Real-world descriptions of how a group, tool or campaign used a technique.
1146 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1021.007 Cloud Services |
CampaignC0027 | During C0027, Scattered Spider used compromised Azure credentials for credential theft activity and lateral movement to on-premises systems. |
| T1027 Obfuscated Files or Information |
Campaign3CX Supply Chain Attack | During the 3CX Supply Chain Attack, AppleJeus payloads use AES-256 GCM cipher to encrypt data to include ICONICSTEALER and VEILEDSIGNAL. |
| T1027 Obfuscated Files or Information |
CampaignC0015 | During C0015, the threat actors used Base64-encoded strings. |
| T1027 Obfuscated Files or Information |
Campaign2016 Ukraine Electric Power Attack | During the 2016 Ukraine Electric Power Attack, Sandworm Team used heavily obfuscated code with Industroyer in its Windows Notepad backdoor. |
| T1027 Obfuscated Files or Information |
CampaignC0017 | During C0017, APT41 broke malicious binaries, including DEADEYE and KEYPLUG, into multiple sections on disk to evade detection. |
| T1027.002 Software Packing |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group packed malicious .db files with Themida to evade detection. |
| T1027.002 Software Packing |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors UPX-packed malicous payloads including 4L4MD4R ransomware. |
| T1027.002 Software Packing |
CampaignOperation Dust Storm | For Operation Dust Storm, the threat actors used UPX to pack some payloads. |
| T1027.002 Software Packing |
CampaignOperation Spalax | For Operation Spalax, the threat actors used a variety of packers, including CyaX, to obfuscate malicious executables. |
| T1027.002 Software Packing |
Campaign2016 Ukraine Electric Power Attack | During the 2016 Ukraine Electric Power Attack, Sandworm Team used UPX to pack a copy of Mimikatz. |
| T1027.002 Software Packing |
CampaignNight Dragon | During Night Dragon, threat actors used software packing in its tools. |
| T1027.002 Software Packing |
CampaignC0017 | During C0017, APT41 used VMProtect to slow the reverse engineering of malicious binaries. |
| T1027.003 Steganography |
CampaignOperation Spalax | For Operation Spalax, the threat actors used packers that read pixel data from images contained in PE files' resource sections and build the next layer of execution from the data. |
| T1027.003 Steganography |
CampaignOperation Ghost | During Operation Ghost, APT29 used steganography to hide payloads inside valid images. |
| T1027.005 Indicator Removal from Tools |
CampaignTriton Safety Instrumented System Attack | In the Triton Safety Instrumented System Attack, TEMP.Veles modified files based on the open-source project cryptcat in an apparent attempt to decrease anti-virus detection rates. |
| T1027.005 Indicator Removal from Tools |
CampaignOperation Wocao | During Operation Wocao, threat actors edited variable names within the Impacket suite to avoid automated detection. |
| T1027.009 Embedded Payloads |
Campaign3CX Supply Chain Attack | During the 3CX Supply Chain Attack, AppleJeus uses embedded .dll as apart of a chained delivery mechanism to invoke the COM class factory. |
| T1027.009 Embedded Payloads |
CampaignC0021 | For C0021, the threat actors embedded a base64-encoded payload within a LNK file. |
| T1027.010 Command Obfuscation |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors executed Base64-encoded PowerShell commands. |
| T1027.010 Command Obfuscation |
CampaignFrankenstein | During Frankenstein, the threat actors ran encoded commands from the command line. |
| T1027.010 Command Obfuscation |
CampaignC0018 | During C0018, the threat actors used Base64 to encode their PowerShell scripts. |
| T1027.010 Command Obfuscation |
CampaignC0021 | During C0021, the threat actors used encoded PowerShell commands. |
| T1027.010 Command Obfuscation |
CampaignOperation CuckooBees | During Operation CuckooBees, the threat actors executed an encoded VBScript file. |
| T1027.010 Command Obfuscation |
CampaignOperation Wocao | During Operation Wocao, threat actors executed PowerShell commands which were encoded or compressed using Base64, zlib, and XOR. |
| T1027.011 Fileless Storage |
CampaignOperation CuckooBees | During Operation CuckooBees, the threat actors stroed payloads in Windows CLFS (Common Log File System) transactional logs. |
| T1027.011 Fileless Storage |
CampaignQuad7 Activity | Quad7 Activity has infected victim network devices by storing artifacts in the |
| T1027.013 Encrypted/Encoded File |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group encrypted malware such as DRATzarus with XOR and DLL files with base64. |
| T1027.013 Encrypted/Encoded File |
CampaignRedDelta Modified PlugX Infection Chain Operations | Mustang Panda stored installation payloads as encrypted files in hidden folders during RedDelta Modified PlugX Infection Chain Operations. |
| T1027.013 Encrypted/Encoded File |
CampaignRedPenguin | During RedPenguin, UNC3886 generated Base64-encoded files in the FreeBSD shell environment of targeted Juniper devices. |
| T1027.013 Encrypted/Encoded File |
CampaignOperation Honeybee | During Operation Honeybee, the threat actors used Base64 to encode files with a custom key. |
| T1027.013 Encrypted/Encoded File |
CampaignOperation Dust Storm | During Operation Dust Storm, the threat actors encoded some payloads with a single-byte XOR, both skipping the key itself and zeroing in an attempt to avoid exposing the key; other payloads were Base64-encoded. |
| T1027.013 Encrypted/Encoded File |
CampaignOperation Spalax | For Operation Spalax, the threat actors used XOR-encrypted payloads. |
| T1027.013 Encrypted/Encoded File |
Campaign3CX Supply Chain Attack | During the 3CX Supply Chain Attack, AppleJeus encrypts its dynamic library files (.dll) using RC4, and when loaded only decrypts specific portions of the file using the key `3jB(2bsG#@c7`. |
| T1027.013 Encrypted/Encoded File |
CampaignCutting Edge | During Cutting Edge, threat actors used a Base64-encoded Python script to write a patched version of the Ivanti Connect Secure `dsls` binary. |
| T1027.013 Encrypted/Encoded File |
CampaignShadowRay | During ShadowRay, threat actors used Base64-encrypted Python code to evade detection. |
| T1027.013 Encrypted/Encoded File |
CampaignOuter Space | During Outer Space, OilRig deployed VBS droppers with obfuscated strings. |
| T1027.013 Encrypted/Encoded File |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries utilized a Base64-encoded ZIP archive to prevent content analysis. |
| T1027.013 Encrypted/Encoded File |
CampaignAPT41 DUST | APT41 DUST used encrypted payloads decrypted and executed in memory. |
| T1027.013 Encrypted/Encoded File |
CampaignNight Dragon | During Night Dragon, threat actors used a DLL that included an XOR-encoded section. |
| T1030 Data Transfer Size Limits |
CampaignC0015 | During C0015, the threat actors limited Rclone's bandwidth setting during exfiltration. |
| T1030 Data Transfer Size Limits |
CampaignC0026 | During C0026, the threat actors split encrypted archives containing stolen files and information into 3MB parts prior to exfiltration. |
| T1033 System Owner/User Discovery |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors executed `whoami` on victim machines to enumerate user context and validate privilege levels. |
| T1033 System Owner/User Discovery |
CampaignFrankenstein | During Frankenstein, the threat actors used Empire to enumerate hosts and gather username, machine name, and administrative permissions information. |
| T1033 System Owner/User Discovery |
CampaignC0018 | During C0018, the threat actors collected `whoami` information via PowerShell scripts. |
| T1033 System Owner/User Discovery |
CampaignOperation Digital Eye | During Operation Digital Eye, threat actors used `GetUserInfo` to identify current user information. |
| T1033 System Owner/User Discovery |
CampaignOperation CuckooBees | During Operation CuckooBees, the threat actors used the `query user` and `whoami` commands as part of their advanced reconnaissance. |
| T1033 System Owner/User Discovery |
CampaignNight Dragon | During Night Dragon, threat actors used password cracking and pass-the-hash tools to discover usernames and passwords. |
| T1033 System Owner/User Discovery |
CampaignOperation Wocao | During Operation Wocao, threat actors enumerated sessions and users on a remote host, and identified privileged users logged into a targeted system. |
| T1033 System Owner/User Discovery |
CampaignC0017 | During C0017, APT41 used `whoami` to gather information from victim machines. |
| T1036 Masquerading |
CampaignKV Botnet Activity | KV Botnet Activity involves changing process filename to |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.