ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

4628 examples

TechniqueUsed byProcedure example
T1113
Screen Capture
GroupGOLD SOUTHFIELD

GOLD SOUTHFIELD has used the remote monitoring and management tool ConnectWise to obtain screen captures from victim's machines.

T1113
Screen Capture
GroupSilence

Silence can capture victim screen activity.

T1113
Screen Capture
GroupVOID MANTICORE

VOID MANTICORE has captured screen content during an active Zoom session.

T1113
Screen Capture
GroupMagic Hound

Magic Hound malware can take a screenshot and upload the file to its C2 server.

T1114
Email Collection
GroupScattered Spider

Scattered Spider searched the victim’s Microsoft Exchange for emails about the intrusion and incident response.

T1114
Email Collection
GroupSilent Librarian

Silent Librarian has exfiltrated entire mailboxes from compromised accounts.

T1114
Email Collection
GroupEmber Bear

Ember Bear attempts to collect mail from accessed systems and servers.

T1114
Email Collection
GroupMagic Hound

Magic Hound has compromised email credentials in order to steal sensitive data.

T1114.001
Local Email Collection
GroupSea Turtle

Sea Turtle collected email archives from victim environments.

T1114.001
Local Email Collection
GroupAPT1

APT1 uses two utilities, GETMAIL and MAPIGET, to steal email. GETMAIL extracts emails from archived Outlook .pst files.

T1114.001
Local Email Collection
GroupWinter Vivern

Winter Vivern delivered malicious JavaScript payloads capable of exfiltrating email messages from exploited email servers.

T1114.001
Local Email Collection
GroupRedCurl

RedCurl has collected emails to use in future phishing campaigns.

T1114.001
Local Email Collection
GroupChimera

Chimera has harvested data from victim's e-mail including through execution of wmic /node:<ip> process call create "cmd /c copy c:\Users\<username>\<path>\backup.pst c:\windows\temp\backup.pst" copy "i:\<path>\<username>\My Documents\<filename>.pst"
copy
.

T1114.001
Local Email Collection
GroupMirrorFace

MirrorFace has exfiltrated stored emails from compromised hosts.

T1114.001
Local Email Collection
GroupWIRTE

WIRTE has collected documents from victims' email accounts.

T1114.001
Local Email Collection
GroupMagic Hound

Magic Hound has collected .PST archives.

T1114.002
Remote Email Collection
GroupKimsuky

Kimsuky has used tools such as the MailFetch mail crawler to collect victim emails (excluding spam) from online services via IMAP.

T1114.002
Remote Email Collection
GroupDragonfly

Dragonfly has accessed email accounts using Outlook Web Access.

T1114.002
Remote Email Collection
GroupHAFNIUM

HAFNIUM has used web shells and MSGraph to export mailbox data.

T1114.002
Remote Email Collection
GroupLeafminer

Leafminer used a tool called MailSniper to search through the Exchange server mailboxes for keywords.

T1114.002
Remote Email Collection
GroupKe3chang

Ke3chang has used compromised credentials and a .NET tool to dump data from Microsoft Exchange mailboxes.

T1114.002
Remote Email Collection
GroupAPT1

APT1 uses two utilities, GETMAIL and MAPIGET, to steal email. MAPIGET steals email still on Exchange servers that has not yet been archived.

T1114.002
Remote Email Collection
GroupAPT29

APT29 has collected emails from targeted mailboxes within a compromised Azure AD tenant and compromised Exchange servers, including via Exchange Web Services (EWS) API requests.

T1114.002
Remote Email Collection
GroupChimera

Chimera has harvested data from remote mailboxes including through execution of \\<hostname>\c$\Users\<username>\AppData\Local\Microsoft\Outlook*.ost.

T1114.002
Remote Email Collection
GroupStar Blizzard

Star Blizzard has remotely accessed victims' email accounts to steal messages and attachments.

T1114.002
Remote Email Collection
GroupAPT28

APT28 has collected emails from victim Microsoft Exchange servers.

T1114.002
Remote Email Collection
GroupFIN4

FIN4 has accessed and hijacked online email communications using stolen credentials.

T1114.002
Remote Email Collection
GroupVOID MANTICORE

VOID MANTICORE has gathered victim email-content from victim servers.

T1114.002
Remote Email Collection
GroupMagic Hound

Magic Hound has exported emails from compromised Exchange servers including through use of the cmdlet `New-MailboxExportRequest.`

T1114.003
Email Forwarding Rule
GroupKimsuky

Kimsuky has set auto-forward rules on victim's e-mail accounts.

T1114.003
Email Forwarding Rule
GroupScattered Spider

Scattered Spider has redirected emails notifying users of suspicious account activity.

T1114.003
Email Forwarding Rule
GroupSilent Librarian

Silent Librarian has set up auto forwarding rules on compromised e-mail accounts.

T1114.003
Email Forwarding Rule
GroupStar Blizzard

Star Blizzard has abused email forwarding rules to monitor the activities of a victim, steal information, and maintain persistent access after compromised credentials are reset.

T1114.003
Email Forwarding Rule
GroupLAPSUS$

LAPSUS$ has set an Office 365 tenant level mail transport rule to send all mail in and out of the targeted organization to the newly created account.

T1115
Clipboard Data
GroupAPT38

APT38 used a Trojan called KEYLIME to collect data from the clipboard.

T1115
Clipboard Data
GroupKimsuky

Kimsuky has the ability to steal data from the clipboard.

T1115
Clipboard Data
GroupAPT39

APT39 has used tools capable of stealing contents of the clipboard.

T1115
Clipboard Data
GroupOilRig

OilRig has used infostealer tools to copy clipboard data.

T1119
Automated Collection
GroupPatchwork

Patchwork developed a file stealer to search C:\ and collect files with certain extensions. Patchwork also executed a script to enumerate all drives, store them as a list, and upload generated files to the C2 server.

T1119
Automated Collection
GroupmenuPass

menuPass has used the Csvde tool to collect Active Directory files and data.

T1119
Automated Collection
GroupHAFNIUM

HAFNIUM has used MSGraph to exfiltrate data from email, OneDrive, and SharePoint.

T1119
Automated Collection
GroupFIN6

FIN6 has used a script to iterate through a list of compromised PoS systems, copy and remove data to a log file, and to bind to events from the submit payment button.

T1119
Automated Collection
GroupGamaredon Group

Gamaredon Group has deployed scripts on compromised systems that automatically scan for interesting documents.

T1119
Automated Collection
GroupSidewinder

Sidewinder has used tools to automatically collect system and network configuration information.

T1119
Automated Collection
GroupMustang Panda

Mustang Panda used custom batch scripts to collect files automatically from a targeted system.

T1119
Automated Collection
GroupOilRig

OilRig has used automated collection.

T1119
Automated Collection
GroupTropic Trooper

Tropic Trooper has collected information automatically using the adversary's USBferry attack.

T1119
Automated Collection
GroupKe3chang

Ke3chang has performed frequent and scheduled data collection from victim networks.

T1119
Automated Collection
GroupAPT1

APT1 used a batch script to perform a series of discovery techniques and saves it to a text file.

T1119
Automated Collection
GroupConfucius

Confucius has used a file stealer to steal documents and images with the following extensions: txt, pdf, png, jpg, doc, xls, xlm, odp, ods, odt, rtf, ppt, xlsx, xlsm, docx, pptx, and jpeg.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.