ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

4628 examples

TechniqueUsed byProcedure example
T1071.004
DNS
GroupCobalt Group

Cobalt Group has used DNS tunneling for C2.

T1072
Software Deployment Tools
GroupAPT32

APT32 compromised McAfee ePO to move laterally by distributing malware as a software deployment task.

T1072
Software Deployment Tools
GroupSandworm Team

Sandworm Team has used the commercially available tool RemoteExec for agentless remote code execution.

T1072
Software Deployment Tools
GroupMustang Panda

Mustang Panda has leveraged legitimate software tools such as AntiVirus Agents, Security Services, and App Development tools to execute scripts and to side-load dlls.

T1072
Software Deployment Tools
GroupMedusa Group

Medusa Group has utilized software deployment and management solutions to deploy their encryption payload to include BigFix and PDQ Deploy.

T1072
Software Deployment Tools
GroupSilence

Silence has used RAdmin, a remote software tool used to remotely control workstations and ATMs.

T1072
Software Deployment Tools
GroupThreat Group-1314

Threat Group-1314 actors used a victim's endpoint management platform, Altiris, for lateral movement.

T1072
Software Deployment Tools
GroupVOID MANTICORE

VOID MANTICORE has leveraged legitimate built-in features of cloud-based management platforms to include mobile device management (MDM) and Remote Monitoring and Management (RMM) solutions. VOID MANTICORE has also initiated built-in remote wipe instructions using a privileged account within Microsoft Intune.

T1072
Software Deployment Tools
GroupShinyHunters

ShinyHunters has abused software deployment tools for lateral movement.

T1074
Data Staged
GroupVolt Typhoon

Volt Typhoon has staged collected data in password-protected archives.

T1074
Data Staged
GroupScattered Spider

Scattered Spider stages data in a centralized database prior to exfiltration.

T1074
Data Staged
GroupINC Ransom

INC Ransom has staged data on compromised hosts prior to exfiltration.

T1074
Data Staged
GroupWizard Spider

Wizard Spider has collected and staged credentials and network enumeration information, using the networkdll and psfin TrickBot modules.

T1074
Data Staged
GroupVOID MANTICORE

VOID MANTICORE has staged compressed files in specified locations prior to exfiltration over C2.

T1074.001
Local Data Staging
GroupIndrik Spider

Indrik Spider has stored collected data in a .tmp file.

T1074.001
Local Data Staging
GroupGALLIUM

GALLIUM compressed and staged files in multi-part archives in the Recycle Bin prior to exfiltration.

T1074.001
Local Data Staging
GroupAPT3

APT3 has been known to stage files for exfiltration in a single location.

T1074.001
Local Data Staging
GroupKimsuky

Kimsuky has staged collected data files under C:\Program Files\Common Files\System\Ole DB\. Kimsuky has also gathered data in structured directories prior to exfiltration under the %TEMP% environment variable.

T1074.001
Local Data Staging
GroupVolt Typhoon

Volt Typhoon has saved stolen files including the `ntds.dit` database and the `SYSTEM` and `SECURITY` Registry hives locally to the `C:\Windows\Temp\` directory.

T1074.001
Local Data Staging
GroupPatchwork

Patchwork copied all targeted files to a directory called index that was eventually uploaded to the C&C server.

T1074.001
Local Data Staging
GroupDragonfly

Dragonfly has created a directory named "out" in the user's %AppData% folder and copied files to it.

T1074.001
Local Data Staging
GroupmenuPass

menuPass stages data prior to exfiltration in multi-part archives, often saved in the Recycle Bin.

T1074.001
Local Data Staging
GroupMuddyWater

MuddyWater has stored a decoy PDF file within a victim's `%temp%` folder.

T1074.001
Local Data Staging
GroupStorm-1811

Storm-1811 has locally staged captured credentials for subsequent manual exfiltration.

T1074.001
Local Data Staging
GroupTeamTNT

TeamTNT has aggregated collected credentials in text files before exfiltrating.

T1074.001
Local Data Staging
GroupSidewinder

Sidewinder has collected stolen files in a temporary folder in preparation for exfiltration.

T1074.001
Local Data Staging
GroupMustang Panda

Mustang Panda has stored collected credential files in c:\windows\temp prior to exfiltration. Mustang Panda has also stored documents for exfiltration in a hidden folder on USB drives.

T1074.001
Local Data Staging
GroupAPT39

APT39 has utilized tools to aggregate data prior to exfiltration.

T1074.001
Local Data Staging
GroupUNC3886

UNC3886 has staged captured credentials in `var/log/ldapd<unique_keyword>.2.gz`.

T1074.001
Local Data Staging
GroupLeviathan

Leviathan has used C:\Windows\Debug and C:\Perflogs as staging directories.

T1074.001
Local Data Staging
GroupFIN5

FIN5 scripts save memory dump data into a specific directory on hosts in the victim environment.

T1074.001
Local Data Staging
GroupLotus Blossom

Lotus Blossom has locally staged compressed and archived data for follow-on exfiltration.

T1074.001
Local Data Staging
GroupChimera

Chimera has staged stolen data locally on compromised hosts.

T1074.001
Local Data Staging
GroupBackdoorDiplomacy

BackdoorDiplomacy has copied files of interest to the main drive's recycle bin.

T1074.001
Local Data Staging
GroupAgrius

Agrius has used the folder, C:\\windows\\temp\\s\\, to stage data for exfiltration.

T1074.001
Local Data Staging
GroupAPT28

APT28 has stored captured credential information in a file named pi.log.

T1074.001
Local Data Staging
GroupAPT5

APT5 has staged data on compromised systems prior to exfiltration often in `C:\Users\Public`.

T1074.001
Local Data Staging
GroupLazarus Group

Lazarus Group malware IndiaIndia saves information gathered about the victim to a file that is saved in the %TEMP% directory, then compressed, encrypted, and uploaded to a C2 server.

T1074.001
Local Data Staging
GroupWizard Spider

Wizard Spider has staged ZIP files in local directories such as, `C:\PerfLogs\1\` and `C:\User\1\` prior to exfiltration.

T1074.001
Local Data Staging
GroupWIRTE

WIRTE has staged collected documents of interest in `C:\Users\Public folder`.

T1074.001
Local Data Staging
GroupThreat Group-3390

Threat Group-3390 has locally staged encrypted archives for later exfiltration efforts.

T1074.001
Local Data Staging
GroupFIN13

FIN13 has utilized the following temporary folders on compromised Windows and Linux systems for their operations prior to exfiltration: `C:\Windows\Temp` and `/tmp`.

T1074.002
Remote Data Staging
GroupmenuPass

menuPass has staged data on remote MSP systems or other victim networks prior to exfiltration.

T1074.002
Remote Data Staging
GroupFIN6

FIN6 actors have compressed data from remote systems and moved it to another staging system before exfiltration.

T1074.002
Remote Data Staging
GroupSea Turtle

Sea Turtle staged collected email archives in the public web directory of a website that was accessible from the internet.

T1074.002
Remote Data Staging
GroupLeviathan

Leviathan has staged data remotely prior to exfiltration.

T1074.002
Remote Data Staging
GroupMoustachedBouncer

MoustachedBouncer has used plugins to save captured screenshots to `.\AActdata\` on an SMB share.

T1074.002
Remote Data Staging
GroupChimera

Chimera has staged stolen data on designated servers in the target environment.

T1074.002
Remote Data Staging
GroupMirrorFace

MirrorFace has gathered data and files of interest on a single victim machine.

T1074.002
Remote Data Staging
GroupToddyCat

ToddyCat manually transferred collected files to an exfiltration host using xcopy.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.