Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1480.002 Mutual Exclusion |
MalwareREvil | REvil attempts to create a mutex using a hard-coded value to ensure that no other instances of itself are running on the host. |
| T1480.002 Mutual Exclusion |
MalwarePoisonIvy | PoisonIvy creates a mutex using either a custom or default value. |
| T1480.002 Mutual Exclusion |
MalwareSUNSPOT | SUNSPOT creates a mutex using the hard-coded value ` {12d61a41-4b74-7610-a4d8-3028d2f56395}` to ensure that only one instance of itself is running. |
| T1480.002 Mutual Exclusion |
MalwareGrimAgent | GrimAgent uses the last 64 bytes of the binary to compute a mutex name. If the generated name is invalid, it will default to the generic `mymutex`. |
| T1480.002 Mutual Exclusion |
MalwareSPAWNCHIMERA | SPAWNCHIMERA has fixed a buffer overflow vulnerability (CVE-2025-0282) by hooking the strncpy function and limiting the size to 256 to prevent other actors from leveraging the exploit. SPAWNCHIMERA has converted its process name to hexadecimal and verifies an added value which is triggered when the first byte of the source copied to the fixed strncpy function matches `0x04050203`. |
| T1480.002 Mutual Exclusion |
MalwareTroll Stealer | Troll Stealer creates a mutex during installation to prevent duplicate execution. |
| T1480.002 Mutual Exclusion |
MalwareQilin | Qilin can create a mutex to ensure only one instance is running. |
| T1482 Domain Trust Discovery |
CampaignC0015 | During C0015, the threat actors used the command `nltest /domain_trusts /all_trusts` to enumerate domain trusts. |
| T1482 Domain Trust Discovery |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used the `Get-AcceptedDomain` PowerShell cmdlet to enumerate accepted domains through an Exchange Management Shell. They also used AdFind to enumerate domains and to discover trust between federated domains. |
| T1482 Domain Trust Discovery |
CampaignLeviathan Australian Intrusions | Leviathan performed Active Directory enumeration of victim environments during Leviathan Australian Intrusions. |
| T1482 Domain Trust Discovery |
GroupBlackByte | BlackByte enumerated Active Directory information and trust relationships during operations. |
| T1482 Domain Trust Discovery |
GroupStorm-1811 | Storm-1811 has enumerated domain accounts and access during intrusions. |
| T1482 Domain Trust Discovery |
GroupAkira | Akira uses the built-in Nltest utility or tools such as AdFind to enumerate Active Directory trusts in victim environments. |
| T1482 Domain Trust Discovery |
GroupStorm-0501 | Storm-0501 has used Windows native utility Nltest `nltest.exe` for discovery. |
| T1482 Domain Trust Discovery |
GroupLotus Blossom | Lotus Blossom has used tools such as AdFind to make Active Directory queries. |
| T1482 Domain Trust Discovery |
GroupChimera | Chimera has |
| T1482 Domain Trust Discovery |
GroupMirrorFace | MirrorFace has run `nltest.exe /domain_trusts` on compromised systems to discover domain relationships. |
| T1482 Domain Trust Discovery |
GroupEarth Lusca | Earth Lusca has used Nltest to obtain information about domain controllers. |
| T1482 Domain Trust Discovery |
GroupMagic Hound | Magic Hound has used a web shell to execute `nltest /trusted_domains` to identify trust relationships. |
| T1482 Domain Trust Discovery |
GroupFIN8 | FIN8 has retrieved a list of trusted domains by using |
| T1482 Domain Trust Discovery |
MalwareTrickBot | TrickBot can gather information about domain trusts by utilizing Nltest. |
| T1482 Domain Trust Discovery |
MalwarePikabot | Pikabot will gather information concerning the Windows Domain the victim machine is a member of during execution. |
| T1482 Domain Trust Discovery |
MalwareDUSTTRAP | DUSTTRAP can identify Active Directory information and related items. |
| T1482 Domain Trust Discovery |
MalwareBADHATCH | BADHATCH can use `nltest.exe /domain_trusts` to discover domain trust relationships on a compromised machine. |
| T1482 Domain Trust Discovery |
MalwareIcedID | |
| T1482 Domain Trust Discovery |
MalwareSocGholish | SocGholish can profile compromised systems to identify domain trust relationships. |
| T1482 Domain Trust Discovery |
MalwareLatrodectus | Latrodectus can run `C:\Windows\System32\cmd.exe /c nltest /domain_trusts` to discover domain trusts. |
| T1482 Domain Trust Discovery |
MalwareBazar | Bazar can use Nltest tools to obtain information about the domain. |
| T1482 Domain Trust Discovery |
MalwareMgBot | MgBot includes modules for collecting information on local domain users and permissions. |
| T1482 Domain Trust Discovery |
MalwareLAMEHUG | LAMEHUG can gather Active Directory domain information. |
| T1482 Domain Trust Discovery |
MalwareQakBot | QakBot can run |
| T1482 Domain Trust Discovery |
ToolBloodHound | BloodHound has the ability to map domain trusts and identify misconfigurations for potential abuse. |
| T1482 Domain Trust Discovery |
ToolPowerSploit | PowerSploit has modules such as |
| T1482 Domain Trust Discovery |
ToolEmpire | Empire has modules for enumerating domain trusts. |
| T1482 Domain Trust Discovery |
Tooldsquery | dsquery can be used to gather information on domain trusts with |
| T1482 Domain Trust Discovery |
ToolPoshC2 | PoshC2 has modules for enumerating domain trusts. |
| T1482 Domain Trust Discovery |
ToolBrute Ratel C4 | Brute Ratel C4 can use LDAP queries and `nltest /domain_trusts` for domain trust discovery. |
| T1482 Domain Trust Discovery |
ToolNltest | Nltest may be used to enumerate trusted domains by using commands such as |
| T1482 Domain Trust Discovery |
ToolRubeus | Rubeus can gather information about domain trusts. |
| T1482 Domain Trust Discovery |
ToolAdFind | AdFind can gather information about organizational units (OUs) and domain trusts from Active Directory. |
| T1484.001 Group Policy Modification |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors, including Storm-2603, modified group policy to enable ransomware distribution. |
| T1484.001 Group Policy Modification |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries had leveraged Group Policy Objects to distribute wiper malware to victim devices through a network share. |
| T1484.001 Group Policy Modification |
Campaign2022 Ukraine Electric Power Attack | During the 2022 Ukraine Electric Power Attack, Sandworm Team leveraged Group Policy Objects (GPOs) to deploy and execute malware. |
| T1484.001 Group Policy Modification |
GroupIndrik Spider | Indrik Spider has used Group Policy Objects to deploy batch scripts. |
| T1484.001 Group Policy Modification |
GroupAPT41 | APT41 used scheduled tasks created via Group Policy Objects (GPOs) to deploy ransomware. |
| T1484.001 Group Policy Modification |
GroupStorm-0501 | Storm-0501 distributed Group Policy Objects to tamper with security products. |
| T1484.001 Group Policy Modification |
GroupCinnamon Tempest | Cinnamon Tempest has used Group Policy to deploy batch scripts for ransomware deployment. |
| T1484.001 Group Policy Modification |
GroupVOID MANTICORE | VOID MANTICORE had utilized Group Policy logon scripts to distribute the malicious payloads to victim devices through the execution of a batch file. |
| T1484.001 Group Policy Modification |
MalwarePrestige | Prestige has been deployed using the Default Domain Group Policy Object from an Active Directory Domain Controller. |
| T1484.001 Group Policy Modification |
MalwareLockBit 3.0 | LockBit 3.0 can enable options for propogation through Group Policy Objects. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.