ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

1146 examples

TechniqueUsed byProcedure example
T1046
Network Service Discovery
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries utilized Ping, the Advanced Port Scanner and Advanced IP Scanner to enumerate network devices.

T1046
Network Service Discovery
CampaignOperation Wocao

During Operation Wocao, threat actors scanned for open ports and used nbtscan to find NETBIOS nameservers.

T1046
Network Service Discovery
CampaignC0027

During C0027, used RustScan to scan for open ports on targeted ESXi appliances.

T1046
Network Service Discovery
CampaignCostaRicto

During CostaRicto, the threat actors employed nmap and pscan to scan target environments.

T1047
Windows Management Instrumentation
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group used WMIC to executed a remote XSL script.

T1047
Windows Management Instrumentation
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors used WMI for execution.

T1047
Windows Management Instrumentation
CampaignFrankenstein

During Frankenstein, the threat actors used WMI queries to check if various security applications were running as well as to determine the operating system version.

T1047
Windows Management Instrumentation
CampaignC0018

During C0018, the threat actors used WMIC to modify administrative settings on both a local and a remote host, likely as part of the first stages for their lateral movement; they also used WMI Provider Host (`wmiprvse.exe`) to execute a variety of encoded PowerShell scripts using the `DownloadString` method.

T1047
Windows Management Instrumentation
CampaignC0015

During C0015, the threat actors used `wmic` and `rundll32` to load Cobalt Strike onto a target host.

T1047
Windows Management Instrumentation
CampaignHomeLand Justice

During HomeLand Justice, threat actors used WMI to modify Windows Defender settings.

T1047
Windows Management Instrumentation
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used WMI for the remote execution of files for lateral movement.

T1047
Windows Management Instrumentation
CampaignOperation AkaiRyū

During Operation AkaiRyū, MirrorFace used WMI to proxy execution of UPPERCUT.

T1047
Windows Management Instrumentation
CampaignFunnyDream

During FunnyDream, the threat actors used `wmiexec.vbs` to run remote commands.

T1047
Windows Management Instrumentation
Campaign2016 Ukraine Electric Power Attack

During the 2016 Ukraine Electric Power Attack, WMI in scripts were used for remote execution and system surveys.

T1047
Windows Management Instrumentation
CampaignOperation Wocao

During Operation Wocao, threat actors has used WMI to execute commands.

T1047
Windows Management Instrumentation
CampaignC0027

During C0027, Scattered Spider used Windows Management Instrumentation (WMI) to move laterally via Impacket.

T1048.002
Exfiltration Over Asymmetric Encrypted Non-C2 Protocol
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 exfiltrated collected data over a simple HTTPS request to a password-protected archive staged on a victim's OWA servers.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries exfiltrated data to an actor-controlled infrastructure using HTTP POSTs.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
CampaignC0017

During C0017, APT41 exfiltrated victim data via DNS lookups by encoding and prepending it as subdomains to the attacker-controlled domain.

T1049
System Network Connections Discovery
CampaignAnthropic AI-orchestrated Campaign

During the Anthropic AI-orchestrated Campaign, the adversary used Claude Code to map internal network architecture and access relationships.

T1049
System Network Connections Discovery
CampaignFunnyDream

During FunnyDream, the threat actors used netstat to discover network connections on remote systems.

T1049
System Network Connections Discovery
CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors used the `net session`, `net use`, and `netstat` commands as part of their advanced reconnaissance.

T1049
System Network Connections Discovery
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries identified network connections utilizing `netstat -nao` and `netstat -r`.

T1049
System Network Connections Discovery
CampaignOperation Wocao

During Operation Wocao, threat actors collected a list of open connections on the infected system using `netstat` and checks whether it has an internet connection.

T1053
Scheduled Task/Job
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries set FortiGate scheduled tasks to run the adversary generated CLI scripts weekly.

T1053.003
Cron
CampaignOperation MidnightEclipse

During Operation MidnightEclipse, threat actors configured cron jobs to retrieve payloads from actor-controlled infrastructure.

T1053.005
Scheduled Task
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group created scheduled tasks to set a periodic execution of a remote XSL script.

T1053.005
Scheduled Task
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors used scheduled tasks to help establish persistence.

T1053.005
Scheduled Task
CampaignFrankenstein

During Frankenstein, the threat actors established persistence through a scheduled task using the command: `/Create /F /SC DAILY /ST 09:00 /TN WinUpdate /TR`, named "WinUpdate"

T1053.005
Scheduled Task
CampaignTriton Safety Instrumented System Attack

In the Triton Safety Instrumented System Attack, TEMP.Veles installed scheduled tasks defined in XML files.

T1053.005
Scheduled Task
CampaignJuicy Mix

During Juicy Mix, OilRig used VBS droppers to schedule tasks for persistence.

T1053.005
Scheduled Task
CampaignC0032

During the C0032 campaign, TEMP.Veles used scheduled task XML triggers.

T1053.005
Scheduled Task
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used `scheduler` and `schtasks` to create new tasks on remote host as part of their lateral movement. They manipulated scheduled tasks by updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration. APT29 also created a scheduled task to maintain SUNSPOT persistence when the host booted.

T1053.005
Scheduled Task
CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors used scheduled tasks to execute batch scripts for lateral movement with the following command: `SCHTASKS /Create /S <IP Address> /U <Username> /p <Password> /SC ONCE /TN test /TR <Path to a Batch File> /ST <Time> /RU SYSTEM.`

T1053.005
Scheduled Task
CampaignOperation Wocao

During Operation Wocao, threat actors used scheduled tasks to execute malicious PowerShell code on remote systems.

T1053.005
Scheduled Task
CampaignC0017

During C0017, APT41 used the following Windows scheduled tasks for DEADEYE dropper persistence on US state government networks: `\Microsoft\Windows\PLA\Server Manager Performance Monitor`, `\Microsoft\Windows\Ras\ManagerMobility`, `\Microsoft\Windows\WDI\SrvSetupResults`, and `\Microsoft\Windows\WDI\USOShared`.

T1053.005
Scheduled Task
Campaign2022 Ukraine Electric Power Attack

During the 2022 Ukraine Electric Power Attack, Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.

T1053.005
Scheduled Task
CampaignCostaRicto

During CostaRicto, the threat actors used scheduled tasks to download backdoor tools.

T1055
Process Injection
CampaignRedPenguin

During RedPenguin, UNC3886 exploited CVE-2025-21590 to enable malicious code injection into the memory of legitimate processes.

T1055
Process Injection
CampaignOperation Sharpshooter

During Operation Sharpshooter, threat actors leveraged embedded shellcode to inject a downloader into the memory of Word.

T1055
Process Injection
Campaign2015 Ukraine Electric Power Attack

During the 2015 Ukraine Electric Power Attack, Sandworm Team loaded BlackEnergy into svchost.exe, which then launched iexplore.exe for their C2.

T1055
Process Injection
Campaign3CX Supply Chain Attack

During the 3CX Supply Chain Attack, AppleJeus's VEILEDSIGNAL uses process injection to inject the C2 communication module code in the first found process instance of Chrome, Firefox, or Edge web browsers. It also monitors the established named pipe and re-injects the C2 communication module if necessary.

T1055
Process Injection
CampaignCutting Edge

During Cutting Edge, threat actors used malicious SparkGateway plugins to inject shared objects into web process memory on compromised Ivanti Secure Connect VPNs to enable deployment of backdoors.

T1055
Process Injection
CampaignArcaneDoor

ArcaneDoor included injecting code into the AAA and Crash Dump processes on infected Cisco ASA devices.

T1055
Process Injection
CampaignOperation Wocao

During Operation Wocao, threat actors injected code into a selected process, which in turn launches a command as a child process of the original.

T1055.001
Dynamic-link Library Injection
CampaignC0015

During C0015, the threat actors used a DLL named `D8B3.dll` that was injected into the Winlogon process.

T1055.002
Portable Executable Injection
Campaign3CX Supply Chain Attack

During the 3CX Supply Chain Attack, AppleJeus uses the SigFlip tool to inject arbitrary code without affecting or breaking the file's signature.

T1055.009
Proc Memory
CampaignKV Botnet Activity

KV Botnet Activity final payload installation includes mounting and binding to the \/proc\/ filepath on the victim system to enable subsequent operation in memory while also removing on-disk artifacts.

T1056
Input Capture
CampaignVersa Director Zero Day Exploitation

Versa Director Zero Day Exploitation intercepted and harvested credentials from user logins to compromised devices.

T1056
Input Capture
CampaignLeviathan Australian Intrusions

Leviathan captured submitted multfactor authentication codes and other technical artifacts related to remote access sessions during Leviathan Australian Intrusions.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.