ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1039
Data from Network Shared Drive
CampaignC0015

During C0015, the threat actors collected files from network shared drives prior to network encryption.

T1039
Data from Network Shared Drive
GroupmenuPass

menuPass has collected data from remote systems by mounting network shares with net use and using Robocopy to transfer data.

T1039
Data from Network Shared Drive
GroupGamaredon Group

Gamaredon Group malware has collected Microsoft Office documents from mapped network drives.

T1039
Data from Network Shared Drive
GroupRedCurl

RedCurl has collected data about network drives.

T1039
Data from Network Shared Drive
GroupChimera

Chimera has collected data of interest from network shares.

T1039
Data from Network Shared Drive
GroupBRONZE BUTLER

BRONZE BUTLER has exfiltrated files stolen from file shares.

T1039
Data from Network Shared Drive
GroupAPT28

APT28 has collected files from network shared drives.

T1039
Data from Network Shared Drive
GroupFox Kitten

Fox Kitten has searched network shares to access sensitive documents.

T1039
Data from Network Shared Drive
GroupSowbug

Sowbug extracted Word documents from a file server on a victim network.

T1039
Data from Network Shared Drive
MalwareCosmicDuke

CosmicDuke steals user files from network shared drives with file extensions and keywords that match a predefined list.

T1039
Data from Network Shared Drive
MalwareRamsay

Ramsay can collect data from network drives and stage it for exfiltration.

T1039
Data from Network Shared Drive
MalwareEgregor

Egregor can collect any files found in the enumerated drivers before sending it to its C2 channel.

T1039
Data from Network Shared Drive
MalwareBADNEWS

When it first starts, BADNEWS crawls the victim's mapped drives and collects documents with the following extensions: .doc, .docx, .pdf, .ppt, .pptx, and .txt.

T1040
Network Sniffing
CampaignRedPenguin

During RedPenguin, UNC3886 used a passive backdoor to act as a libpcap-based packet sniffer.

T1040
Network Sniffing
Campaign2015 Ukraine Electric Power Attack

During the 2015 Ukraine Electric Power Attack, Sandworm Team used BlackEnergy’s network sniffer module to discover user credentials being sent over the network between the local LAN and the power grid’s industrial control systems.

T1040
Network Sniffing
CampaignArcaneDoor

ArcaneDoor included network packet capture and sniffing for data collection in victim environments.

T1040
Network Sniffing
GroupKimsuky

Kimsuky has used the Nirsoft SniffPass network sniffer to obtain passwords sent over non-secure protocols.

T1040
Network Sniffing
GroupSalt Typhoon

Salt Typhoon has used a variety of tools and techniques to capture packet data between network interfaces.

T1040
Network Sniffing
GroupSandworm Team

Sandworm Team has used intercepter-NG to sniff passwords in network traffic.

T1040
Network Sniffing
GroupUNC3886

UNC3886 has used the LOOKOVER sniffer to sniff TACACS+ authentication packets.

T1040
Network Sniffing
GroupDarkVishnya

DarkVishnya used network sniffing to obtain login data.

T1040
Network Sniffing
GroupAPT28

APT28 deployed the open source tool Responder to conduct NetBIOS Name Service poisoning, which captured usernames and hashed passwords that allowed access to legitimate credentials. APT28 close-access teams have used Wi-Fi pineapples to intercept Wi-Fi signals and user credentials.

T1040
Network Sniffing
GroupVelvet Ant

Velvet Ant has used a custom tool, "VELVETTAP", to perform packet capture from compromised F5 BIG-IP devices.

T1040
Network Sniffing
GroupAPT33

APT33 has used SniffPass to collect credentials by sniffing network traffic.

T1040
Network Sniffing
Malwarecd00r

cd00r can use the libpcap library to monitor captured packets for specifc sequences.

T1040
Network Sniffing
MalwareJumbledPath

JumbledPath has the ability to perform packet capture on remote devices via actor-defined jump-hosts.

T1040
Network Sniffing
MalwareVersaMem

VersaMem hooked the Catalina application filter chain `doFilter` on compromised systems to monitor all inbound requests to the local Tomcat web server, inspecting them for parameters like passwords and follow-on Java modules.

T1040
Network Sniffing
MalwareCASTLETAP

CASTLETAP has the ability to create a raw promiscuous socket to sniff network traffic.

T1040
Network Sniffing
MalwareJ-magic

J-magic has a pcap listener function that can create an Extended Berkley Packet Filter (eBPF) on designated interfaces and ports.

T1040
Network Sniffing
MalwareEmotet

Emotet has been observed to hook network APIs to monitor network traffic.

T1040
Network Sniffing
MalwareRegin

Regin appears to have functionality to sniff for credentials passed over HTTP, SMTP, and SMB.

T1040
Network Sniffing
MalwareLine Dancer

Line Dancer can create and exfiltrate packet captures from compromised environments.

T1040
Network Sniffing
MalwareFoggyWeb

FoggyWeb can configure custom listeners to passively monitor all incoming HTTP GET and POST requests sent to the AD FS server from the intranet/internet and intercept HTTP requests that match the custom URI patterns defined by the actor.

T1040
Network Sniffing
MalwareMESSAGETAP

MESSAGETAP uses the libpcap library to listen to all traffic and parses network protocols starting with Ethernet and IP layers. It continues parsing protocol layers including SCTP, SCCP, and TCAP and finally extracts SMS message data and routing metadata.

T1040
Network Sniffing
MalwarePenquin

Penquin can sniff network traffic to look for packets matching specific conditions.

T1040
Network Sniffing
MalwareSPAWNCHIMERA

SPAWNCHIMERA has monitored and filtered network traffic on compromised edge devices, allowing legitimate traffic to pass while redirecting attacker-controlled traffic to infrastructure under adversary control.

T1040
Network Sniffing
ToolImpacket

Impacket can be used to sniff network traffic via an interface or raw socket.

T1040
Network Sniffing
ToolEmpire

Empire can be used to conduct packet captures on target hosts.

T1040
Network Sniffing
ToolPoshC2

PoshC2 contains a module for taking packet captures on compromised hosts.

T1040
Network Sniffing
ToolResponder

Responder captures hashes and credentials that are sent to the system after the name services have been poisoned.

T1040
Network Sniffing
ToolNBTscan

NBTscan can dump and print whole packet content.

T1041
Exfiltration Over C2 Channel
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group exfiltrated data from a compromised host to actor-controlled C2 servers.

T1041
Exfiltration Over C2 Channel
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors exfiltrated stolen credentials and internal data over HTTPS to C2 infrastructure.

T1041
Exfiltration Over C2 Channel
CampaignFrankenstein

During Frankenstein, the threat actors collected information via Empire, which sent the data back to the adversary's C2.

T1041
Exfiltration Over C2 Channel
CampaignRedPenguin

During RedPenguin, UNC3886 uploaded specified files from compromised devices to a remote server.

T1041
Exfiltration Over C2 Channel
CampaignOperation Honeybee

During Operation Honeybee, the threat actors uploaded stolen files to their C2 servers.

T1041
Exfiltration Over C2 Channel
CampaignHomeLand Justice

During HomeLand Justice, threat actors used HTTP to transfer data from compromised Exchange servers.

T1041
Exfiltration Over C2 Channel
CampaignArcaneDoor

ArcaneDoor included use of existing command and control channels for data exfiltration.

T1041
Exfiltration Over C2 Channel
CampaignOperation Wocao

During Operation Wocao, threat actors used the XServer backdoor to exfiltrate data.

T1041
Exfiltration Over C2 Channel
CampaignLeviathan Australian Intrusions

Leviathan exfiltrated collected data over existing command and control channels during Leviathan Australian Intrusions.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.