ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1589.002
Email Addresses
GroupKimsuky

Kimsuky has collected valid email addresses including personal accounts that were subsequently used for spearphishing and other forms of social engineering.

T1589.002
Email Addresses
GroupEXOTIC LILY

EXOTIC LILY has gathered targeted individuals' e-mail addresses through open source research and website contact forms.

T1589.002
Email Addresses
GroupVolt Typhoon

Volt Typhoon has targeted the personal emails of key network and IT staff at victim organizations.

T1589.002
Email Addresses
GroupAPT32

APT32 has collected e-mail addresses for activists and bloggers in order to target them with spyware.

T1589.002
Email Addresses
GroupHAFNIUM

HAFNIUM has collected e-mail addresses for users they intended to target.

T1589.002
Email Addresses
GroupSandworm Team

Sandworm Team has obtained valid emails addresses while conducting research against target organizations that were subsequently used in spearphishing campaigns.

T1589.002
Email Addresses
GroupSaint Bear

Saint Bear gathered victim email information in advance of phishing operations for targeted attacks.

T1589.002
Email Addresses
GroupSilent Librarian

Silent Librarian has collected e-mail addresses from targeted organizations from open Internet searches.

T1589.002
Email Addresses
GroupTA551

TA551 has used spoofed company emails that were acquired from email clients on previously infected hosts to target other individuals.

T1589.002
Email Addresses
GroupLazarus Group

Lazarus Group collected email addresses belonging to various departments of a targeted organization which were used in follow-on phishing campaigns.

T1589.002
Email Addresses
GroupLAPSUS$

LAPSUS$ has gathered employee email addresses, including personal accounts, for social engineering and initial access efforts.

T1589.002
Email Addresses
GroupMoonstone Sleet

Moonstone Sleet gathered victim email address information for follow-on phishing activity.

T1589.002
Email Addresses
GroupHEXANE

HEXANE has targeted executives, human resources staff, and IT personnel for spearphishing.

T1589.002
Email Addresses
GroupMagic Hound

Magic Hound has identified high-value email accounts in academia, journalism, NGO's, foreign policy, and national security for targeting.

T1589.002
Email Addresses
ToolAADInternals

AADInternals can check for the existence of user email addresses using public Microsoft APIs.

T1589.003
Employee Names
GroupKimsuky

Kimsuky has collected victim employee name information.

T1589.003
Employee Names
GroupSandworm Team

Sandworm Team's research of potential victim organizations included the identification and collection of employee information.

T1589.003
Employee Names
GroupSilent Librarian

Silent Librarian has collected lists of names for individuals from targeted organizations.

T1590
Gather Victim Network Information
GroupIndrik Spider

Indrik Spider has downloaded tools, such as the Advanced Port Scanner utility and Lansweeper, to conduct internal reconnaissance of the victim network. Indrik Spider has also accessed the victim’s VMware VCenter, which had information about host configuration, clusters, etc.

T1590
Gather Victim Network Information
GroupVolt Typhoon

Volt Typhoon has conducted extensive pre-compromise reconnaissance to learn about the target organization’s network.

T1590
Gather Victim Network Information
GroupHAFNIUM

HAFNIUM gathered the fully qualified domain names (FQDNs) for targeted Exchange servers in the victim's environment.

T1590.001
Domain Properties
GroupSandworm Team

Sandworm Team conducted technical reconnaissance of the Parliament of Georgia's official internet domain prior to its 2019 attack.

T1590.001
Domain Properties
ToolAADInternals

AADInternals can gather information about a tenant’s domains using public Microsoft APIs.

T1590.004
Network Topology
CampaignAnthropic AI-orchestrated Campaign

During the Anthropic AI-orchestrated Campaign, the adversary used Claude Code to map a complete network topology of the target infrastructure.

T1590.004
Network Topology
GroupVolt Typhoon

Volt Typhoon has conducted extensive reconnaissance of victim networks including identifying network topologies.

T1590.004
Network Topology
GroupSalt Typhoon

Salt Typhoon has used configuration files from exploited network devices to help discover upstream and downstream network segments.

T1590.004
Network Topology
GroupMuddyWater

MuddyWater has mapped target networks; access to this information and more is then shared/sold to other Iran threat actors.

T1590.004
Network Topology
GroupFIN13

FIN13 has searched for infrastructure that can provide remote access to an environment for targeting efforts.

T1590.005
IP Addresses
GroupHAFNIUM

HAFNIUM has obtained IP addresses for publicly-accessible Exchange servers.

T1590.005
IP Addresses
GroupAndariel

Andariel has limited its watering hole attacks to specific IP address ranges.

T1590.005
IP Addresses
GroupMagic Hound

Magic Hound has captured the IP addresses of visitors to their phishing sites.

T1590.006
Network Security Appliances
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries obtained details on the configuration of the victim Fortinet perimeter device to include publicly disclosed details on an online forum used by criminal communities.

T1590.006
Network Security Appliances
GroupVolt Typhoon

Volt Typhoon has identified target network security measures as part of pre-compromise reconnaissance.

T1591
Gather Victim Org Information
CampaignOperation Dream Job

For Operation Dream Job, Lazarus Group gathered victim organization information to identify specific targets.

T1591
Gather Victim Org Information
CampaignOperation Digital Eye

During Operation Digital Eye, threat actors concealed malicious activity by using terms that aligned with the technological context of the targeted organization.

T1591
Gather Victim Org Information
GroupKimsuky

Kimsuky has collected victim organization information including but not limited to organization hierarchy, functions, press releases, and others. Kimsuky has also used large language models (LLMs) to gather information about potential targets of interest.

T1591
Gather Victim Org Information
GroupVolt Typhoon

Volt Typhoon has conducted extensive reconnaissance pre-compromise to gain information about the targeted organization.

T1591
Gather Victim Org Information
GroupFIN7

FIN7 has compiled a list of victims by filtering companies by revenue using Zoominfo, which is a service that provides business information.

T1591
Gather Victim Org Information
GroupMirrorFace

MirrorFace has placed specific content in phishing emails to target members of particular political parties.

T1591
Gather Victim Org Information
GroupAPT28

APT28 has used large language models (LLMs) to gather information about satellite capabilities.

T1591
Gather Victim Org Information
GroupLazarus Group

Lazarus Group has studied publicly available information about a targeted organization to tailor spearphishing efforts against specific departments and/or individuals.

T1591
Gather Victim Org Information
GroupMoonstone Sleet

Moonstone Sleet has gathered information on victim organizations through email and social media interaction.

T1591.001
Determine Physical Locations
GroupMagic Hound

Magic Hound has collected location information from visitors to their phishing sites.

T1591.002
Business Relationships
GroupDragonfly

Dragonfly has collected open source information to identify relationships between organizations for targeting purposes.

T1591.002
Business Relationships
GroupSandworm Team

In preparation for its attack against the 2018 Winter Olympics, Sandworm Team conducted online research of partner organizations listed on an official PyeongChang Olympics partnership site.

T1591.002
Business Relationships
GroupLAPSUS$

LAPSUS$ has gathered detailed knowledge of an organization's supply chain relationships.

T1591.004
Identify Roles
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group targeted specific individuals within an organization with tailored job vacancy announcements.

T1591.004
Identify Roles
GroupVolt Typhoon

Volt Typhoon has identified key network and IT staff members pre-compromise at targeted organizations.

T1591.004
Identify Roles
GroupFIN7

FIN7 has identified IT staff and employees who had higher levels of administrative rights.

T1591.004
Identify Roles
GroupLAPSUS$

LAPSUS$ has gathered detailed knowledge of team structures within a target organization.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.