on the system.

T1202
Indirect Command Execution
ToolForfiles

Forfiles can be used to subvert controls and possibly conceal command execution by not directly invoking cmd.

T1203
Exploitation for Client Execution
CampaignFrankenstein

During Frankenstein, the threat actors exploited CVE-2017-11882 to execute code on the victim's machine.

T1203
Exploitation for Client Execution
CampaignRedDelta Modified PlugX Infection Chain Operations

Mustang Panda used the GrimResource exploitation technique via specially crafted MSC files for arbitrary code execution during RedDelta Modified PlugX Infection Chain Operations.

T1203
Exploitation for Client Execution
CampaignRedPenguin

During RedPenguin, UNC3886 exploited CVE-2025-21590 to bypass Veriexec protections in Junos OS designed to prevent unauthorized binary execution.

T1203
Exploitation for Client Execution
CampaignOperation Dust Storm

During Operation Dust Storm, the threat actors exploited Adobe Flash vulnerability CVE-2011-0611, Microsoft Windows Help vulnerability CVE-2010-1885, and several Internet Explorer vulnerabilities, including CVE-2011-1255, CVE-2012-1889, and CVE-2014-0322.

T1203
Exploitation for Client Execution
Campaign3CX Supply Chain Attack

During the 3CX Supply Chain Attack, AppleJeus leveraged the Chrome vulnerability, CVE-2022-0609, in combination with a Drive-by Compromise website.

T1203
Exploitation for Client Execution
GroupElderwood

Elderwood has used exploitation of endpoint software, including Microsoft Internet Explorer Adobe Flash vulnerabilities, to gain execution. They have also used zero-day exploits.

T1203
Exploitation for Client Execution
GroupAPT3

APT3 has exploited the Adobe Flash Player vulnerability CVE-2015-3113 and Internet Explorer vulnerability CVE-2014-1776.

T1203
Exploitation for Client Execution
GroupEXOTIC LILY

EXOTIC LILY has used malicious documents containing exploits for CVE-2021-40444 affecting Microsoft MSHTML.

T1203
Exploitation for Client Execution
Groupadmin@338

admin@338 has exploited client software vulnerabilities for execution, such as Microsoft Word CVE-2012-0158.

T1203
Exploitation for Client Execution
GroupPatchwork

Patchwork uses malicious documents to deliver remote execution exploits as part of. The group has previously exploited CVE-2017-8570, CVE-2012-1856, CVE-2014-4114, CVE-2017-0199, CVE-2017-11882, and CVE-2015-1641.

T1203
Exploitation for Client Execution
GroupAPT41

APT41 leveraged the follow exploits in their operations: CVE-2012-0158, CVE-2015-1641, CVE-2017-0199, CVE-2017-11882, and CVE-2019-3396.

T1203
Exploitation for Client Execution
GroupDragonfly

Dragonfly has exploited CVE-2011-0611 in Adobe Flash Player to gain execution on a targeted system.

T1203
Exploitation for Client Execution
GroupAPT32

APT32 has used RTF document that includes an exploit to execute malicious code. (CVE-2017-11882)

T1203
Exploitation for Client Execution
GroupMuddyWater

MuddyWater has exploited the Office vulnerability CVE-2017-0199 for execution.

T1203
Exploitation for Client Execution
GroupSandworm Team

Sandworm Team has exploited vulnerabilities in Microsoft PowerPoint via OLE objects (CVE-2014-4114) and Microsoft Word via crafted TIFF images (CVE-2013-3906).

T1203
Exploitation for Client Execution
GroupAndariel

Andariel has exploited numerous ActiveX vulnerabilities, including zero-days.

T1203
Exploitation for Client Execution
GroupSidewinder

Sidewinder has exploited vulnerabilities to gain execution including CVE-2017-11882 and CVE-2020-0674.

T1203
Exploitation for Client Execution
GroupMustang Panda

Mustang Panda has exploited CVE-2017-0199 in Microsoft Word to execute code.

T1203
Exploitation for Client Execution
GroupUNC3886

UNC3886 has exoloited CVE-2023-34048 to enable command execution on vCenter servers and CVE-2023-20867 in VMware Tools to execute unauthenticated Guest Operations from ESXi hosts to guest VMs.

T1203
Exploitation for Client Execution
GroupAPT37

APT37 has used exploits for Flash Player (CVE-2016-4117, CVE-2018-4878), Word (CVE-2017-0199), Internet Explorer (CVE-2020-1380 and CVE-2020-26411), and Microsoft Edge (CVE-2021-26411) for execution.

T1203
Exploitation for Client Execution
GroupOilRig

OilRig has exploited CVE-2024-30088 to run arbitrary code in the context of `SYSTEM`.

T1203
Exploitation for Client Execution
GroupHigaisa

Higaisa has exploited CVE-2018-0798 for execution.

T1203
Exploitation for Client Execution
GroupTropic Trooper

Tropic Trooper has executed commands through Microsoft security vulnerabilities, including CVE-2017-11882, CVE-2018-0802, and CVE-2012-0158.

T1203
Exploitation for Client Execution
GroupSea Turtle

Sea Turtle has used exploits for vulnerabilities such as CVE-2021-44228, CVE-2021-21974, and CVE-2022-0847 to achieve client code execution.

T1203
Exploitation for Client Execution
GroupTA459

TA459 has exploited Microsoft Word vulnerability CVE-2017-0199 for execution.

T1203
Exploitation for Client Execution
GroupAoqin Dragon

Aoqin Dragon has exploited CVE-2012-0158 and CVE-2010-3333 for execution against targeted systems.

T1203
Exploitation for Client Execution
GroupThe White Company

The White Company has taken advantage of a known vulnerability in Microsoft Word (CVE 2012-0158) to execute code.

T1203
Exploitation for Client Execution
GroupSaint Bear

Saint Bear has leveraged vulnerabilities in client applications such as CVE-2017-11882 in Microsoft Office to enable code execution in victim environments.

T1203
Exploitation for Client Execution
GroupConfucius

Confucius has exploited Microsoft Office vulnerabilities, including CVE-2015-1641, CVE-2017-11882, and CVE-2018-0802.

T1203
Exploitation for Client Execution
GroupBlackTech

BlackTech has exploited multiple vulnerabilities for execution, including Microsoft Office vulnerabilities CVE-2012-0158, CVE-2014-6352, CVE-2017-0199, and Adobe Flash CVE-2015-5119.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.