Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1671 Cloud Application Integration |
CampaignSalesforce Data Exfiltration | During Salesforce Data Exfiltration, threat actors deceived victims into authorizing malicious connected apps to their organization's Salesforce portal. |
| T1673 Virtual Machine Discovery |
GroupUNC3886 | UNC3886 has used scripts to enumerate ESXi hypervisors and their guest VMs. |
| T1673 Virtual Machine Discovery |
MalwareCheerscrypt | Cheerscrypt has leveraged `esxcli vm process list` in order to gather a list of running virtual machines to terminate them. |
| T1673 Virtual Machine Discovery |
MalwarePureCrypter | PureCrypter can identify virtual machines by querying the WMI object Win32_ComputerSystem for manufacturer and model and check it against the regular expression Microsoft|VMWare|Virtual. |
| T1673 Virtual Machine Discovery |
MalwareVIRTUALPITA | VIRTUALPITA can target specific guest virtual machines for script execution. |
| T1673 Virtual Machine Discovery |
MalwareQilin | Qilin can detect virtual machine environments including ESXi hosts, datacenters, and clusters within vCenter environments. |
| T1674 Input Injection |
GroupFIN7 | FIN7 has used malicious USBs to emulate keystrokes to launch PowerShell to download and execute malware from the adversary's server. |
| T1675 ESXi Administration Command |
GroupUNC3886 | UNC3886 used `vmtoolsd.exe` to run commands on guest virtual machines from a compromised ESXi host. |
| T1675 ESXi Administration Command |
MalwareVIRTUALPITA | VIRTUALPITA can execute commands on guest virtual machines from compromised ESXi hypervisors. |
| T1677 Poisoned Pipeline Execution |
MalwareShai-Hulud | Shai-Hulud has also leveraged GitHub actions from stolen accounts in order to create a malicious Github workflow within `.github/workflows/discussion.yaml`. |
| T1677 Poisoned Pipeline Execution |
MalwareMini Shai-Hulud | Mini Shai-Hulud has utilized Github Actions to propagate through the use of triggered workflows. |
| T1677 Poisoned Pipeline Execution |
MalwareCanisterWorm | CanisterWorm has leveraged stolen tokens from Trivy users to publish itself across over 46 npm packages. |
| T1677 Poisoned Pipeline Execution |
GroupTeamPCP | TeamPCP has compromised trusted CI/CD pipelines by injecting credential-stealing payloads into legitimate workflows and software packages including open-source security tools Trivy and KICS, and AI gateway LiteLLM. Aikido TeamPCP Telnyx MAR 2026Aqua Security Blog Trivy Compromise APR 2026Aqua Security Trivy Compromise MAR 2026FBI TeamPCP JUL 2026Flashpoint Mini Shai-Hulud MAY 2026Google AI Threat Tracker MAY 2026Hunt.io TeamPCP Toolkit MAY 2026Palo Alto TeamPCP MAR 2026Phoenix TeamPCP 20 MAY 2026Sysdig TeamPCP MAR 2026Trend Micro TeamPCP MAY 2026Wiz Mini Shai-Hulud MAY 2026Wiz TeamPCP KICS MAR 2026Wiz Trivy Compromise MAR 2026 |
| T1678 Delay Execution |
Campaign3CX Supply Chain Attack | During the 3CX Supply Chain Attack, AppleJeus's software generates a randomly selected date that is between 1-4 weeks in the future. This timestamp is then checked against the current time of the compromised machine, and the malware will sleep until that time is encountered. |
| T1678 Delay Execution |
GroupKimsuky | Kimsuky has utilized the Sleep function to ensure execution of scripts. |
| T1678 Delay Execution |
GroupMustang Panda | Mustang Panda has delayed the execution of payloads leveraging ping echo requests `cmd /c ping 8.8.8.8 -n 70&&"%temp%\<legitimate executable>"`. |
| T1678 Delay Execution |
MalwareBRICKSTORM | BRICKSTORM has embedded delayed-start logic that attempts to circumvent detection for long-term persistence. BRICKSTORM has been observed configured with a “delay” timer built-in that waited for a hard-coded date months in the future before beginning to beacon to the configured C2 domain. |
| T1678 Delay Execution |
MalwareTONESHELL | TONESHELL has the ability to pause operations for a specified duration prior to follow-on execution of activities. |
| T1678 Delay Execution |
MalwareDynoWiper | DynoWiper has utilized a five-second delay using `Sleep(5000)` between two of the three phases of the attack that involves file overwriting, file deletion, and system reboot. |
| T1678 Delay Execution |
MalwareSystemBC | SystemBC has leveraged the Sleep functions before and after commands to ensure execution using the hexadecimal values within commands to include `Sleep(0x2710u)` that waits 10 seconds, and `Sleep(0xEA60u)` for 60 seconds. |
| T1678 Delay Execution |
MalwareRustyWater | RustyWater has generated random sleep intervals between C2 communication. |
| T1678 Delay Execution |
MalwarePureCrypter | PureCrypter has the ability to delay for a specified number of seconds before execution. |
| T1678 Delay Execution |
MalwareMuddyViper | MuddyViper has the ability to sleep for a certain amount of time, with the default being one minute. |
| T1678 Delay Execution |
MalwareFooder | Fooder has used a custom delay function (`delayExecution(integer)`) and Sleep API calls (`Sleep(integer)`) to slow code execution. |
| T1678 Delay Execution |
MalwareGlassWorm | GlassWorm has used a timeout function set to `9e5` which delays execution 900,000 milliseconds or 15 minutes to avoid detection. |
| T1678 Delay Execution |
MalwareAshTag | AshTag can use a set sleep time to delay C2 beaconing. |
| T1678 Delay Execution |
MalwarePHASEJAM | PHASEJAM has used the `sleep` command within its code to generate a fake HTML upgrade progress bar that mimics a running process. |
| T1678 Delay Execution |
MalwareSPAWNCHIMERA | SPAWNCHIMERA has used delayed execution to pause for a defined interval before performing environment discovery, repeatedly checking for specific processes, such as the `dslogserver` process, prior to continuing execution. |
| T1678 Delay Execution |
MalwareHIUPAN | HIUPAN has used a config file “$.ini” to store a sleep multiplier to execute at a set interval value prior to initiating a watcher function that checks for a specific running process, that checks for removable drives and installs itself and supporting files if one is available. |
| T1678 Delay Execution |
MalwareShai-Hulud | Shai-Hulud has delayed execution of its larger payloads by forking itself into background process. |
| T1678 Delay Execution |
MalwareQilin | Qilin has the ability to delay execution. |
| T1678 Delay Execution |
MalwareUPPERCUT | UPPERCUT can use a sleep function to delay execution. |
| T1678 Delay Execution |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer has leveraged a persistence script that will sleep for five minutes before additional execution. |
| T1679 Selective Exclusion |
GroupVOID MANTICORE | VOID MANTICORE has avoided interacting with specific directories in order to reduce the likelihood of detection. |
| T1679 Selective Exclusion |
MalwareInvisibleFerret | InvisibleFerret has the capability to scan for file names, file extensions, and avoids pre-designated path names and file types. |
| T1679 Selective Exclusion |
MalwareMedusa Ransomware | Medusa Ransomware has avoided specified files, file extensions and folders to ensure successful execution of the payload and continued operations of the impacted device. |
| T1679 Selective Exclusion |
MalwareDynoWiper | DynoWiper has recursively enumerated directories with the exception of the following: System32, Windows, Program Files, Program Files(x86), Temp, Recycle.Bin, $Recycle.Bin, Boot, PerfLogs, AppData, Documents and Settings. |
| T1679 Selective Exclusion |
MalwareSameCoin | SameCoin can avoid overwriting file names that contain “desktop.ini” and “conf.conf." |
| T1679 Selective Exclusion |
MalwareEmbargo | Embargo has avoided encrypting specific files and directories by leveraging a regular expression within the ransomware binary. |
| T1679 Selective Exclusion |
MalwareLazyWiper | LazyWiper can enumerate the hostname of the system to determine if it is a domain controller and exclude it from being wiped if so. |
| T1680 Local Storage Discovery |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used `fsutil` to check available free space before executing actions that might create large files on disk. |
| T1680 Local Storage Discovery |
CampaignOperation Wocao | During Operation Wocao, threat actors discovered the local disks attached to the system and their hardware information including manufacturer and model. |
| T1680 Local Storage Discovery |
CampaignC0017 | During C0017, APT41 issued `ping -n 1 ((cmd /c dir c:\|findstr Number).split()[-1]+` commands to find the volume serial number of compromised systems. |
| T1680 Local Storage Discovery |
GroupKimsuky | Kimsuky has enumerated drives. |
| T1680 Local Storage Discovery |
GroupVolt Typhoon | Volt Typhoon has discovered file system types, drive names, size, and free space on compromised systems. |
| T1680 Local Storage Discovery |
GroupPatchwork | Patchwork enumerated all available drives on the victim's machine. |
| T1680 Local Storage Discovery |
GroupTeamTNT | TeamTNT has searched for disk partition and logical volume information. |
| T1680 Local Storage Discovery |
GroupHigaisa | Higaisa collected the system volume serial number. |
| T1680 Local Storage Discovery |
GroupTropic Trooper | Tropic Trooper has detected a target system’s system volume information. |
| T1680 Local Storage Discovery |
GroupConfucius | Confucius has used a file stealer that can examine system drives, including those other than the C drive. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.