Real-world descriptions of how a group, tool or campaign used a technique.
4628 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1071.004 DNS |
GroupCobalt Group | Cobalt Group has used DNS tunneling for C2. |
| T1072 Software Deployment Tools |
GroupAPT32 | APT32 compromised McAfee ePO to move laterally by distributing malware as a software deployment task. |
| T1072 Software Deployment Tools |
GroupSandworm Team | Sandworm Team has used the commercially available tool RemoteExec for agentless remote code execution. |
| T1072 Software Deployment Tools |
GroupMustang Panda | Mustang Panda has leveraged legitimate software tools such as AntiVirus Agents, Security Services, and App Development tools to execute scripts and to side-load dlls. |
| T1072 Software Deployment Tools |
GroupMedusa Group | Medusa Group has utilized software deployment and management solutions to deploy their encryption payload to include BigFix and PDQ Deploy. |
| T1072 Software Deployment Tools |
GroupSilence | Silence has used RAdmin, a remote software tool used to remotely control workstations and ATMs. |
| T1072 Software Deployment Tools |
GroupThreat Group-1314 | Threat Group-1314 actors used a victim's endpoint management platform, Altiris, for lateral movement. |
| T1072 Software Deployment Tools |
GroupVOID MANTICORE | VOID MANTICORE has leveraged legitimate built-in features of cloud-based management platforms to include mobile device management (MDM) and Remote Monitoring and Management (RMM) solutions. VOID MANTICORE has also initiated built-in remote wipe instructions using a privileged account within Microsoft Intune. |
| T1072 Software Deployment Tools |
GroupShinyHunters | ShinyHunters has abused software deployment tools for lateral movement. |
| T1074 Data Staged |
GroupVolt Typhoon | Volt Typhoon has staged collected data in password-protected archives. |
| T1074 Data Staged |
GroupScattered Spider | Scattered Spider stages data in a centralized database prior to exfiltration. |
| T1074 Data Staged |
GroupINC Ransom | INC Ransom has staged data on compromised hosts prior to exfiltration. |
| T1074 Data Staged |
GroupWizard Spider | Wizard Spider has collected and staged credentials and network enumeration information, using the networkdll and psfin TrickBot modules. |
| T1074 Data Staged |
GroupVOID MANTICORE | VOID MANTICORE has staged compressed files in specified locations prior to exfiltration over C2. |
| T1074.001 Local Data Staging |
GroupIndrik Spider | Indrik Spider has stored collected data in a .tmp file. |
| T1074.001 Local Data Staging |
GroupGALLIUM | GALLIUM compressed and staged files in multi-part archives in the Recycle Bin prior to exfiltration. |
| T1074.001 Local Data Staging |
GroupAPT3 | APT3 has been known to stage files for exfiltration in a single location. |
| T1074.001 Local Data Staging |
GroupKimsuky | Kimsuky has staged collected data files under |
| T1074.001 Local Data Staging |
GroupVolt Typhoon | Volt Typhoon has saved stolen files including the `ntds.dit` database and the `SYSTEM` and `SECURITY` Registry hives locally to the `C:\Windows\Temp\` directory. |
| T1074.001 Local Data Staging |
GroupPatchwork | Patchwork copied all targeted files to a directory called index that was eventually uploaded to the C&C server. |
| T1074.001 Local Data Staging |
GroupDragonfly | Dragonfly has created a directory named "out" in the user's %AppData% folder and copied files to it. |
| T1074.001 Local Data Staging |
GroupmenuPass | menuPass stages data prior to exfiltration in multi-part archives, often saved in the Recycle Bin. |
| T1074.001 Local Data Staging |
GroupMuddyWater | MuddyWater has stored a decoy PDF file within a victim's `%temp%` folder. |
| T1074.001 Local Data Staging |
GroupStorm-1811 | Storm-1811 has locally staged captured credentials for subsequent manual exfiltration. |
| T1074.001 Local Data Staging |
GroupTeamTNT | TeamTNT has aggregated collected credentials in text files before exfiltrating. |
| T1074.001 Local Data Staging |
GroupSidewinder | Sidewinder has collected stolen files in a temporary folder in preparation for exfiltration. |
| T1074.001 Local Data Staging |
GroupMustang Panda | Mustang Panda has stored collected credential files in |
| T1074.001 Local Data Staging |
GroupAPT39 | APT39 has utilized tools to aggregate data prior to exfiltration. |
| T1074.001 Local Data Staging |
GroupUNC3886 | UNC3886 has staged captured credentials in `var/log/ldapd<unique_keyword>.2.gz`. |
| T1074.001 Local Data Staging |
GroupLeviathan | Leviathan has used C:\Windows\Debug and C:\Perflogs as staging directories. |
| T1074.001 Local Data Staging |
GroupFIN5 | FIN5 scripts save memory dump data into a specific directory on hosts in the victim environment. |
| T1074.001 Local Data Staging |
GroupLotus Blossom | Lotus Blossom has locally staged compressed and archived data for follow-on exfiltration. |
| T1074.001 Local Data Staging |
GroupChimera | Chimera has staged stolen data locally on compromised hosts. |
| T1074.001 Local Data Staging |
GroupBackdoorDiplomacy | BackdoorDiplomacy has copied files of interest to the main drive's recycle bin. |
| T1074.001 Local Data Staging |
GroupAgrius | Agrius has used the folder, |
| T1074.001 Local Data Staging |
GroupAPT28 | APT28 has stored captured credential information in a file named pi.log. |
| T1074.001 Local Data Staging |
GroupAPT5 | APT5 has staged data on compromised systems prior to exfiltration often in `C:\Users\Public`. |
| T1074.001 Local Data Staging |
GroupLazarus Group | Lazarus Group malware IndiaIndia saves information gathered about the victim to a file that is saved in the %TEMP% directory, then compressed, encrypted, and uploaded to a C2 server. |
| T1074.001 Local Data Staging |
GroupWizard Spider | Wizard Spider has staged ZIP files in local directories such as, `C:\PerfLogs\1\` and `C:\User\1\` prior to exfiltration. |
| T1074.001 Local Data Staging |
GroupWIRTE | WIRTE has staged collected documents of interest in `C:\Users\Public folder`. |
| T1074.001 Local Data Staging |
GroupThreat Group-3390 | Threat Group-3390 has locally staged encrypted archives for later exfiltration efforts. |
| T1074.001 Local Data Staging |
GroupFIN13 | FIN13 has utilized the following temporary folders on compromised Windows and Linux systems for their operations prior to exfiltration: `C:\Windows\Temp` and `/tmp`. |
| T1074.002 Remote Data Staging |
GroupmenuPass | menuPass has staged data on remote MSP systems or other victim networks prior to exfiltration. |
| T1074.002 Remote Data Staging |
GroupFIN6 | FIN6 actors have compressed data from remote systems and moved it to another staging system before exfiltration. |
| T1074.002 Remote Data Staging |
GroupSea Turtle | Sea Turtle staged collected email archives in the public web directory of a website that was accessible from the internet. |
| T1074.002 Remote Data Staging |
GroupLeviathan | Leviathan has staged data remotely prior to exfiltration. |
| T1074.002 Remote Data Staging |
GroupMoustachedBouncer | MoustachedBouncer has used plugins to save captured screenshots to `.\AActdata\` on an SMB share. |
| T1074.002 Remote Data Staging |
GroupChimera | Chimera has staged stolen data on designated servers in the target environment. |
| T1074.002 Remote Data Staging |
GroupMirrorFace | MirrorFace has gathered data and files of interest on a single victim machine. |
| T1074.002 Remote Data Staging |
GroupToddyCat | ToddyCat manually transferred collected files to an exfiltration host using xcopy. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.