ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1480.002
Mutual Exclusion
MalwareREvil

REvil attempts to create a mutex using a hard-coded value to ensure that no other instances of itself are running on the host.

T1480.002
Mutual Exclusion
MalwarePoisonIvy

PoisonIvy creates a mutex using either a custom or default value.

T1480.002
Mutual Exclusion
MalwareSUNSPOT

SUNSPOT creates a mutex using the hard-coded value ` {12d61a41-4b74-7610-a4d8-3028d2f56395}` to ensure that only one instance of itself is running.

T1480.002
Mutual Exclusion
MalwareGrimAgent

GrimAgent uses the last 64 bytes of the binary to compute a mutex name. If the generated name is invalid, it will default to the generic `mymutex`.

T1480.002
Mutual Exclusion
MalwareSPAWNCHIMERA

SPAWNCHIMERA has fixed a buffer overflow vulnerability (CVE-2025-0282) by hooking the strncpy function and limiting the size to 256 to prevent other actors from leveraging the exploit. SPAWNCHIMERA has converted its process name to hexadecimal and verifies an added value which is triggered when the first byte of the source copied to the fixed strncpy function matches `0x04050203`.

T1480.002
Mutual Exclusion
MalwareTroll Stealer

Troll Stealer creates a mutex during installation to prevent duplicate execution.

T1480.002
Mutual Exclusion
MalwareQilin

Qilin can create a mutex to ensure only one instance is running.

T1482
Domain Trust Discovery
CampaignC0015

During C0015, the threat actors used the command `nltest /domain_trusts /all_trusts` to enumerate domain trusts.

T1482
Domain Trust Discovery
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used the `Get-AcceptedDomain` PowerShell cmdlet to enumerate accepted domains through an Exchange Management Shell. They also used AdFind to enumerate domains and to discover trust between federated domains.

T1482
Domain Trust Discovery
CampaignLeviathan Australian Intrusions

Leviathan performed Active Directory enumeration of victim environments during Leviathan Australian Intrusions.

T1482
Domain Trust Discovery
GroupBlackByte

BlackByte enumerated Active Directory information and trust relationships during operations.

T1482
Domain Trust Discovery
GroupStorm-1811

Storm-1811 has enumerated domain accounts and access during intrusions.

T1482
Domain Trust Discovery
GroupAkira

Akira uses the built-in Nltest utility or tools such as AdFind to enumerate Active Directory trusts in victim environments.

T1482
Domain Trust Discovery
GroupStorm-0501

Storm-0501 has used Windows native utility Nltest `nltest.exe` for discovery.

T1482
Domain Trust Discovery
GroupLotus Blossom

Lotus Blossom has used tools such as AdFind to make Active Directory queries.

T1482
Domain Trust Discovery
GroupChimera

Chimera has nltest /domain_trusts to identify domain trust relationships.

T1482
Domain Trust Discovery
GroupMirrorFace

MirrorFace has run `nltest.exe /domain_trusts` on compromised systems to discover domain relationships.

T1482
Domain Trust Discovery
GroupEarth Lusca

Earth Lusca has used Nltest to obtain information about domain controllers.

T1482
Domain Trust Discovery
GroupMagic Hound

Magic Hound has used a web shell to execute `nltest /trusted_domains` to identify trust relationships.

T1482
Domain Trust Discovery
GroupFIN8

FIN8 has retrieved a list of trusted domains by using nltest.exe /domain_trusts.

T1482
Domain Trust Discovery
MalwareTrickBot

TrickBot can gather information about domain trusts by utilizing Nltest.

T1482
Domain Trust Discovery
MalwarePikabot

Pikabot will gather information concerning the Windows Domain the victim machine is a member of during execution.

T1482
Domain Trust Discovery
MalwareDUSTTRAP

DUSTTRAP can identify Active Directory information and related items.

T1482
Domain Trust Discovery
MalwareBADHATCH

BADHATCH can use `nltest.exe /domain_trusts` to discover domain trust relationships on a compromised machine.

T1482
Domain Trust Discovery
MalwareIcedID

IcedID used Nltest during initial discovery.

T1482
Domain Trust Discovery
MalwareSocGholish

SocGholish can profile compromised systems to identify domain trust relationships.

T1482
Domain Trust Discovery
MalwareLatrodectus

Latrodectus can run `C:\Windows\System32\cmd.exe /c nltest /domain_trusts` to discover domain trusts.

T1482
Domain Trust Discovery
MalwareBazar

Bazar can use Nltest tools to obtain information about the domain.

T1482
Domain Trust Discovery
MalwareMgBot

MgBot includes modules for collecting information on local domain users and permissions.

T1482
Domain Trust Discovery
MalwareLAMEHUG

LAMEHUG can gather Active Directory domain information.

T1482
Domain Trust Discovery
MalwareQakBot

QakBot can run nltest /domain_trusts /all_trusts for domain trust discovery.

T1482
Domain Trust Discovery
ToolBloodHound

BloodHound has the ability to map domain trusts and identify misconfigurations for potential abuse.

T1482
Domain Trust Discovery
ToolPowerSploit

PowerSploit has modules such as Get-NetDomainTrust and Get-NetForestTrust to enumerate domain and forest trusts.

T1482
Domain Trust Discovery
ToolEmpire

Empire has modules for enumerating domain trusts.

T1482
Domain Trust Discovery
Tooldsquery

dsquery can be used to gather information on domain trusts with dsquery * -filter "(objectClass=trustedDomain)" -attr *.

T1482
Domain Trust Discovery
ToolPoshC2

PoshC2 has modules for enumerating domain trusts.

T1482
Domain Trust Discovery
ToolBrute Ratel C4

Brute Ratel C4 can use LDAP queries and `nltest /domain_trusts` for domain trust discovery.

T1482
Domain Trust Discovery
ToolNltest

Nltest may be used to enumerate trusted domains by using commands such as nltest /domain_trusts.

T1482
Domain Trust Discovery
ToolRubeus

Rubeus can gather information about domain trusts.

T1482
Domain Trust Discovery
ToolAdFind

AdFind can gather information about organizational units (OUs) and domain trusts from Active Directory.

T1484.001
Group Policy Modification
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors, including Storm-2603, modified group policy to enable ransomware distribution.

T1484.001
Group Policy Modification
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries had leveraged Group Policy Objects to distribute wiper malware to victim devices through a network share.

T1484.001
Group Policy Modification
Campaign2022 Ukraine Electric Power Attack

During the 2022 Ukraine Electric Power Attack, Sandworm Team leveraged Group Policy Objects (GPOs) to deploy and execute malware.

T1484.001
Group Policy Modification
GroupIndrik Spider

Indrik Spider has used Group Policy Objects to deploy batch scripts.

T1484.001
Group Policy Modification
GroupAPT41

APT41 used scheduled tasks created via Group Policy Objects (GPOs) to deploy ransomware.

T1484.001
Group Policy Modification
GroupStorm-0501

Storm-0501 distributed Group Policy Objects to tamper with security products.

T1484.001
Group Policy Modification
GroupCinnamon Tempest

Cinnamon Tempest has used Group Policy to deploy batch scripts for ransomware deployment.

T1484.001
Group Policy Modification
GroupVOID MANTICORE

VOID MANTICORE had utilized Group Policy logon scripts to distribute the malicious payloads to victim devices through the execution of a batch file.

T1484.001
Group Policy Modification
MalwarePrestige

Prestige has been deployed using the Default Domain Group Policy Object from an Active Directory Domain Controller.

T1484.001
Group Policy Modification
MalwareLockBit 3.0

LockBit 3.0 can enable options for propogation through Group Policy Objects.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.