Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1039 Data from Network Shared Drive |
MalwareCosmicDuke | CosmicDuke steals user files from network shared drives with file extensions and keywords that match a predefined list. |
| T1039 Data from Network Shared Drive |
MalwareRamsay | Ramsay can collect data from network drives and stage it for exfiltration. |
| T1039 Data from Network Shared Drive |
MalwareEgregor | Egregor can collect any files found in the enumerated drivers before sending it to its C2 channel. |
| T1039 Data from Network Shared Drive |
MalwareBADNEWS | When it first starts, BADNEWS crawls the victim's mapped drives and collects documents with the following extensions: .doc, .docx, .pdf, .ppt, .pptx, and .txt. |
| T1040 Network Sniffing |
Malwarecd00r | cd00r can use the libpcap library to monitor captured packets for specifc sequences. |
| T1040 Network Sniffing |
MalwareJumbledPath | JumbledPath has the ability to perform packet capture on remote devices via actor-defined jump-hosts. |
| T1040 Network Sniffing |
MalwareVersaMem | VersaMem hooked the Catalina application filter chain `doFilter` on compromised systems to monitor all inbound requests to the local Tomcat web server, inspecting them for parameters like passwords and follow-on Java modules. |
| T1040 Network Sniffing |
MalwareCASTLETAP | CASTLETAP has the ability to create a raw promiscuous socket to sniff network traffic. |
| T1040 Network Sniffing |
MalwareJ-magic | J-magic has a pcap listener function that can create an Extended Berkley Packet Filter (eBPF) on designated interfaces and ports. |
| T1040 Network Sniffing |
MalwareEmotet | Emotet has been observed to hook network APIs to monitor network traffic. |
| T1040 Network Sniffing |
MalwareRegin | Regin appears to have functionality to sniff for credentials passed over HTTP, SMTP, and SMB. |
| T1040 Network Sniffing |
MalwareLine Dancer | Line Dancer can create and exfiltrate packet captures from compromised environments. |
| T1040 Network Sniffing |
MalwareFoggyWeb | FoggyWeb can configure custom listeners to passively monitor all incoming HTTP GET and POST requests sent to the AD FS server from the intranet/internet and intercept HTTP requests that match the custom URI patterns defined by the actor. |
| T1040 Network Sniffing |
MalwareMESSAGETAP | MESSAGETAP uses the libpcap library to listen to all traffic and parses network protocols starting with Ethernet and IP layers. It continues parsing protocol layers including SCTP, SCCP, and TCAP and finally extracts SMS message data and routing metadata. |
| T1040 Network Sniffing |
MalwarePenquin | Penquin can sniff network traffic to look for packets matching specific conditions. |
| T1040 Network Sniffing |
MalwareSPAWNCHIMERA | SPAWNCHIMERA has monitored and filtered network traffic on compromised edge devices, allowing legitimate traffic to pass while redirecting attacker-controlled traffic to infrastructure under adversary control. |
| T1040 Network Sniffing |
ToolImpacket | Impacket can be used to sniff network traffic via an interface or raw socket. |
| T1040 Network Sniffing |
ToolEmpire | Empire can be used to conduct packet captures on target hosts. |
| T1040 Network Sniffing |
ToolPoshC2 | PoshC2 contains a module for taking packet captures on compromised hosts. |
| T1040 Network Sniffing |
ToolResponder | Responder captures hashes and credentials that are sent to the system after the name services have been poisoned. |
| T1040 Network Sniffing |
ToolNBTscan | NBTscan can dump and print whole packet content. |
| T1041 Exfiltration Over C2 Channel |
MalwareTrickBot | TrickBot can send information about the compromised host and upload data to a hardcoded C2 server. |
| T1041 Exfiltration Over C2 Channel |
MalwareBLINDINGCAN | BLINDINGCAN has sent user and system information to a C2 server via HTTP POST requests. |
| T1041 Exfiltration Over C2 Channel |
MalwarePikabot | During the initial Pikabot command and control check-in, Pikabot will transmit collected system information encrypted using RC4. |
| T1041 Exfiltration Over C2 Channel |
MalwareSpark | Spark has exfiltrated data over the C2 channel. |
| T1041 Exfiltration Over C2 Channel |
MalwareBumblebee | Bumblebee can send collected data in JSON format to C2. |
| T1041 Exfiltration Over C2 Channel |
MalwareBRICKSTORM | BRICKSTORM has uploaded files from the victim system to C2 servers. CISA BRICKSTORM UNC5221 AR25-338A February 2026CrowdStrike BRICKSTORM WARP PANDA UNC5221 December 2025Google BRICKSTORM September 2025Google UNC5221 BRICKSTORM SPAWNCHIMERA April 2024NVISO BRICKSTORM April 2025Picus Security BRICKSTORM UNC5221 October 2025Resecurity UNC5221 BRICKSTORM F5 Big-IP October 2025 |
| T1041 Exfiltration Over C2 Channel |
MalwareAmadey | Amadey has sent victim data to its C2 servers. |
| T1041 Exfiltration Over C2 Channel |
MalwareProxysvc | Proxysvc performs data exfiltration over the control server channel using a custom protocol. |
| T1041 Exfiltration Over C2 Channel |
MalwareTorisma | Torisma can send victim data to an actor-controlled C2 server. |
| T1041 Exfiltration Over C2 Channel |
MalwareStuxnet | Stuxnet sends compromised victim information via HTTP. |
| T1041 Exfiltration Over C2 Channel |
MalwareRotaJakiro | RotaJakiro sends device and other collected data back to the C2 using the established C2 channels over TCP. |
| T1041 Exfiltration Over C2 Channel |
MalwareKOPILUWAK | KOPILUWAK has exfiltrated collected data to its C2 via POST requests. |
| T1041 Exfiltration Over C2 Channel |
MalwareMisdat | Misdat has uploaded files and data to its C2 servers. |
| T1041 Exfiltration Over C2 Channel |
MalwareHAWKBALL | HAWKBALL has sent system information and files over the C2 channel. |
| T1041 Exfiltration Over C2 Channel |
MalwareUrsnif | Ursnif has used HTTP POSTs to exfil gathered information. |
| T1041 Exfiltration Over C2 Channel |
MalwareZLib | ZLib has sent data and files from a compromised host to its C2 servers. |
| T1041 Exfiltration Over C2 Channel |
MalwareInvisibleFerret | InvisibleFerret has used HTTP communications to the “/Uploads” URI for file exfiltration. |
| T1041 Exfiltration Over C2 Channel |
MalwareBankshot | Bankshot exfiltrates data over its C2 channel. |
| T1041 Exfiltration Over C2 Channel |
MalwareSharpDisco | SharpDisco can load a plugin to exfiltrate stolen files to SMB shares also used in C2. |
| T1041 Exfiltration Over C2 Channel |
MalwareStrongPity | StrongPity can exfiltrate collected documents through C2 channels. |
| T1041 Exfiltration Over C2 Channel |
MalwareAppleSeed | AppleSeed can exfiltrate files via the C2 channel. |
| T1041 Exfiltration Over C2 Channel |
MalwarePowerExchange | PowerExchange can exfiltrate files via its email C2 channel. |
| T1041 Exfiltration Over C2 Channel |
MalwareEmotet | Emotet has exfiltrated data over its C2 channel. |
| T1041 Exfiltration Over C2 Channel |
MalwareCrimson | Crimson can exfiltrate stolen information over its C2. |
| T1041 Exfiltration Over C2 Channel |
MalwareTomiris | Tomiris can upload files matching a hardcoded set of extensions, such as .doc, .docx, .pdf, and .rar, to its C2 server. |
| T1041 Exfiltration Over C2 Channel |
MalwareDUSTTRAP | DUSTTRAP can exfiltrate collected data over C2 channels. |
| T1041 Exfiltration Over C2 Channel |
MalwareBADHATCH | BADHATCH can exfiltrate data over the C2 channel. |
| T1041 Exfiltration Over C2 Channel |
MalwareMachete | Machete's collected data is exfiltrated over the same channel used for C2. |
| T1041 Exfiltration Over C2 Channel |
MalwarePingPull | PingPull has the ability to exfiltrate stolen victim data through its C2 channel. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.