Real-world descriptions of how a group, tool or campaign used a technique.
4628 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1113 Screen Capture |
GroupGOLD SOUTHFIELD | GOLD SOUTHFIELD has used the remote monitoring and management tool ConnectWise to obtain screen captures from victim's machines. |
| T1113 Screen Capture |
GroupSilence | Silence can capture victim screen activity. |
| T1113 Screen Capture |
GroupVOID MANTICORE | VOID MANTICORE has captured screen content during an active Zoom session. |
| T1113 Screen Capture |
GroupMagic Hound | Magic Hound malware can take a screenshot and upload the file to its C2 server. |
| T1114 Email Collection |
GroupScattered Spider | Scattered Spider searched the victim’s Microsoft Exchange for emails about the intrusion and incident response. |
| T1114 Email Collection |
GroupSilent Librarian | Silent Librarian has exfiltrated entire mailboxes from compromised accounts. |
| T1114 Email Collection |
GroupEmber Bear | Ember Bear attempts to collect mail from accessed systems and servers. |
| T1114 Email Collection |
GroupMagic Hound | Magic Hound has compromised email credentials in order to steal sensitive data. |
| T1114.001 Local Email Collection |
GroupSea Turtle | Sea Turtle collected email archives from victim environments. |
| T1114.001 Local Email Collection |
GroupAPT1 | APT1 uses two utilities, GETMAIL and MAPIGET, to steal email. GETMAIL extracts emails from archived Outlook .pst files. |
| T1114.001 Local Email Collection |
GroupWinter Vivern | Winter Vivern delivered malicious JavaScript payloads capable of exfiltrating email messages from exploited email servers. |
| T1114.001 Local Email Collection |
GroupRedCurl | RedCurl has collected emails to use in future phishing campaigns. |
| T1114.001 Local Email Collection |
GroupChimera | Chimera has harvested data from victim's e-mail including through execution of |
| T1114.001 Local Email Collection |
GroupMirrorFace | MirrorFace has exfiltrated stored emails from compromised hosts. |
| T1114.001 Local Email Collection |
GroupWIRTE | WIRTE has collected documents from victims' email accounts. |
| T1114.001 Local Email Collection |
GroupMagic Hound | Magic Hound has collected .PST archives. |
| T1114.002 Remote Email Collection |
GroupKimsuky | Kimsuky has used tools such as the MailFetch mail crawler to collect victim emails (excluding spam) from online services via IMAP. |
| T1114.002 Remote Email Collection |
GroupDragonfly | Dragonfly has accessed email accounts using Outlook Web Access. |
| T1114.002 Remote Email Collection |
GroupHAFNIUM | HAFNIUM has used web shells and MSGraph to export mailbox data. |
| T1114.002 Remote Email Collection |
GroupLeafminer | Leafminer used a tool called MailSniper to search through the Exchange server mailboxes for keywords. |
| T1114.002 Remote Email Collection |
GroupKe3chang | Ke3chang has used compromised credentials and a .NET tool to dump data from Microsoft Exchange mailboxes. |
| T1114.002 Remote Email Collection |
GroupAPT1 | APT1 uses two utilities, GETMAIL and MAPIGET, to steal email. MAPIGET steals email still on Exchange servers that has not yet been archived. |
| T1114.002 Remote Email Collection |
GroupAPT29 | APT29 has collected emails from targeted mailboxes within a compromised Azure AD tenant and compromised Exchange servers, including via Exchange Web Services (EWS) API requests. |
| T1114.002 Remote Email Collection |
GroupChimera | Chimera has harvested data from remote mailboxes including through execution of |
| T1114.002 Remote Email Collection |
GroupStar Blizzard | Star Blizzard has remotely accessed victims' email accounts to steal messages and attachments. |
| T1114.002 Remote Email Collection |
GroupAPT28 | APT28 has collected emails from victim Microsoft Exchange servers. |
| T1114.002 Remote Email Collection |
GroupFIN4 | FIN4 has accessed and hijacked online email communications using stolen credentials. |
| T1114.002 Remote Email Collection |
GroupVOID MANTICORE | VOID MANTICORE has gathered victim email-content from victim servers. |
| T1114.002 Remote Email Collection |
GroupMagic Hound | Magic Hound has exported emails from compromised Exchange servers including through use of the cmdlet `New-MailboxExportRequest.` |
| T1114.003 Email Forwarding Rule |
GroupKimsuky | Kimsuky has set auto-forward rules on victim's e-mail accounts. |
| T1114.003 Email Forwarding Rule |
GroupScattered Spider | Scattered Spider has redirected emails notifying users of suspicious account activity. |
| T1114.003 Email Forwarding Rule |
GroupSilent Librarian | Silent Librarian has set up auto forwarding rules on compromised e-mail accounts. |
| T1114.003 Email Forwarding Rule |
GroupStar Blizzard | Star Blizzard has abused email forwarding rules to monitor the activities of a victim, steal information, and maintain persistent access after compromised credentials are reset. |
| T1114.003 Email Forwarding Rule |
GroupLAPSUS$ | LAPSUS$ has set an Office 365 tenant level mail transport rule to send all mail in and out of the targeted organization to the newly created account. |
| T1115 Clipboard Data |
GroupAPT38 | APT38 used a Trojan called KEYLIME to collect data from the clipboard. |
| T1115 Clipboard Data |
GroupKimsuky | Kimsuky has the ability to steal data from the clipboard. |
| T1115 Clipboard Data |
GroupAPT39 | APT39 has used tools capable of stealing contents of the clipboard. |
| T1115 Clipboard Data |
GroupOilRig | OilRig has used infostealer tools to copy clipboard data. |
| T1119 Automated Collection |
GroupPatchwork | Patchwork developed a file stealer to search C:\ and collect files with certain extensions. Patchwork also executed a script to enumerate all drives, store them as a list, and upload generated files to the C2 server. |
| T1119 Automated Collection |
GroupmenuPass | menuPass has used the Csvde tool to collect Active Directory files and data. |
| T1119 Automated Collection |
GroupHAFNIUM | HAFNIUM has used MSGraph to exfiltrate data from email, OneDrive, and SharePoint. |
| T1119 Automated Collection |
GroupFIN6 | FIN6 has used a script to iterate through a list of compromised PoS systems, copy and remove data to a log file, and to bind to events from the submit payment button. |
| T1119 Automated Collection |
GroupGamaredon Group | Gamaredon Group has deployed scripts on compromised systems that automatically scan for interesting documents. |
| T1119 Automated Collection |
GroupSidewinder | Sidewinder has used tools to automatically collect system and network configuration information. |
| T1119 Automated Collection |
GroupMustang Panda | Mustang Panda used custom batch scripts to collect files automatically from a targeted system. |
| T1119 Automated Collection |
GroupOilRig | OilRig has used automated collection. |
| T1119 Automated Collection |
GroupTropic Trooper | Tropic Trooper has collected information automatically using the adversary's USBferry attack. |
| T1119 Automated Collection |
GroupKe3chang | Ke3chang has performed frequent and scheduled data collection from victim networks. |
| T1119 Automated Collection |
GroupAPT1 | APT1 used a batch script to perform a series of discovery techniques and saves it to a text file. |
| T1119 Automated Collection |
GroupConfucius | Confucius has used a file stealer to steal documents and images with the following extensions: txt, pdf, png, jpg, doc, xls, xlm, odp, ods, odt, rtf, ppt, xlsx, xlsm, docx, pptx, and jpeg. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.