ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

4628 examples

TechniqueUsed byProcedure example
T1119
Automated Collection
GroupWinter Vivern

Winter Vivern delivered a PowerShell script capable of recursively scanning victim machines looking for various file types before exfiltrating identified files via HTTP.

T1119
Automated Collection
GroupRedCurl

RedCurl has used batch scripts to collect data.

T1119
Automated Collection
GroupFIN5

FIN5 scans processes on all victim systems in the environment and uses automated scripts to pull back the results.

T1119
Automated Collection
GroupChimera

Chimera has used custom DLLs for continuous retrieval of data from memory.

T1119
Automated Collection
GroupEmber Bear

Ember Bear engages in mass collection from compromised systems during intrusions.

T1119
Automated Collection
GroupAgrius

Agrius used a custom tool, sql.net4.exe, to query SQL databases and then identify and extract personally identifiable information.

T1119
Automated Collection
GroupAPT28

APT28 used a publicly available tool to gather and compress multiple documents on the DCCC and DNC networks.

T1119
Automated Collection
GroupVOID MANTICORE

VOID MANTICORE conducted large-scale data exfiltration in the Stryker operation, consistent with automated or scripted collection against enterprise systems.

T1119
Automated Collection
GroupThreat Group-3390

Threat Group-3390 ran a command to compile an archive of file types of interest from the victim user's directories.

T1120
Peripheral Device Discovery
GroupVolt Typhoon

Volt Typhoon has obtained victim's screen dimension and display device information.

T1120
Peripheral Device Discovery
GroupGamaredon Group

Gamaredon Group tools have contained an application to check performance of USB flash drives. Gamaredon Group has also used malware to scan for removable drives.

T1120
Peripheral Device Discovery
GroupTeamTNT

TeamTNT has searched for attached VGA devices using lspci.

T1120
Peripheral Device Discovery
GroupAPT37

APT37 has a Bluetooth device harvester, which uses Windows Bluetooth APIs to find information on connected Bluetooth devices.

T1120
Peripheral Device Discovery
GroupOilRig

OilRig has used tools to identify if a mouse is connected to a targeted system.

T1120
Peripheral Device Discovery
GroupTurla

Turla has used fsutil fsinfo drives to list connected drives.

T1120
Peripheral Device Discovery
GroupEquation

Equation has used tools with the functionality to search for specific information about the attached hard drive that could be used to identify and overwrite the firmware.

T1120
Peripheral Device Discovery
GroupBackdoorDiplomacy

BackdoorDiplomacy has used an executable to detect removable media, such as USB flash drives.

T1120
Peripheral Device Discovery
GroupAPT28

APT28 uses a module to receive a notification every time a USB mass storage device is inserted into a victim.

T1123
Audio Capture
GroupAPT37

APT37 has used an audio capturing utility known as SOUNDWAVE that captures microphone input.

T1123
Audio Capture
GroupVOID MANTICORE

VOID MANTICORE has gathered audio during a Zoom session.

T1124
System Time Discovery
GroupKimsuky

Kimsuky has gathered the system time of the device using the PowerShell cmdlet `Get-Date`.

T1124
System Time Discovery
GroupVolt Typhoon

Volt Typhoon has obtained the victim's system timezone.

T1124
System Time Discovery
GroupFIN7

FIN7 has used the PowerShell script 3CF9.ps1 to execute `net time`.

T1124
System Time Discovery
GroupCURIUM

CURIUM deployed mechanisms to check system time information following strategic website compromise attacks.

T1124
System Time Discovery
GroupSidewinder

Sidewinder has used tools to obtain the current system time.

T1124
System Time Discovery
GroupZIRCONIUM

ZIRCONIUM has used a tool to capture the time on a compromised host in order to register it with C2.

T1124
System Time Discovery
GroupUNC3886

UNC3886 has used installation scripts to collect the system time on targeted ESXi hosts.

T1124
System Time Discovery
GroupHigaisa

Higaisa used a function to gather the current time.

T1124
System Time Discovery
GroupThe White Company

The White Company has checked the current date on the victim system.

T1124
System Time Discovery
GroupTurla

Turla surveys a system upon check-in to discover the system time by using the net time command.

T1124
System Time Discovery
GroupChimera

Chimera has used time /t and net time \\ip/hostname for system time discovery.

T1124
System Time Discovery
GroupBRONZE BUTLER

BRONZE BUTLER has used net time to check the local time on a target system.

T1124
System Time Discovery
GroupDarkhotel

Darkhotel malware can obtain system time from a compromised host.

T1124
System Time Discovery
GroupLazarus Group

A Destover-like implant used by Lazarus Group can obtain the current system time and send it to the C2 server.

T1125
Video Capture
GroupFIN7

FIN7 created a custom video recording capability that could be used to monitor operations in the victim's environment.

T1125
Video Capture
GroupEmber Bear

Ember Bear has exfiltrated images from compromised IP cameras.

T1125
Video Capture
GroupSilence

Silence has been observed making videos of victims to observe bank employees day to day activities.

T1125
Video Capture
GroupVOID MANTICORE

VOID MANTICORE has collected video from compromised victim devices.

T1129
Shared Modules
GroupMustang Panda

Mustang Panda has leveraged `LoadLibrary` to load DLLs.

T1132
Data Encoding
GroupVelvet Ant

Velvet Ant sent commands to compromised F5 BIG-IP devices in an encoded format requiring a passkey before interpretation and execution.

T1132.001
Standard Encoding
GroupPatchwork

Patchwork used Base64 to encode C2 traffic.

T1132.001
Standard Encoding
GroupHAFNIUM

HAFNIUM has used ASCII encoding for C2 traffic.

T1132.001
Standard Encoding
GroupMuddyWater

MuddyWater has used tools to encode C2 communications including Base64 encoding.

T1132.001
Standard Encoding
GroupSandworm Team

Sandworm Team's BCS-server tool uses base64 encoding and HTML tags for the communication traffic between the C2 server.

T1132.001
Standard Encoding
GroupTropic Trooper

Tropic Trooper has used base64 encoding to hide command strings delivered from the C2.

T1132.001
Standard Encoding
GroupBRONZE BUTLER

Several BRONZE BUTLER tools encode data with base64 when posting it to a C2 server.

T1132.001
Standard Encoding
GroupTA551

TA551 has used encoded ASCII text for initial C2 communications.

T1132.001
Standard Encoding
GroupAPT42

APT42 has encoded C2 traffic with Base64.

T1132.001
Standard Encoding
GroupLazarus Group

A Lazarus Group malware sample encodes data with base64.

T1132.001
Standard Encoding
GroupAPT33

APT33 has used base64 to encode command and control traffic.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.