Real-world descriptions of how a group, tool or campaign used a technique.
1146 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1046 Network Service Discovery |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries utilized Ping, the Advanced Port Scanner and Advanced IP Scanner to enumerate network devices. |
| T1046 Network Service Discovery |
CampaignOperation Wocao | During Operation Wocao, threat actors scanned for open ports and used nbtscan to find NETBIOS nameservers. |
| T1046 Network Service Discovery |
CampaignC0027 | During C0027, used RustScan to scan for open ports on targeted ESXi appliances. |
| T1046 Network Service Discovery |
CampaignCostaRicto | During CostaRicto, the threat actors employed nmap and pscan to scan target environments. |
| T1047 Windows Management Instrumentation |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group used WMIC to executed a remote XSL script. |
| T1047 Windows Management Instrumentation |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors used WMI for execution. |
| T1047 Windows Management Instrumentation |
CampaignFrankenstein | During Frankenstein, the threat actors used WMI queries to check if various security applications were running as well as to determine the operating system version. |
| T1047 Windows Management Instrumentation |
CampaignC0018 | During C0018, the threat actors used WMIC to modify administrative settings on both a local and a remote host, likely as part of the first stages for their lateral movement; they also used WMI Provider Host (`wmiprvse.exe`) to execute a variety of encoded PowerShell scripts using the `DownloadString` method. |
| T1047 Windows Management Instrumentation |
CampaignC0015 | During C0015, the threat actors used `wmic` and `rundll32` to load Cobalt Strike onto a target host. |
| T1047 Windows Management Instrumentation |
CampaignHomeLand Justice | During HomeLand Justice, threat actors used WMI to modify Windows Defender settings. |
| T1047 Windows Management Instrumentation |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used WMI for the remote execution of files for lateral movement. |
| T1047 Windows Management Instrumentation |
CampaignOperation AkaiRyū | During Operation AkaiRyū, MirrorFace used WMI to proxy execution of UPPERCUT. |
| T1047 Windows Management Instrumentation |
CampaignFunnyDream | During FunnyDream, the threat actors used `wmiexec.vbs` to run remote commands. |
| T1047 Windows Management Instrumentation |
Campaign2016 Ukraine Electric Power Attack | During the 2016 Ukraine Electric Power Attack, WMI in scripts were used for remote execution and system surveys. |
| T1047 Windows Management Instrumentation |
CampaignOperation Wocao | During Operation Wocao, threat actors has used WMI to execute commands. |
| T1047 Windows Management Instrumentation |
CampaignC0027 | During C0027, Scattered Spider used Windows Management Instrumentation (WMI) to move laterally via Impacket. |
| T1048.002 Exfiltration Over Asymmetric Encrypted Non-C2 Protocol |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 exfiltrated collected data over a simple HTTPS request to a password-protected archive staged on a victim's OWA servers. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries exfiltrated data to an actor-controlled infrastructure using HTTP POSTs. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
CampaignC0017 | During C0017, APT41 exfiltrated victim data via DNS lookups by encoding and prepending it as subdomains to the attacker-controlled domain. |
| T1049 System Network Connections Discovery |
CampaignAnthropic AI-orchestrated Campaign | During the Anthropic AI-orchestrated Campaign, the adversary used Claude Code to map internal network architecture and access relationships. |
| T1049 System Network Connections Discovery |
CampaignFunnyDream | During FunnyDream, the threat actors used netstat to discover network connections on remote systems. |
| T1049 System Network Connections Discovery |
CampaignOperation CuckooBees | During Operation CuckooBees, the threat actors used the `net session`, `net use`, and `netstat` commands as part of their advanced reconnaissance. |
| T1049 System Network Connections Discovery |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries identified network connections utilizing `netstat -nao` and `netstat -r`. |
| T1049 System Network Connections Discovery |
CampaignOperation Wocao | During Operation Wocao, threat actors collected a list of open connections on the infected system using `netstat` and checks whether it has an internet connection. |
| T1053 Scheduled Task/Job |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries set FortiGate scheduled tasks to run the adversary generated CLI scripts weekly. |
| T1053.003 Cron |
CampaignOperation MidnightEclipse | During Operation MidnightEclipse, threat actors configured cron jobs to retrieve payloads from actor-controlled infrastructure. |
| T1053.005 Scheduled Task |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group created scheduled tasks to set a periodic execution of a remote XSL script. |
| T1053.005 Scheduled Task |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors used scheduled tasks to help establish persistence. |
| T1053.005 Scheduled Task |
CampaignFrankenstein | During Frankenstein, the threat actors established persistence through a scheduled task using the command: `/Create /F /SC DAILY /ST 09:00 /TN WinUpdate /TR`, named "WinUpdate" |
| T1053.005 Scheduled Task |
CampaignTriton Safety Instrumented System Attack | In the Triton Safety Instrumented System Attack, TEMP.Veles installed scheduled tasks defined in XML files. |
| T1053.005 Scheduled Task |
CampaignJuicy Mix | During Juicy Mix, OilRig used VBS droppers to schedule tasks for persistence. |
| T1053.005 Scheduled Task |
CampaignC0032 | During the C0032 campaign, TEMP.Veles used scheduled task XML triggers. |
| T1053.005 Scheduled Task |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used `scheduler` and `schtasks` to create new tasks on remote host as part of their lateral movement. They manipulated scheduled tasks by updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration. APT29 also created a scheduled task to maintain SUNSPOT persistence when the host booted. |
| T1053.005 Scheduled Task |
CampaignOperation CuckooBees | During Operation CuckooBees, the threat actors used scheduled tasks to execute batch scripts for lateral movement with the following command: `SCHTASKS /Create /S <IP Address> /U <Username> /p <Password> /SC ONCE /TN test /TR <Path to a Batch File> /ST <Time> /RU SYSTEM.` |
| T1053.005 Scheduled Task |
CampaignOperation Wocao | During Operation Wocao, threat actors used scheduled tasks to execute malicious PowerShell code on remote systems. |
| T1053.005 Scheduled Task |
CampaignC0017 | During C0017, APT41 used the following Windows scheduled tasks for DEADEYE dropper persistence on US state government networks: `\Microsoft\Windows\PLA\Server Manager Performance Monitor`, `\Microsoft\Windows\Ras\ManagerMobility`, `\Microsoft\Windows\WDI\SrvSetupResults`, and `\Microsoft\Windows\WDI\USOShared`. |
| T1053.005 Scheduled Task |
Campaign2022 Ukraine Electric Power Attack | During the 2022 Ukraine Electric Power Attack, Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time. |
| T1053.005 Scheduled Task |
CampaignCostaRicto | During CostaRicto, the threat actors used scheduled tasks to download backdoor tools. |
| T1055 Process Injection |
CampaignRedPenguin | During RedPenguin, UNC3886 exploited CVE-2025-21590 to enable malicious code injection into the memory of legitimate processes. |
| T1055 Process Injection |
CampaignOperation Sharpshooter | During Operation Sharpshooter, threat actors leveraged embedded shellcode to inject a downloader into the memory of Word. |
| T1055 Process Injection |
Campaign2015 Ukraine Electric Power Attack | During the 2015 Ukraine Electric Power Attack, Sandworm Team loaded BlackEnergy into svchost.exe, which then launched iexplore.exe for their C2. |
| T1055 Process Injection |
Campaign3CX Supply Chain Attack | During the 3CX Supply Chain Attack, AppleJeus's VEILEDSIGNAL uses process injection to inject the C2 communication module code in the first found process instance of Chrome, Firefox, or Edge web browsers. It also monitors the established named pipe and re-injects the C2 communication module if necessary. |
| T1055 Process Injection |
CampaignCutting Edge | During Cutting Edge, threat actors used malicious SparkGateway plugins to inject shared objects into web process memory on compromised Ivanti Secure Connect VPNs to enable deployment of backdoors. |
| T1055 Process Injection |
CampaignArcaneDoor | ArcaneDoor included injecting code into the AAA and Crash Dump processes on infected Cisco ASA devices. |
| T1055 Process Injection |
CampaignOperation Wocao | During Operation Wocao, threat actors injected code into a selected process, which in turn launches a command as a child process of the original. |
| T1055.001 Dynamic-link Library Injection |
CampaignC0015 | During C0015, the threat actors used a DLL named `D8B3.dll` that was injected into the Winlogon process. |
| T1055.002 Portable Executable Injection |
Campaign3CX Supply Chain Attack | During the 3CX Supply Chain Attack, AppleJeus uses the SigFlip tool to inject arbitrary code without affecting or breaking the file's signature. |
| T1055.009 Proc Memory |
CampaignKV Botnet Activity | KV Botnet Activity final payload installation includes mounting and binding to the |
| T1056 Input Capture |
CampaignVersa Director Zero Day Exploitation | Versa Director Zero Day Exploitation intercepted and harvested credentials from user logins to compromised devices. |
| T1056 Input Capture |
CampaignLeviathan Australian Intrusions | Leviathan captured submitted multfactor authentication codes and other technical artifacts related to remote access sessions during Leviathan Australian Intrusions. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.