ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1591.004
Identify Roles
GroupHEXANE

HEXANE has identified executives, HR, and IT staff at victim organizations for further targeting.

T1592
Gather Victim Host Information
GroupVolt Typhoon

Volt Typhoon has conducted pre-compromise reconnaissance for victim host information.

T1592.002
Software
CampaignAnthropic AI-orchestrated Campaign

During the Anthropic AI-orchestrated Campaign, the adversary utilized Claude Code to catalog services and data on discovered endpoints.

T1592.002
Software
GroupSandworm Team

Sandworm Team has researched software code to enable supply-chain operations, most notably for the 2017 NotPetya attack. Sandworm Team also collected a list of computers using specific software as part of its targeting efforts.

T1592.002
Software
GroupAndariel

Andariel has inserted a malicious script within compromised websites to collect potential victim information such as browser type, system language, Flash Player version, and other data.

T1592.002
Software
GroupMagic Hound

Magic Hound has captured the user-agent strings from visitors to their phishing sites.

T1592.004
Client Configurations
CampaignAnthropic AI-orchestrated Campaign

During the Anthropic AI-orchestrated Campaign, the adversary leveraged Claude Code to gather details of high-value systems to include databases and workflow orchestration platforms.

T1592.004
Client Configurations
GroupHAFNIUM

HAFNIUM has interacted with Office 365 tenants to gather details regarding target's environments.

T1593
Search Open Websites/Domains
GroupVolt Typhoon

Volt Typhoon has conducted pre-compromise web searches for victim information.

T1593
Search Open Websites/Domains
GroupSandworm Team

Sandworm Team researched Ukraine's unique legal entity identifier (called an "EDRPOU" number), including running queries on the EDRPOU website, in preparation for the NotPetya attack. Sandworm Team has also researched third-party websites to help it craft credible spearphishing emails.

T1593
Search Open Websites/Domains
GroupMustang Panda

Mustang Panda has used open-source research to identify information about victims to use in targeting to include creating weaponized phishing lures and attachments.

T1593
Search Open Websites/Domains
GroupContagious Interview

Contagious Interview has utilized open-source indicator of compromise repositories to determine their exposure to include VirusTotal, and MalTrail.

T1593
Search Open Websites/Domains
GroupStar Blizzard

Star Blizzard has used open-source research to identify information about victims to use in targeting.

T1593
Search Open Websites/Domains
GroupAPT-C-36

APT-C-36 has gathered information on Colombian financial institutions, including Bancolombia, BBVA, Banco Caja Social, and Davivienda to craft phishing pages.

T1593.001
Social Media
CampaignOperation Dream Job

For Operation Dream Job, Lazarus Group used LinkedIn to identify and target employees within a chosen organization.

T1593.001
Social Media
GroupKimsuky

Kimsuky has used Twitter to monitor potential victims and to prepare targeted phishing e-mails.

T1593.001
Social Media
GroupEXOTIC LILY

EXOTIC LILY has copied data from social media sites to impersonate targeted individuals.

T1593.001
Social Media
GroupContagious Interview

Contagious Interview had identified and solicited victims through social media such as LinkedIn, X, and Telegram.

T1593.002
Search Engines
CampaignAPT41 DUST

APT41 DUST involved use of search engines to research victim servers.

T1593.002
Search Engines
GroupKimsuky

Kimsuky has searched for vulnerabilities, tools, and geopolitical trends on Google to target victims.

T1593.003
Code Repositories
GroupHAFNIUM

HAFNIUM has discovered leaked corporate credentials on public repositories including GitHub.

T1593.003
Code Repositories
GroupContagious Interview

Contagious Interview had identified and solicited victims through code repositories such as GitHub.

T1593.003
Code Repositories
GroupLAPSUS$

LAPSUS$ has searched public code repositories for exposed credentials.

T1593.003
Code Repositories
MalwareShai-Hulud

Shai-Hulud has the ability to search open sites and code repositories for compromised credentials. Shai-Hulud has discovered packages associated with compromised accounts. Shai-Hulud has also searched code repositories for other compromised repositories that include predefined parameters or markers to include “Second Coming” combined with an 18-character alphanumeric string.

T1593.003
Code Repositories
GroupShinyHunters

ShinyHunters has searched through target companies’ GitHub repositories for login credentials or API keys.

T1594
Search Victim-Owned Websites
CampaignCutting Edge

During Cutting Edge, threat actors peformed reconnaissance of victims' internal websites via proxied connections.

T1594
Search Victim-Owned Websites
CampaignAPT41 DUST

APT41 DUST involved access of external victim websites for target development.

T1594
Search Victim-Owned Websites
CampaignLeviathan Australian Intrusions

Leviathan enumerated compromised web application resources to identify additional endpoints and resources linkd to the website for follow-on access during Leviathan Australian Intrusions.

T1594
Search Victim-Owned Websites
GroupKimsuky

Kimsuky has searched for information on the target company's website.

T1594
Search Victim-Owned Websites
GroupEXOTIC LILY

EXOTIC LILY has used contact forms on victim websites to generate phishing e-mails.

T1594
Search Victim-Owned Websites
GroupVolt Typhoon

Volt Typhoon has conducted pre-compromise reconnaissance on victim-owned sites.

T1594
Search Victim-Owned Websites
GroupSandworm Team

Sandworm Team has conducted research against potential victim websites as part of its operational planning.

T1594
Search Victim-Owned Websites
GroupSilent Librarian

Silent Librarian has searched victim's websites to identify the interests and academic areas of targeted individuals and to scrape source code, branding, and organizational contact information for phishing pages.

T1594
Search Victim-Owned Websites
GroupTA578

TA578 has filled out contact forms on victims' websites to direct them to adversary-controlled URLs.

T1595
Active Scanning
CampaignTriton Safety Instrumented System Attack

In the Triton Safety Instrumented System Attack, TEMP.Veles engaged in network reconnaissance against targets of interest.

T1595.001
Scanning IP Blocks
CampaignAnthropic AI-orchestrated Campaign

During the Anthropic AI-orchestrated Campaign, the adversary used Claude Code to scan infrastructure across IP ranges associated with the target organization.

T1595.001
Scanning IP Blocks
GroupTeamTNT

TeamTNT has scanned specific lists of target IP addresses.

T1595.001
Scanning IP Blocks
GroupEmber Bear

Ember Bear has targeted IP ranges for vulnerability scanning related to government and critical infrastructure organizations.

T1595.002
Vulnerability Scanning
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors scanned for SharePoint servers vulnerable to CVE-2025-53770.

T1595.002
Vulnerability Scanning
CampaignCutting Edge

During Cutting Edge, threat actors used the publicly available Interactsh tool to identify Ivanti Connect Secure VPNs vulnerable to CVE-2024-21893.

T1595.002
Vulnerability Scanning
CampaignAnthropic AI-orchestrated Campaign

During the Anthropic AI-orchestrated Campaign, the adversary used Claude Code to scan target infrastructure to identify potential vulnerabilities and to enumerate services and endpoints.

T1595.002
Vulnerability Scanning
GroupAPT41

APT41 used the Acunetix SQL injection vulnerability scanner in target reconnaissance operations, as well as the JexBoss tool to identify vulnerabilities in Java applications.

T1595.002
Vulnerability Scanning
GroupDragonfly

Dragonfly has scanned targeted systems for vulnerable Citrix and Microsoft Exchange services.

T1595.002
Vulnerability Scanning
GroupTeamTNT

TeamTNT has scanned for vulnerabilities in IoT devices and other related resources such as the Docker API.

T1595.002
Vulnerability Scanning
GroupSandworm Team

Sandworm Team has scanned network infrastructure for vulnerabilities as part of its operational planning.

T1595.002
Vulnerability Scanning
GroupAquatic Panda

Aquatic Panda has used publicly accessible DNS logging services to identify servers vulnerable to Log4j (CVE 2021-44228).

T1595.002
Vulnerability Scanning
GroupLeviathan

Leviathan has conducted reconnaissance against target networks of interest looking for vulnerable, end-of-life, or no longer maintainted devices against which to rapidly deploy exploits.

T1595.002
Vulnerability Scanning
GroupWinter Vivern

Winter Vivern has used remotely-hosted instances of the Acunetix vulnerability scanner.

T1595.002
Vulnerability Scanning
GroupAPT29

APT29 has conducted widespread scanning of target environments to identify vulnerabilities for exploit.

T1595.002
Vulnerability Scanning
GroupEmber Bear

Ember Bear has used publicly available tools such as MASSCAN and Acunetix for vulnerability scanning of public-facing infrastructure.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.