Real-world descriptions of how a group, tool or campaign used a technique.
4628 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
GroupLazarus Group | Lazarus Group has collected data and files from compromised networks. |
| T1005 Data from Local System |
GroupLAPSUS$ | LAPSUS$ uploaded sensitive files, information, and credentials from a targeted organization for extortion or public release. |
| T1005 Data from Local System |
GroupWizard Spider | Wizard Spider has collected data from a compromised host prior to exfiltration. |
| T1005 Data from Local System |
GroupInception | Inception used a file hunting plugin to collect .txt, .pdf, .xls or .doc files from the infected host. |
| T1005 Data from Local System |
GroupVOID MANTICORE | VOID MANTICORE has collected cached data and files from within the victim environment. |
| T1005 Data from Local System |
GroupMagic Hound | Magic Hound has used a web shell to exfiltrate a ZIP file containing a dump of LSASS memory on a compromised machine. |
| T1005 Data from Local System |
GroupThreat Group-3390 | Threat Group-3390 ran a command to compile an archive of file types of interest from the victim user's directories. |
| T1005 Data from Local System |
GroupFIN13 | FIN13 has gathered stolen credentials, sensitive data such as point-of-sale (POS), and ATM data from a compromised network before exfiltration. |
| T1005 Data from Local System |
GroupTeamPCP | TeamPCP has stolen source code from victim environments including Mistral AI. |
| T1006 Direct Volume Access |
GroupVolt Typhoon | Volt Typhoon has executed the Windows-native `vssadmin` command to create volume shadow copies. |
| T1006 Direct Volume Access |
GroupScattered Spider | Scattered Spider has created volume shadow copies of virtual domain controller disks to extract the `NTDS.dit` file. |
| T1007 System Service Discovery |
GroupIndrik Spider | Indrik Spider has used the win32_service WMI class to retrieve a list of services from the system. |
| T1007 System Service Discovery |
GroupKimsuky | Kimsuky has used an instrumentor script to gather the names of all services running on a victim's system. |
| T1007 System Service Discovery |
Groupadmin@338 | admin@338 actors used the following command following exploitation of a machine with LOWBALL malware to obtain information about services: |
| T1007 System Service Discovery |
GroupVolt Typhoon | Volt Typhoon has used `net start` to list running services. |
| T1007 System Service Discovery |
GroupTeamTNT | TeamTNT has searched for services such as Alibaba Cloud Security's aliyun service and BMC Helix Cloud Security's bmc-agent service in order to disable them. |
| T1007 System Service Discovery |
GroupOilRig | OilRig has used |
| T1007 System Service Discovery |
GroupAquatic Panda | Aquatic Panda has attempted to discover services for third party EDR products. |
| T1007 System Service Discovery |
GroupKe3chang | Ke3chang performs service discovery using |
| T1007 System Service Discovery |
GroupAPT1 | APT1 used the commands |
| T1007 System Service Discovery |
GroupTurla | Turla surveys a system upon check-in to discover running services and associated processes using the |
| T1007 System Service Discovery |
GroupPoseidon Group | After compromising a victim, Poseidon Group discovers all running services. |
| T1007 System Service Discovery |
GroupChimera | Chimera has used |
| T1007 System Service Discovery |
GroupMirrorFace | MirrorFace has used Tasklist for discovery post compromise. |
| T1007 System Service Discovery |
GroupBRONZE BUTLER | BRONZE BUTLER has used TROJ_GETVERSION to discover system services. |
| T1007 System Service Discovery |
GroupEarth Lusca | Earth Lusca has used Tasklist to obtain information from a compromised host. |
| T1008 Fallback Channels |
GroupAPT41 | APT41 used the Steam community page as a fallback mechanism for C2. |
| T1008 Fallback Channels |
GroupFIN7 | FIN7's Harpy backdoor malware can use DNS as a backup channel for C2 if HTTP fails. |
| T1008 Fallback Channels |
GroupUNC3886 | UNC3886 has employed layers of redundancy to maintain access to compromised environments including network devices, hypervisors, and virtual machines. |
| T1008 Fallback Channels |
GroupOilRig | OilRig malware ISMAgent falls back to its DNS tunneling mechanism if it is unable to reach the C2 server over HTTP. |
| T1008 Fallback Channels |
GroupLazarus Group | Lazarus Group malware SierraAlfa sends data to one of the hard-coded C2 servers chosen at random, and if the transmission fails, chooses a new C2 server to attempt the transmission again. |
| T1010 Application Window Discovery |
GroupVolt Typhoon | Volt Typhoon has collected window title information from compromised systems. |
| T1010 Application Window Discovery |
GroupLazarus Group | Lazarus Group malware IndiaIndia obtains and sends to its C2 server the title of the window for each running process. The KilaAlfa keylogger also reports the title of the window in the foreground. |
| T1010 Application Window Discovery |
GroupHEXANE | HEXANE has used a PowerShell-based keylogging tool to capture the window title. |
| T1012 Query Registry |
GroupIndrik Spider | Indrik Spider has used a service account to extract copies of the `Security` Registry hive. |
| T1012 Query Registry |
GroupBlackByte | BlackByte queried registry values to determine system language settings. |
| T1012 Query Registry |
GroupKimsuky | Kimsuky has obtained specific Registry keys and values on a compromised host. |
| T1012 Query Registry |
GroupVolt Typhoon | Volt Typhoon has queried the Registry on compromised systems, `reg query hklm\software\`, for information on installed software including PuTTY. |
| T1012 Query Registry |
GroupAPT41 | APT41 queried registry values to determine items such as configured RDP ports and network configurations. |
| T1012 Query Registry |
GroupDragonfly | Dragonfly has queried the Registry to identify victim information. |
| T1012 Query Registry |
GroupAPT32 | APT32's backdoor can query the Windows Registry to gather system information. |
| T1012 Query Registry |
GroupGamaredon Group | Gamaredon Group has queried ` HKEY_CURRENT_USER\\Console\\WindowsUpdates` to obtain the C2 addresses. Gamaredon Group has queried ` HKEY_CURRENT_USER\\Console\\WindowsUpdates` to obtain the C2 addresses. |
| T1012 Query Registry |
GroupZIRCONIUM | ZIRCONIUM has used a tool to query the Registry for proxy settings. |
| T1012 Query Registry |
GroupAPT39 | APT39 has used various strains of malware to query the Registry. |
| T1012 Query Registry |
GroupOilRig | OilRig has used |
| T1012 Query Registry |
GroupTurla | Turla surveys a system upon check-in to discover information in the Windows Registry with the |
| T1012 Query Registry |
GroupLotus Blossom | Lotus Blossom has run commands such as `reg query HKLM\SYSTEM\CurrentControlSet\Services\[service name]\Parameters` to verify if installed implants are running as a service. |
| T1012 Query Registry |
GroupStealth Falcon | Stealth Falcon malware attempts to determine the installed version of .NET by querying the Registry. |
| T1012 Query Registry |
GroupChimera | Chimera has queried Registry keys using |
| T1012 Query Registry |
GroupFox Kitten | Fox Kitten has accessed Registry hives ntuser.dat and UserClass.dat. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.