ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1213.002
Sharepoint
GroupChimera

Chimera has collected documents from the victim's SharePoint.

T1213.002
Sharepoint
GroupAPT28

APT28 has collected information from Microsoft SharePoint services within target networks.

T1213.002
Sharepoint
GroupLAPSUS$

LAPSUS$ has searched a victim's network for collaboration platforms like SharePoint to discover further high-privilege account credentials.

T1213.002
Sharepoint
GroupVOID MANTICORE

VOID MANTICORE has accessed victim’s public facing SharePoint servers and exfiltrated data.

T1213.002
Sharepoint
Toolspwebmember

spwebmember is used to enumerate and dump information from Microsoft SharePoint.

T1213.002
Sharepoint
ToolTruffleHog

TruffleHog has searched SharePoint for data and credentials.

T1213.003
Code Repositories
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 downloaded source code from code repositories.

T1213.003
Code Repositories
GroupAPT41

APT41 cloned victim user Git repositories during intrusions.

T1213.003
Code Repositories
GroupScattered Spider

Scattered Spider enumerates data stored within victim code repositories, such as internal GitHub repositories.

T1213.003
Code Repositories
GroupLAPSUS$

LAPSUS$ has searched a victim's network for code repositories like GitLab and GitHub to discover further high-privilege account credentials.

T1213.003
Code Repositories
MalwareGlassWorm

GlassWorm has gathered code repository authentication materials for NPM and GitHub. GlassWorm has collected details pertaining to the npm configuration data for `_authToken`.

T1213.003
Code Repositories
MalwareShai-Hulud

Shai-Hulud has downloaded existing packages from code repositories and extracted data stored within them.

T1213.003
Code Repositories
ToolTruffleHog

TruffleHog has gathered data and credentials from code repositories.

T1213.003
Code Repositories
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer can target sensitive file paths in Git repos to extract credentials.

T1213.003
Code Repositories
MalwareMini Shai-Hulud

Mini Shai-Hulud has gathered and downloaded data stored on both compromised and publicly accessible code repositories.

T1213.003
Code Repositories
GroupShinyHunters

ShinyHunters has gathered information from and has searched for vulnerabilities in the target company’s GitHub repository source code.

T1213.004
Customer Relationship Management Software
CampaignSalesforce Data Exfiltration

During Salesforce Data Exfiltration, threat actors accessed and exfiltrated sensitive information from compromised Salesforce instances.

T1213.005
Messaging Applications
GroupScattered Spider

Scattered Spider threat actors search the victim’s Slack and Microsoft Teams for conversations about the intrusion and incident response.

T1213.005
Messaging Applications
GroupFox Kitten

Fox Kitten has accessed victim security and IT environments and Microsoft Teams to mine valuable information.

T1213.005
Messaging Applications
GroupLAPSUS$

LAPSUS$ has searched a victim's network for organization collaboration channels like MS Teams or Slack to discover further high-privilege account credentials.

T1213.005
Messaging Applications
ToolTruffleHog

TruffleHog has obtained data and credentials associated with messaging applications to include Slack.

T1213.006
Databases
CampaignAnthropic AI-orchestrated Campaign

During the Anthropic AI-orchestrated Campaign, the adversary used Claude Code to query internal databases and systems to extract proprietary information, system configurations, and sensitive operational data.

T1213.006
Databases
CampaignAPT41 DUST

APT41 DUST collected data from victim Oracle databases using SQLULDR2.

T1213.006
Databases
CampaignLeviathan Australian Intrusions

Leviathan gathered information from SQL servers and Building Management System (BMS) servers during Leviathan Australian Intrusions.

T1213.006
Databases
GroupFIN6

FIN6 has collected schemas and user accounts from systems running SQL Server.

T1213.006
Databases
GroupSandworm Team

Sandworm Team exfiltrates data of interest from enterprise databases using Adminer.

T1213.006
Databases
GroupSea Turtle

Sea Turtle used the tool Adminer to remotely logon to the MySQL service of victim machines.

T1213.006
Databases
GroupTurla

Turla has used a custom .NET tool to collect documents from an organization's internal central database.

T1213.006
Databases
MalwareP.A.S. Webshell

P.A.S. Webshell has the ability to list and extract data from SQL databases.

T1213.006
Databases
MalwareGlassWorm

GlassWorm has collected data from macOS devices through the gathering of Apple Notes related files by targeting `/Library/Group Containers/group.com.apple.notes/NoteStore.sqlite`, `/Library/Group Containers/group.com.apple.notes/NoteStore.sqlite-wal`, and `/Library/Group Containers/group.com.apple.notes/NoteStore.sqlite-shm`.

T1213.006
Databases
MalwareMgBot

MgBot includes a module capable of stealing content from the Tencent QQ database storing user QQ message history on infected devices.

T1213.006
Databases
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer can extract credentials from multiple database configuration files including ~/.pgpass, ~/.my.cnf, ~/.mongorc.js, and /etc/mysql/my.cnf.

T1213.006
Databases
GroupShinyHunters

ShinyHunters has collected Salesforce datasets from victims in the airline and retail sectors.

T1216.001
PubPrn
GroupAPT32

APT32 has used PubPrn.vbs within execution scripts to execute malware, possibly bypassing defenses.

T1217
Browser Information Discovery
Campaign3CX Supply Chain Attack

During the 3CX Supply Chain Attack, AppleJeus leveraged ICONICSTEALER to steal browser information to include browser history located on the infected host.

T1217
Browser Information Discovery
CampaignJuicy Mix

During Juicy Mix, OilRig used the CDumper (Chrome browser) and EDumper (Edge browser) data stealers to collect cookies, browsing history, and credentials.

T1217
Browser Information Discovery
CampaignOperation AkaiRyū

During Operation AkaiRyū, MirrorFace exported Chrome web data including contact information, keywords, autofill data, and stored credit card information.

T1217
Browser Information Discovery
CampaignOuter Space

During Outer Space, OilRig used a Chrome data dumper named MKG.

T1217
Browser Information Discovery
GroupAPT38

APT38 has collected browser bookmark information to learn more about compromised hosts, obtain personal information about users, and acquire details about internal network resources.

T1217
Browser Information Discovery
GroupKimsuky

Kimsuky has collected sensitive browser data using the function `GetBrowserData()` to include login credentials, bookmarks, cookies, and encryption keys.

T1217
Browser Information Discovery
GroupVolt Typhoon

Volt Typhoon has targeted the browsing history of network administrators.

T1217
Browser Information Discovery
GroupScattered Spider

Scattered Spider retrieves browser histories via infostealer malware such as Raccoon Stealer.

T1217
Browser Information Discovery
GroupChimera

Chimera has used type \\<hostname>\c$\Users\<username>\Favorites\Links\Bookmarks bar\Imported From IE\*citrix* for bookmark discovery.

T1217
Browser Information Discovery
GroupFox Kitten

Fox Kitten has used Google Chrome bookmarks to identify internal resources and assets.

T1217
Browser Information Discovery
GroupMoonstone Sleet

Moonstone Sleet deployed malware such as YouieLoader capable of capturing victim system browser information.

T1217
Browser Information Discovery
MalwareMachete

Machete retrieves the user profile data (e.g., browsers) from Chrome and Firefox browsers.

T1217
Browser Information Discovery
MalwarePowerLess

PowerLess has a browser info stealer module that can read Chrome and Edge browser database files.

T1217
Browser Information Discovery
MalwareMafalda

Mafalda can collect the contents of the `%USERPROFILE%\AppData\Local\Google\Chrome\User Data\LocalState` file.

T1217
Browser Information Discovery
MalwareCuckoo Stealer

Cuckoo Stealer can collect bookmarks, cookies, and history from Safari.

T1217
Browser Information Discovery
MalwareMobileOrder

MobileOrder has a command to upload to its C2 server victim browser bookmarks.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.