Real-world descriptions of how a group, tool or campaign used a technique.
4628 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1213.002 Sharepoint |
GroupAkira | Akira has accessed and downloaded information stored in SharePoint instances as part of data gathering and exfiltration activity. |
| T1213.002 Sharepoint |
GroupKe3chang | Ke3chang used a SharePoint enumeration and data dumping tool known as spwebmember. |
| T1213.002 Sharepoint |
GroupChimera | Chimera has collected documents from the victim's SharePoint. |
| T1213.002 Sharepoint |
GroupAPT28 | APT28 has collected information from Microsoft SharePoint services within target networks. |
| T1213.002 Sharepoint |
GroupLAPSUS$ | LAPSUS$ has searched a victim's network for collaboration platforms like SharePoint to discover further high-privilege account credentials. |
| T1213.002 Sharepoint |
GroupVOID MANTICORE | VOID MANTICORE has accessed victim’s public facing SharePoint servers and exfiltrated data. |
| T1213.003 Code Repositories |
GroupAPT41 | APT41 cloned victim user Git repositories during intrusions. |
| T1213.003 Code Repositories |
GroupScattered Spider | Scattered Spider enumerates data stored within victim code repositories, such as internal GitHub repositories. |
| T1213.003 Code Repositories |
GroupLAPSUS$ | LAPSUS$ has searched a victim's network for code repositories like GitLab and GitHub to discover further high-privilege account credentials. |
| T1213.003 Code Repositories |
GroupShinyHunters | ShinyHunters has gathered information from and has searched for vulnerabilities in the target company’s GitHub repository source code. |
| T1213.005 Messaging Applications |
GroupScattered Spider | Scattered Spider threat actors search the victim’s Slack and Microsoft Teams for conversations about the intrusion and incident response. |
| T1213.005 Messaging Applications |
GroupFox Kitten | Fox Kitten has accessed victim security and IT environments and Microsoft Teams to mine valuable information. |
| T1213.005 Messaging Applications |
GroupLAPSUS$ | LAPSUS$ has searched a victim's network for organization collaboration channels like MS Teams or Slack to discover further high-privilege account credentials. |
| T1213.006 Databases |
GroupFIN6 | FIN6 has collected schemas and user accounts from systems running SQL Server. |
| T1213.006 Databases |
GroupSandworm Team | Sandworm Team exfiltrates data of interest from enterprise databases using Adminer. |
| T1213.006 Databases |
GroupSea Turtle | Sea Turtle used the tool Adminer to remotely logon to the MySQL service of victim machines. |
| T1213.006 Databases |
GroupTurla | Turla has used a custom .NET tool to collect documents from an organization's internal central database. |
| T1213.006 Databases |
GroupShinyHunters | ShinyHunters has collected Salesforce datasets from victims in the airline and retail sectors. |
| T1216.001 PubPrn |
GroupAPT32 | APT32 has used PubPrn.vbs within execution scripts to execute malware, possibly bypassing defenses. |
| T1217 Browser Information Discovery |
GroupAPT38 | APT38 has collected browser bookmark information to learn more about compromised hosts, obtain personal information about users, and acquire details about internal network resources. |
| T1217 Browser Information Discovery |
GroupKimsuky | Kimsuky has collected sensitive browser data using the function `GetBrowserData()` to include login credentials, bookmarks, cookies, and encryption keys. |
| T1217 Browser Information Discovery |
GroupVolt Typhoon | Volt Typhoon has targeted the browsing history of network administrators. |
| T1217 Browser Information Discovery |
GroupScattered Spider | Scattered Spider retrieves browser histories via infostealer malware such as Raccoon Stealer. |
| T1217 Browser Information Discovery |
GroupChimera | Chimera has used |
| T1217 Browser Information Discovery |
GroupFox Kitten | Fox Kitten has used Google Chrome bookmarks to identify internal resources and assets. |
| T1217 Browser Information Discovery |
GroupMoonstone Sleet | Moonstone Sleet deployed malware such as YouieLoader capable of capturing victim system browser information. |
| T1218 System Binary Proxy Execution |
GroupVolt Typhoon | Volt Typhoon has used native tools and processes including living off the land binaries or “LOLBins" to maintain and expand access to the victim networks. |
| T1218 System Binary Proxy Execution |
GroupLazarus Group | Lazarus Group lnk files used for persistence have abused the Windows Update Client ( |
| T1218.001 Compiled HTML File |
GroupAPT38 | APT38 has used CHM files to move concealed payloads. |
| T1218.001 Compiled HTML File |
GroupAPT41 | APT41 used compiled HTML (.chm) files for targeting. |
| T1218.001 Compiled HTML File |
GroupOilRig | OilRig has used a CHM payload to load and execute another malicious file once delivered to a victim. |
| T1218.001 Compiled HTML File |
GroupDark Caracal | Dark Caracal leveraged a compiled HTML file that contained a command to download and run an executable. |
| T1218.001 Compiled HTML File |
GroupSilence | Silence has weaponized CHM files in their phishing campaigns. |
| T1218.003 CMSTP |
GroupMuddyWater | MuddyWater has used CMSTP.exe and a malicious INF to execute its POWERSTATS payload. |
| T1218.003 CMSTP |
GroupCobalt Group | Cobalt Group has used the command |
| T1218.004 InstallUtil |
GroupmenuPass | menuPass has used |
| T1218.004 InstallUtil |
GroupMustang Panda | Mustang Panda has used |
| T1218.005 Mshta |
GroupAPT38 | APT38 has used a renamed version of `mshta.exe` to execute malicious HTML files. |
| T1218.005 Mshta |
GroupSideCopy | SideCopy has utilized `mshta.exe` to execute a malicious hta file. |
| T1218.005 Mshta |
GroupKimsuky | Kimsuky has used mshta.exe to run malicious scripts on the system. |
| T1218.005 Mshta |
GroupAPT32 | APT32 has used mshta.exe for code execution. |
| T1218.005 Mshta |
GroupMuddyWater | MuddyWater has used mshta.exe to execute its POWERSTATS payload and to pass a PowerShell one-liner for execution. |
| T1218.005 Mshta |
GroupGamaredon Group | Gamaredon Group has used `mshta.exe` to execute malicious files. |
| T1218.005 Mshta |
GroupFIN7 | FIN7 has used mshta.exe to execute VBScript to execute malicious code on victim systems. |
| T1218.005 Mshta |
GroupSidewinder | Sidewinder has used |
| T1218.005 Mshta |
GroupMustang Panda | Mustang Panda has used mshta.exe to launch collection scripts. |
| T1218.005 Mshta |
GroupTA2541 | TA2541 has used `mshta` to execute scripts including VBS. |
| T1218.005 Mshta |
GroupConfucius | Confucius has used mshta.exe to execute malicious VBScript. |
| T1218.005 Mshta |
GroupAPT29 | APT29 has use `mshta` to execute malicious scripts on a compromised host. |
| T1218.005 Mshta |
GroupTA551 | TA551 has used mshta.exe to execute malicious payloads. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.