Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1591.004 Identify Roles |
GroupHEXANE | HEXANE has identified executives, HR, and IT staff at victim organizations for further targeting. |
| T1592 Gather Victim Host Information |
GroupVolt Typhoon | Volt Typhoon has conducted pre-compromise reconnaissance for victim host information. |
| T1592.002 Software |
CampaignAnthropic AI-orchestrated Campaign | During the Anthropic AI-orchestrated Campaign, the adversary utilized Claude Code to catalog services and data on discovered endpoints. |
| T1592.002 Software |
GroupSandworm Team | Sandworm Team has researched software code to enable supply-chain operations, most notably for the 2017 NotPetya attack. Sandworm Team also collected a list of computers using specific software as part of its targeting efforts. |
| T1592.002 Software |
GroupAndariel | Andariel has inserted a malicious script within compromised websites to collect potential victim information such as browser type, system language, Flash Player version, and other data. |
| T1592.002 Software |
GroupMagic Hound | Magic Hound has captured the user-agent strings from visitors to their phishing sites. |
| T1592.004 Client Configurations |
CampaignAnthropic AI-orchestrated Campaign | During the Anthropic AI-orchestrated Campaign, the adversary leveraged Claude Code to gather details of high-value systems to include databases and workflow orchestration platforms. |
| T1592.004 Client Configurations |
GroupHAFNIUM | HAFNIUM has interacted with Office 365 tenants to gather details regarding target's environments. |
| T1593 Search Open Websites/Domains |
GroupVolt Typhoon | Volt Typhoon has conducted pre-compromise web searches for victim information. |
| T1593 Search Open Websites/Domains |
GroupSandworm Team | Sandworm Team researched Ukraine's unique legal entity identifier (called an "EDRPOU" number), including running queries on the EDRPOU website, in preparation for the NotPetya attack. Sandworm Team has also researched third-party websites to help it craft credible spearphishing emails. |
| T1593 Search Open Websites/Domains |
GroupMustang Panda | Mustang Panda has used open-source research to identify information about victims to use in targeting to include creating weaponized phishing lures and attachments. |
| T1593 Search Open Websites/Domains |
GroupContagious Interview | Contagious Interview has utilized open-source indicator of compromise repositories to determine their exposure to include VirusTotal, and MalTrail. |
| T1593 Search Open Websites/Domains |
GroupStar Blizzard | Star Blizzard has used open-source research to identify information about victims to use in targeting. |
| T1593 Search Open Websites/Domains |
GroupAPT-C-36 | APT-C-36 has gathered information on Colombian financial institutions, including Bancolombia, BBVA, Banco Caja Social, and Davivienda to craft phishing pages. |
| T1593.001 Social Media |
CampaignOperation Dream Job | For Operation Dream Job, Lazarus Group used LinkedIn to identify and target employees within a chosen organization. |
| T1593.001 Social Media |
GroupKimsuky | Kimsuky has used Twitter to monitor potential victims and to prepare targeted phishing e-mails. |
| T1593.001 Social Media |
GroupEXOTIC LILY | EXOTIC LILY has copied data from social media sites to impersonate targeted individuals. |
| T1593.001 Social Media |
GroupContagious Interview | Contagious Interview had identified and solicited victims through social media such as LinkedIn, X, and Telegram. PaloAlto ContagiousInterview BeaverTail InvisibleFerret November 2023PaloAlto Unit42 ContagiousInterview BeaverTail InvisibileFerret October 2024SecurityScorecard Contagious Interview FamousChollima October 2024SecurityScorecard Contagious Interview October 2024Sekoia ClickFake 2025Validin Contagious Interview North Korea ClickFix January 2025 |
| T1593.002 Search Engines |
CampaignAPT41 DUST | APT41 DUST involved use of search engines to research victim servers. |
| T1593.002 Search Engines |
GroupKimsuky | Kimsuky has searched for vulnerabilities, tools, and geopolitical trends on Google to target victims. |
| T1593.003 Code Repositories |
GroupHAFNIUM | HAFNIUM has discovered leaked corporate credentials on public repositories including GitHub. |
| T1593.003 Code Repositories |
GroupContagious Interview | Contagious Interview had identified and solicited victims through code repositories such as GitHub. |
| T1593.003 Code Repositories |
GroupLAPSUS$ | LAPSUS$ has searched public code repositories for exposed credentials. |
| T1593.003 Code Repositories |
MalwareShai-Hulud | Shai-Hulud has the ability to search open sites and code repositories for compromised credentials. Shai-Hulud has discovered packages associated with compromised accounts. Shai-Hulud has also searched code repositories for other compromised repositories that include predefined parameters or markers to include “Second Coming” combined with an 18-character alphanumeric string. |
| T1593.003 Code Repositories |
GroupShinyHunters | ShinyHunters has searched through target companies’ GitHub repositories for login credentials or API keys. |
| T1594 Search Victim-Owned Websites |
CampaignCutting Edge | During Cutting Edge, threat actors peformed reconnaissance of victims' internal websites via proxied connections. |
| T1594 Search Victim-Owned Websites |
CampaignAPT41 DUST | APT41 DUST involved access of external victim websites for target development. |
| T1594 Search Victim-Owned Websites |
CampaignLeviathan Australian Intrusions | Leviathan enumerated compromised web application resources to identify additional endpoints and resources linkd to the website for follow-on access during Leviathan Australian Intrusions. |
| T1594 Search Victim-Owned Websites |
GroupKimsuky | Kimsuky has searched for information on the target company's website. |
| T1594 Search Victim-Owned Websites |
GroupEXOTIC LILY | EXOTIC LILY has used contact forms on victim websites to generate phishing e-mails. |
| T1594 Search Victim-Owned Websites |
GroupVolt Typhoon | Volt Typhoon has conducted pre-compromise reconnaissance on victim-owned sites. |
| T1594 Search Victim-Owned Websites |
GroupSandworm Team | Sandworm Team has conducted research against potential victim websites as part of its operational planning. |
| T1594 Search Victim-Owned Websites |
GroupSilent Librarian | Silent Librarian has searched victim's websites to identify the interests and academic areas of targeted individuals and to scrape source code, branding, and organizational contact information for phishing pages. |
| T1594 Search Victim-Owned Websites |
GroupTA578 | TA578 has filled out contact forms on victims' websites to direct them to adversary-controlled URLs. |
| T1595 Active Scanning |
CampaignTriton Safety Instrumented System Attack | In the Triton Safety Instrumented System Attack, TEMP.Veles engaged in network reconnaissance against targets of interest. |
| T1595.001 Scanning IP Blocks |
CampaignAnthropic AI-orchestrated Campaign | During the Anthropic AI-orchestrated Campaign, the adversary used Claude Code to scan infrastructure across IP ranges associated with the target organization. |
| T1595.001 Scanning IP Blocks |
GroupTeamTNT | TeamTNT has scanned specific lists of target IP addresses. |
| T1595.001 Scanning IP Blocks |
GroupEmber Bear | Ember Bear has targeted IP ranges for vulnerability scanning related to government and critical infrastructure organizations. |
| T1595.002 Vulnerability Scanning |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors scanned for SharePoint servers vulnerable to CVE-2025-53770. |
| T1595.002 Vulnerability Scanning |
CampaignCutting Edge | During Cutting Edge, threat actors used the publicly available Interactsh tool to identify Ivanti Connect Secure VPNs vulnerable to CVE-2024-21893. |
| T1595.002 Vulnerability Scanning |
CampaignAnthropic AI-orchestrated Campaign | During the Anthropic AI-orchestrated Campaign, the adversary used Claude Code to scan target infrastructure to identify potential vulnerabilities and to enumerate services and endpoints. |
| T1595.002 Vulnerability Scanning |
GroupAPT41 | APT41 used the Acunetix SQL injection vulnerability scanner in target reconnaissance operations, as well as the JexBoss tool to identify vulnerabilities in Java applications. |
| T1595.002 Vulnerability Scanning |
GroupDragonfly | Dragonfly has scanned targeted systems for vulnerable Citrix and Microsoft Exchange services. |
| T1595.002 Vulnerability Scanning |
GroupTeamTNT | TeamTNT has scanned for vulnerabilities in IoT devices and other related resources such as the Docker API. |
| T1595.002 Vulnerability Scanning |
GroupSandworm Team | Sandworm Team has scanned network infrastructure for vulnerabilities as part of its operational planning. |
| T1595.002 Vulnerability Scanning |
GroupAquatic Panda | Aquatic Panda has used publicly accessible DNS logging services to identify servers vulnerable to Log4j (CVE 2021-44228). |
| T1595.002 Vulnerability Scanning |
GroupLeviathan | Leviathan has conducted reconnaissance against target networks of interest looking for vulnerable, end-of-life, or no longer maintainted devices against which to rapidly deploy exploits. |
| T1595.002 Vulnerability Scanning |
GroupWinter Vivern | Winter Vivern has used remotely-hosted instances of the Acunetix vulnerability scanner. |
| T1595.002 Vulnerability Scanning |
GroupAPT29 | APT29 has conducted widespread scanning of target environments to identify vulnerabilities for exploit. |
| T1595.002 Vulnerability Scanning |
GroupEmber Bear | Ember Bear has used publicly available tools such as MASSCAN and Acunetix for vulnerability scanning of public-facing infrastructure. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.