ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

1146 examples

TechniqueUsed byProcedure example
T1608.005
Link Target
CampaignOperation AkaiRyū

During Operation AkaiRyū, MirrorFace used links to direct victims to malicious files hosted on OneDrive.

T1608.005
Link Target
CampaignSalesforce Data Exfiltration

During Salesforce Data Exfiltration, threat actors established an Okta phishing panel which victims were tricked into accessing from mobile phones or work computers during social engineering calls.

T1614.001
System Language Discovery
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group deployed malware designed not to run on computers set to Korean, Japanese, or Chinese in Windows language preferences.

T1614.001
System Language Discovery
CampaignOperation Digital Eye

During Operation Digital Eye, threat actors used the local language of targeted organizations to disguise file system activity.

T1615
Group Policy Discovery
CampaignLeviathan Australian Intrusions

Leviathan performed extensive Active Directory enumeration of victim environments during Leviathan Australian Intrusions.

T1620
Reflective Code Loading
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors reflectively loaded payloads using `System.Reflection.Assembly.Load`.

T1620
Reflective Code Loading
Campaign3CX Supply Chain Attack

During the 3CX Supply Chain Attack, AppleJeus leverages the publicly available open-source project DAVESHELL to convert PE-COFF files to position-independent code to reflectively load the payload into memory.

T1621
Multi-Factor Authentication Request Generation
CampaignC0027

During C0027, Scattered Spider attempted to gain access by continuously sending MFA messages to the victim until they accept the MFA push challenge.

T1622
Debugger Evasion
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group used tools that used the `IsDebuggerPresent` call to detect debuggers.

T1653
Power Settings
CampaignArcaneDoor

ArcaneDoor involved exploitation of CVE-2024-20353 to force a victim Cisco ASA to reboot, triggering the automated unzipping and execution of the Line Runner implant.

T1657
Financial Theft
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors demanded ransom payments to unencrypt filesystems and to refrain from publishing sensitive data exfiltrated from victim networks.

T1665
Hide Infrastructure
CampaignOperation Digital Eye

During Operation Digital Eye, threat actors used public Cloud infrastructure to mask malicious activity.

T1665
Hide Infrastructure
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 set the hostnames of their C2 infrastructure to match legitimate hostnames in the victim environment. They also used IP addresses originating from the same country as the victim for their VPN infrastructure.

T1665
Hide Infrastructure
CampaignQuad7 Activity

Quad7 Activity has rotated the compromised SOHO IPs used in password spraying activity to hamper detection and network blocking activities by defenders.

T1669
Wi-Fi Networks
CampaignAPT28 Nearest Neighbor Campaign

During APT28 Nearest Neighbor Campaign, APT28 established wireless connections to secure, enterprise Wi-Fi networks belonging to a target organization for initial access into the environment.

T1671
Cloud Application Integration
CampaignSalesforce Data Exfiltration

During Salesforce Data Exfiltration, threat actors deceived victims into authorizing malicious connected apps to their organization's Salesforce portal.

T1678
Delay Execution
Campaign3CX Supply Chain Attack

During the 3CX Supply Chain Attack, AppleJeus's software generates a randomly selected date that is between 1-4 weeks in the future. This timestamp is then checked against the current time of the compromised machine, and the malware will sleep until that time is encountered.

T1680
Local Storage Discovery
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used `fsutil` to check available free space before executing actions that might create large files on disk.

T1680
Local Storage Discovery
CampaignOperation Wocao

During Operation Wocao, threat actors discovered the local disks attached to the system and their hardware information including manufacturer and model.

T1680
Local Storage Discovery
CampaignC0017

During C0017, APT41 issued `ping -n 1 ((cmd /c dir c:\|findstr Number).split()[-1]+` commands to find the volume serial number of compromised systems.

T1683
Generate Content
CampaignAnthropic AI-orchestrated Campaign

During the Anthropic AI-orchestrated Campaign, the adversary utilized Claude Code to automatically generate comprehensive documentation throughout the phases of the attack, including discovered services, harvested credentials, sensitive data, exploitation techniques, and complete attack progression.

T1684.001
Impersonation
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group impersonated HR hiring personnel through LinkedIn messages and conducted interviews with victims in order to deceive them into downloading malware.

T1684.001
Impersonation
CampaignSalesforce Data Exfiltration

During Salesforce Data Exfiltration, threat actors impersonated IT support personnel in voice calls with victims at times claiming to be addressing enterprise-wide connectivity issues.

T1684.001
Impersonation
CampaignC0027

During C0027, Scattered Spider impersonated legitimate IT personnel in phone calls and text messages either to direct victims to a credential harvesting site or getting victims to run commercial remote monitoring and management (RMM) tools.

T1685
Disable or Modify Tools
CampaignKV Botnet Activity

KV Botnet Activity used various scripts to remove or disable security tools, such as http_watchdog and firewallsd, as well as tools related to other botnet infections, such as mips_ff, on victim devices.

T1685
Disable or Modify Tools
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors disabled Microsoft Defender through Registry settings and real-time monitoring via PowerShell.

T1685
Disable or Modify Tools
Campaign2015 Ukraine Electric Power Attack

During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry internet settings to lower internet security.

T1685
Disable or Modify Tools
CampaignCutting Edge

During Cutting Edge, threat actors disabled logging and modified the `compcheckresult.cgi` component to edit the Ivanti Connect Secure built-in Integrity Checker exclusion list to evade detection.

T1685
Disable or Modify Tools
CampaignHomeLand Justice

During HomeLand Justice, threat actors modified and disabled components of endpoint detection and response (EDR) solutions including Microsoft Defender Antivirus.

T1685
Disable or Modify Tools
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used the service control manager on a remote system to disable services associated with security monitoring products.

T1685
Disable or Modify Tools
CampaignArcaneDoor

ArcaneDoor modified the Authentication, Authorization, and Accounting (AAA) function of targeted Cisco ASA appliances to allow the threat actor to bypass normal AAA operations.

T1685
Disable or Modify Tools
CampaignNight Dragon

During Night Dragon, threat actors disabled anti-virus and anti-spyware tools in some instances on the victim’s machines. The actors also disabled proxy settings to allow direct communication from victims to the Internet.

T1685
Disable or Modify Tools
CampaignQuad7 Activity

Quad7 Activity has disabled the TP-Link management interface for TP-Link by killing the /usr/bin/httpd process.

T1685.001
Disable or Modify Windows Event Log
CampaignHomeLand Justice

During HomeLand Justice, threat actors deleted Windows events and application logs.

T1685.001
Disable or Modify Windows Event Log
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29, used `AUDITPOL` to prevent the collection of audit logs.

T1685.001
Disable or Modify Windows Event Log
Campaign2016 Ukraine Electric Power Attack

During the 2016 Ukraine Electric Power Attack, Sandworm Team disabled event logging on compromised systems.

T1685.005
Clear Windows Event Logs
CampaignOperation AkaiRyū

During Operation AkaiRyū, MirrorFace cleared Windows event logs post compromise.

T1685.005
Clear Windows Event Logs
CampaignOperation Wocao

During Operation Wocao, the threat actors deleted all Windows system and security event logs using `/Q /c wevtutil cl system` and `/Q /c wevtutil cl security`.

T1686
Disable or Modify System Firewall
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used `netsh` to configure firewall rules that limited certain UDP outbound packets.

T1686
Disable or Modify System Firewall
CampaignLeviathan Australian Intrusions

Leviathan modified system firewalls to add two open listening ports on 9998 and 9999 during Leviathan Australian Intrusions.

T1686.002
Network Device Firewall
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries modified security settings within the victims Fortigate device, utilizing the native CLI. During the 2025 Poland Wiper Attacks, the adversaries also disabled network traffic logging.

T1686.003
Windows Host Firewall
CampaignAPT28 Nearest Neighbor Campaign

During APT28 Nearest Neighbor Campaign, APT28 added rules to a victim's Windows firewall to set up a series of port-forwards allowing traffic to target systems.

T1686.003
Windows Host Firewall
CampaignOperation Wocao

During Operation Wocao, threat actors used PowerShell to add and delete rules in the Windows firewall.

T1689
Downgrade Attack
CampaignFrostyGoop Incident

During FrostyGoop Incident, the adversary downgraded firmware on victim devices in order to impair visibility into the process environment.

T1690
Prevent Command History Logging
CampaignRedPenguin

During RedPenguin, UNC3886 used malware to clear the `HISTFILE` environmental variable and to inject into Junos OS processes to inhibit logging.

T1690
Prevent Command History Logging
CampaignArcaneDoor

ArcaneDoor included disabling logging on targeted Cisco ASA appliances.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.