Real-world descriptions of how a group, tool or campaign used a technique.
1146 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1608.005 Link Target |
CampaignOperation AkaiRyū | During Operation AkaiRyū, MirrorFace used links to direct victims to malicious files hosted on OneDrive. |
| T1608.005 Link Target |
CampaignSalesforce Data Exfiltration | During Salesforce Data Exfiltration, threat actors established an Okta phishing panel which victims were tricked into accessing from mobile phones or work computers during social engineering calls. |
| T1614.001 System Language Discovery |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group deployed malware designed not to run on computers set to Korean, Japanese, or Chinese in Windows language preferences. |
| T1614.001 System Language Discovery |
CampaignOperation Digital Eye | During Operation Digital Eye, threat actors used the local language of targeted organizations to disguise file system activity. |
| T1615 Group Policy Discovery |
CampaignLeviathan Australian Intrusions | Leviathan performed extensive Active Directory enumeration of victim environments during Leviathan Australian Intrusions. |
| T1620 Reflective Code Loading |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors reflectively loaded payloads using `System.Reflection.Assembly.Load`. |
| T1620 Reflective Code Loading |
Campaign3CX Supply Chain Attack | During the 3CX Supply Chain Attack, AppleJeus leverages the publicly available open-source project DAVESHELL to convert PE-COFF files to position-independent code to reflectively load the payload into memory. |
| T1621 Multi-Factor Authentication Request Generation |
CampaignC0027 | During C0027, Scattered Spider attempted to gain access by continuously sending MFA messages to the victim until they accept the MFA push challenge. |
| T1622 Debugger Evasion |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group used tools that used the `IsDebuggerPresent` call to detect debuggers. |
| T1653 Power Settings |
CampaignArcaneDoor | ArcaneDoor involved exploitation of CVE-2024-20353 to force a victim Cisco ASA to reboot, triggering the automated unzipping and execution of the Line Runner implant. |
| T1657 Financial Theft |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors demanded ransom payments to unencrypt filesystems and to refrain from publishing sensitive data exfiltrated from victim networks. |
| T1665 Hide Infrastructure |
CampaignOperation Digital Eye | During Operation Digital Eye, threat actors used public Cloud infrastructure to mask malicious activity. |
| T1665 Hide Infrastructure |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 set the hostnames of their C2 infrastructure to match legitimate hostnames in the victim environment. They also used IP addresses originating from the same country as the victim for their VPN infrastructure. |
| T1665 Hide Infrastructure |
CampaignQuad7 Activity | Quad7 Activity has rotated the compromised SOHO IPs used in password spraying activity to hamper detection and network blocking activities by defenders. |
| T1669 Wi-Fi Networks |
CampaignAPT28 Nearest Neighbor Campaign | During APT28 Nearest Neighbor Campaign, APT28 established wireless connections to secure, enterprise Wi-Fi networks belonging to a target organization for initial access into the environment. |
| T1671 Cloud Application Integration |
CampaignSalesforce Data Exfiltration | During Salesforce Data Exfiltration, threat actors deceived victims into authorizing malicious connected apps to their organization's Salesforce portal. |
| T1678 Delay Execution |
Campaign3CX Supply Chain Attack | During the 3CX Supply Chain Attack, AppleJeus's software generates a randomly selected date that is between 1-4 weeks in the future. This timestamp is then checked against the current time of the compromised machine, and the malware will sleep until that time is encountered. |
| T1680 Local Storage Discovery |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used `fsutil` to check available free space before executing actions that might create large files on disk. |
| T1680 Local Storage Discovery |
CampaignOperation Wocao | During Operation Wocao, threat actors discovered the local disks attached to the system and their hardware information including manufacturer and model. |
| T1680 Local Storage Discovery |
CampaignC0017 | During C0017, APT41 issued `ping -n 1 ((cmd /c dir c:\|findstr Number).split()[-1]+` commands to find the volume serial number of compromised systems. |
| T1683 Generate Content |
CampaignAnthropic AI-orchestrated Campaign | During the Anthropic AI-orchestrated Campaign, the adversary utilized Claude Code to automatically generate comprehensive documentation throughout the phases of the attack, including discovered services, harvested credentials, sensitive data, exploitation techniques, and complete attack progression. |
| T1684.001 Impersonation |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group impersonated HR hiring personnel through LinkedIn messages and conducted interviews with victims in order to deceive them into downloading malware. |
| T1684.001 Impersonation |
CampaignSalesforce Data Exfiltration | During Salesforce Data Exfiltration, threat actors impersonated IT support personnel in voice calls with victims at times claiming to be addressing enterprise-wide connectivity issues. |
| T1684.001 Impersonation |
CampaignC0027 | During C0027, Scattered Spider impersonated legitimate IT personnel in phone calls and text messages either to direct victims to a credential harvesting site or getting victims to run commercial remote monitoring and management (RMM) tools. |
| T1685 Disable or Modify Tools |
CampaignKV Botnet Activity | KV Botnet Activity used various scripts to remove or disable security tools, such as |
| T1685 Disable or Modify Tools |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors disabled Microsoft Defender through Registry settings and real-time monitoring via PowerShell. |
| T1685 Disable or Modify Tools |
Campaign2015 Ukraine Electric Power Attack | During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry internet settings to lower internet security. |
| T1685 Disable or Modify Tools |
CampaignCutting Edge | During Cutting Edge, threat actors disabled logging and modified the `compcheckresult.cgi` component to edit the Ivanti Connect Secure built-in Integrity Checker exclusion list to evade detection. |
| T1685 Disable or Modify Tools |
CampaignHomeLand Justice | During HomeLand Justice, threat actors modified and disabled components of endpoint detection and response (EDR) solutions including Microsoft Defender Antivirus. |
| T1685 Disable or Modify Tools |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used the service control manager on a remote system to disable services associated with security monitoring products. |
| T1685 Disable or Modify Tools |
CampaignArcaneDoor | ArcaneDoor modified the Authentication, Authorization, and Accounting (AAA) function of targeted Cisco ASA appliances to allow the threat actor to bypass normal AAA operations. |
| T1685 Disable or Modify Tools |
CampaignNight Dragon | During Night Dragon, threat actors disabled anti-virus and anti-spyware tools in some instances on the victim’s machines. The actors also disabled proxy settings to allow direct communication from victims to the Internet. |
| T1685 Disable or Modify Tools |
CampaignQuad7 Activity | Quad7 Activity has disabled the TP-Link management interface for TP-Link by killing the |
| T1685.001 Disable or Modify Windows Event Log |
CampaignHomeLand Justice | During HomeLand Justice, threat actors deleted Windows events and application logs. |
| T1685.001 Disable or Modify Windows Event Log |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29, used `AUDITPOL` to prevent the collection of audit logs. |
| T1685.001 Disable or Modify Windows Event Log |
Campaign2016 Ukraine Electric Power Attack | During the 2016 Ukraine Electric Power Attack, Sandworm Team disabled event logging on compromised systems. |
| T1685.005 Clear Windows Event Logs |
CampaignOperation AkaiRyū | During Operation AkaiRyū, MirrorFace cleared Windows event logs post compromise. |
| T1685.005 Clear Windows Event Logs |
CampaignOperation Wocao | During Operation Wocao, the threat actors deleted all Windows system and security event logs using `/Q /c wevtutil cl system` and `/Q /c wevtutil cl security`. |
| T1686 Disable or Modify System Firewall |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used `netsh` to configure firewall rules that limited certain UDP outbound packets. |
| T1686 Disable or Modify System Firewall |
CampaignLeviathan Australian Intrusions | Leviathan modified system firewalls to add two open listening ports on 9998 and 9999 during Leviathan Australian Intrusions. |
| T1686.002 Network Device Firewall |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries modified security settings within the victims Fortigate device, utilizing the native CLI. During the 2025 Poland Wiper Attacks, the adversaries also disabled network traffic logging. |
| T1686.003 Windows Host Firewall |
CampaignAPT28 Nearest Neighbor Campaign | During APT28 Nearest Neighbor Campaign, APT28 added rules to a victim's Windows firewall to set up a series of port-forwards allowing traffic to target systems. |
| T1686.003 Windows Host Firewall |
CampaignOperation Wocao | During Operation Wocao, threat actors used PowerShell to add and delete rules in the Windows firewall. |
| T1689 Downgrade Attack |
CampaignFrostyGoop Incident | During FrostyGoop Incident, the adversary downgraded firmware on victim devices in order to impair visibility into the process environment. |
| T1690 Prevent Command History Logging |
CampaignRedPenguin | During RedPenguin, UNC3886 used malware to clear the `HISTFILE` environmental variable and to inject into Junos OS processes to inhibit logging. |
| T1690 Prevent Command History Logging |
CampaignArcaneDoor | ArcaneDoor included disabling logging on targeted Cisco ASA appliances. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.