Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1213.002 Sharepoint |
GroupChimera | Chimera has collected documents from the victim's SharePoint. |
| T1213.002 Sharepoint |
GroupAPT28 | APT28 has collected information from Microsoft SharePoint services within target networks. |
| T1213.002 Sharepoint |
GroupLAPSUS$ | LAPSUS$ has searched a victim's network for collaboration platforms like SharePoint to discover further high-privilege account credentials. |
| T1213.002 Sharepoint |
GroupVOID MANTICORE | VOID MANTICORE has accessed victim’s public facing SharePoint servers and exfiltrated data. |
| T1213.002 Sharepoint |
Toolspwebmember | spwebmember is used to enumerate and dump information from Microsoft SharePoint. |
| T1213.002 Sharepoint |
ToolTruffleHog | TruffleHog has searched SharePoint for data and credentials. |
| T1213.003 Code Repositories |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 downloaded source code from code repositories. |
| T1213.003 Code Repositories |
GroupAPT41 | APT41 cloned victim user Git repositories during intrusions. |
| T1213.003 Code Repositories |
GroupScattered Spider | Scattered Spider enumerates data stored within victim code repositories, such as internal GitHub repositories. |
| T1213.003 Code Repositories |
GroupLAPSUS$ | LAPSUS$ has searched a victim's network for code repositories like GitLab and GitHub to discover further high-privilege account credentials. |
| T1213.003 Code Repositories |
MalwareGlassWorm | GlassWorm has gathered code repository authentication materials for NPM and GitHub. GlassWorm has collected details pertaining to the npm configuration data for `_authToken`. |
| T1213.003 Code Repositories |
MalwareShai-Hulud | Shai-Hulud has downloaded existing packages from code repositories and extracted data stored within them. |
| T1213.003 Code Repositories |
ToolTruffleHog | TruffleHog has gathered data and credentials from code repositories. |
| T1213.003 Code Repositories |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer can target sensitive file paths in Git repos to extract credentials. |
| T1213.003 Code Repositories |
MalwareMini Shai-Hulud | Mini Shai-Hulud has gathered and downloaded data stored on both compromised and publicly accessible code repositories. |
| T1213.003 Code Repositories |
GroupShinyHunters | ShinyHunters has gathered information from and has searched for vulnerabilities in the target company’s GitHub repository source code. |
| T1213.004 Customer Relationship Management Software |
CampaignSalesforce Data Exfiltration | During Salesforce Data Exfiltration, threat actors accessed and exfiltrated sensitive information from compromised Salesforce instances. |
| T1213.005 Messaging Applications |
GroupScattered Spider | Scattered Spider threat actors search the victim’s Slack and Microsoft Teams for conversations about the intrusion and incident response. |
| T1213.005 Messaging Applications |
GroupFox Kitten | Fox Kitten has accessed victim security and IT environments and Microsoft Teams to mine valuable information. |
| T1213.005 Messaging Applications |
GroupLAPSUS$ | LAPSUS$ has searched a victim's network for organization collaboration channels like MS Teams or Slack to discover further high-privilege account credentials. |
| T1213.005 Messaging Applications |
ToolTruffleHog | TruffleHog has obtained data and credentials associated with messaging applications to include Slack. |
| T1213.006 Databases |
CampaignAnthropic AI-orchestrated Campaign | During the Anthropic AI-orchestrated Campaign, the adversary used Claude Code to query internal databases and systems to extract proprietary information, system configurations, and sensitive operational data. |
| T1213.006 Databases |
CampaignAPT41 DUST | APT41 DUST collected data from victim Oracle databases using SQLULDR2. |
| T1213.006 Databases |
CampaignLeviathan Australian Intrusions | Leviathan gathered information from SQL servers and Building Management System (BMS) servers during Leviathan Australian Intrusions. |
| T1213.006 Databases |
GroupFIN6 | FIN6 has collected schemas and user accounts from systems running SQL Server. |
| T1213.006 Databases |
GroupSandworm Team | Sandworm Team exfiltrates data of interest from enterprise databases using Adminer. |
| T1213.006 Databases |
GroupSea Turtle | Sea Turtle used the tool Adminer to remotely logon to the MySQL service of victim machines. |
| T1213.006 Databases |
GroupTurla | Turla has used a custom .NET tool to collect documents from an organization's internal central database. |
| T1213.006 Databases |
MalwareP.A.S. Webshell | P.A.S. Webshell has the ability to list and extract data from SQL databases. |
| T1213.006 Databases |
MalwareGlassWorm | GlassWorm has collected data from macOS devices through the gathering of Apple Notes related files by targeting `/Library/Group Containers/group.com.apple.notes/NoteStore.sqlite`, `/Library/Group Containers/group.com.apple.notes/NoteStore.sqlite-wal`, and `/Library/Group Containers/group.com.apple.notes/NoteStore.sqlite-shm`. |
| T1213.006 Databases |
MalwareMgBot | MgBot includes a module capable of stealing content from the Tencent QQ database storing user QQ message history on infected devices. |
| T1213.006 Databases |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer can extract credentials from multiple database configuration files including ~/.pgpass, ~/.my.cnf, ~/.mongorc.js, and /etc/mysql/my.cnf. |
| T1213.006 Databases |
GroupShinyHunters | ShinyHunters has collected Salesforce datasets from victims in the airline and retail sectors. |
| T1216.001 PubPrn |
GroupAPT32 | APT32 has used PubPrn.vbs within execution scripts to execute malware, possibly bypassing defenses. |
| T1217 Browser Information Discovery |
Campaign3CX Supply Chain Attack | During the 3CX Supply Chain Attack, AppleJeus leveraged ICONICSTEALER to steal browser information to include browser history located on the infected host. |
| T1217 Browser Information Discovery |
CampaignJuicy Mix | During Juicy Mix, OilRig used the CDumper (Chrome browser) and EDumper (Edge browser) data stealers to collect cookies, browsing history, and credentials. |
| T1217 Browser Information Discovery |
CampaignOperation AkaiRyū | During Operation AkaiRyū, MirrorFace exported Chrome web data including contact information, keywords, autofill data, and stored credit card information. |
| T1217 Browser Information Discovery |
CampaignOuter Space | During Outer Space, OilRig used a Chrome data dumper named MKG. |
| T1217 Browser Information Discovery |
GroupAPT38 | APT38 has collected browser bookmark information to learn more about compromised hosts, obtain personal information about users, and acquire details about internal network resources. |
| T1217 Browser Information Discovery |
GroupKimsuky | Kimsuky has collected sensitive browser data using the function `GetBrowserData()` to include login credentials, bookmarks, cookies, and encryption keys. |
| T1217 Browser Information Discovery |
GroupVolt Typhoon | Volt Typhoon has targeted the browsing history of network administrators. |
| T1217 Browser Information Discovery |
GroupScattered Spider | Scattered Spider retrieves browser histories via infostealer malware such as Raccoon Stealer. |
| T1217 Browser Information Discovery |
GroupChimera | Chimera has used |
| T1217 Browser Information Discovery |
GroupFox Kitten | Fox Kitten has used Google Chrome bookmarks to identify internal resources and assets. |
| T1217 Browser Information Discovery |
GroupMoonstone Sleet | Moonstone Sleet deployed malware such as YouieLoader capable of capturing victim system browser information. |
| T1217 Browser Information Discovery |
MalwareMachete | Machete retrieves the user profile data (e.g., browsers) from Chrome and Firefox browsers. |
| T1217 Browser Information Discovery |
MalwarePowerLess | PowerLess has a browser info stealer module that can read Chrome and Edge browser database files. |
| T1217 Browser Information Discovery |
MalwareMafalda | Mafalda can collect the contents of the `%USERPROFILE%\AppData\Local\Google\Chrome\User Data\LocalState` file. |
| T1217 Browser Information Discovery |
MalwareCuckoo Stealer | Cuckoo Stealer can collect bookmarks, cookies, and history from Safari. |
| T1217 Browser Information Discovery |
MalwareMobileOrder | MobileOrder has a command to upload to its C2 server victim browser bookmarks. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.