ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1588.002
Tool
CampaignC0032

During the C0032 campaign, TEMP.Veles obtained and used tools such as Mimikatz and PsExec.

T1588.002
Tool
CampaignSPACEHOP Activity

SPACEHOP Activity leverages a C2 framework sourced from a publicly-available Github repository for administration of relay nodes.

T1588.002
Tool
CampaignOperation AkaiRyū

During Operation AkaiRyū, MirrorFace deployed multiple publicly available tools including PuTTY, FRP, and Rubeus.

T1588.002
Tool
CampaignFunnyDream

For FunnyDream, the threat actors used a modified version of the open source PcShare remote administration tool.

T1588.002
Tool
CampaignOperation CuckooBees

For Operation CuckooBees, the threat actors obtained publicly-available JSP code that was used to deploy a webshell onto a compromised server.

T1588.002
Tool
CampaignSalesforce Data Exfiltration

During Salesforce Data Exfiltration, threat actors initially relied on the legitimate Salesforce Data Loader app for data exfiltration.

T1588.002
Tool
CampaignC0010

For C0010, UNC3890 actors obtained multiple publicly-available tools, including METASPLOIT, UNICORN, and NorthStar C2.

T1588.002
Tool
CampaignNight Dragon

During Night Dragon, threat actors obtained and used tools such as gsecdump.

T1588.002
Tool
CampaignOperation Wocao

For Operation Wocao, the threat actors obtained a variety of open source tools, including JexBoss, KeeThief, and BloodHound.

T1588.002
Tool
CampaignC0017

For C0017, APT41 obtained publicly available tools such as YSoSerial.NET, ConfuserEx, and BadPotato.

T1588.002
Tool
CampaignC0027

During C0027, Scattered Spider obtained and used multiple tools including the LINpeas privilege escalation utility, aws_consoler, rsocx reverse proxy, Level RMM tool, and RustScan port scanner.

T1588.002
Tool
CampaignCostaRicto

During CostaRicto, the threat actors obtained open source tools to use in their operations.

T1588.002
Tool
GroupAPT38

APT38 has obtained and used open-source tools such as Mimikatz.

T1588.002
Tool
GroupGALLIUM

GALLIUM has used a variety of widely-available tools, which in some cases they modified to add functionality and/or subvert antimalware solutions.

T1588.002
Tool
GroupKimsuky

Kimsuky has obtained and used tools such as Nirsoft WebBrowserPassVIew, Mimikatz, and PsExec.

T1588.002
Tool
GroupVolt Typhoon

Volt Typhoon has used legitimate network and forensic tools and customized versions of open-source tools for C2.

T1588.002
Tool
GroupPatchwork

Patchwork has obtained and used open-source tools such as QuasarRAT.

T1588.002
Tool
GroupAPT41

APT41 has obtained and used tools such as Mimikatz, pwdump, PowerSploit, and Windows Credential Editor.

T1588.002
Tool
GroupSalt Typhoon

Salt Typhoon has used publicly available tooling to exploit vulnerabilities.

T1588.002
Tool
GroupDragonfly

Dragonfly has obtained and used tools such as Mimikatz, CrackMapExec, and PsExec.

T1588.002
Tool
GroupGorgon Group

Gorgon Group has obtained and used tools such as QuasarRAT and Remcos.

T1588.002
Tool
GroupmenuPass

menuPass has used and modified open-source tools like Impacket, Mimikatz, and pwdump.

T1588.002
Tool
GroupAPT32

APT32 has obtained and used tools such as Mimikatz and Cobalt Strike, and a variety of other open-source tools from GitHub.

T1588.002
Tool
GroupMuddyWater

MuddyWater has used legitimate tools ConnectWise, RemoteUtilities, and SimpleHelp to gain access to the target environment.

T1588.002
Tool
GroupFIN6

FIN6 has obtained and used tools such as Mimikatz, Cobalt Strike, and AdFind.

T1588.002
Tool
GroupGamaredon Group

Gamaredon Group has used various legitimate tools, such as `mshta.exe` and Reg, and services during operations.

T1588.002
Tool
GroupStorm-1811

Storm-1811 acquired various legitimate and malicious tools, such as RMM software and commodity malware packages, for operations.

T1588.002
Tool
GroupLeafminer

Leafminer has obtained and used tools such as LaZagne, Mimikatz, PsExec, and MailSniper.

T1588.002
Tool
GroupFIN7

FIN7 has utilized a variety of tools such as Cobalt Strike, PowerSploit, and the remote management tool, Atera for targeting efforts.

T1588.002
Tool
GroupSandworm Team

Sandworm Team has acquired open-source tools for their operations, including Invoke-PSImage, which was used to establish an encrypted channel from a compromised host to Sandworm Team's C2 server in preparation for the 2018 Winter Olympics attack, as well as Impacket and RemoteExec, which were used in their 2022 Prestige operations. Additionally, Sandworm Team has used Empire, Cobalt Strike and PoshC2.

T1588.002
Tool
GroupMustang Panda

Mustang Panda has obtained and leveraged publicly-available tools for intrusion activities.

T1588.002
Tool
GroupScattered Spider

Scattered Spider has obtained tools for use throughout the attack lifecycle to include remote access software, protocol tunneling and proxy tools, exploitation frameworks, and reconnaissance tools.

T1588.002
Tool
GroupAPT39

APT39 has modified and used customized versions of publicly-available tools like PLINK and Mimikatz.

T1588.002
Tool
GroupContagious Interview

Contagious Interview has used remote management and monitoring software such as “AnyDesk”.

T1588.002
Tool
GroupTA2541

TA2541 has used commodity remote access tools.

T1588.002
Tool
GroupMoses Staff

Moses Staff has used the commercial tool DiskCryptor.

T1588.002
Tool
GroupOilRig

OilRig has made use of the publicly available tools including Plink and Mimikatz.

T1588.002
Tool
GroupCarbanak

Carbanak has obtained and used open-source tools such as PsExec and Mimikatz.

T1588.002
Tool
GroupSea Turtle

Sea Turtle has used tools such as Adminer during intrusions.

T1588.002
Tool
GroupPOLONIUM

POLONIUM has obtained and used tools such as AirVPN and plink in their operations.

T1588.002
Tool
GroupAquatic Panda

Aquatic Panda has acquired and used Cobalt Strike in its operations.

T1588.002
Tool
GroupAoqin Dragon

Aoqin Dragon obtained the Heyoka open source exfiltration tool and subsequently modified it for their operations.

T1588.002
Tool
GroupFerocious Kitten

Ferocious Kitten has obtained open source tools for its operations, including JsonCPP and Psiphon.

T1588.002
Tool
GroupKe3chang

Ke3chang has obtained and used tools such as Mimikatz.

T1588.002
Tool
GroupAPT1

APT1 has used various open-source tools for privilege escalation purposes.

T1588.002
Tool
GroupDarkHydrus

DarkHydrus has obtained and used tools such as Mimikatz, Empire, and Cobalt Strike.

T1588.002
Tool
GroupBlackTech

BlackTech has obtained and used tools such as Putty, SNScan, and PsExec for its operations.

T1588.002
Tool
GroupBlue Mockingbird

Blue Mockingbird has obtained and used tools such as Mimikatz.

T1588.002
Tool
GroupTurla

Turla has obtained and customized publicly-available tools like Mimikatz.

T1588.002
Tool
GroupTA505

TA505 has used a variety of tools in their operations, including AdFind, BloodHound, Mimikatz, and PowerSploit.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.