ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1041
Exfiltration Over C2 Channel
MalwareGrimAgent

GrimAgent has sent data related to a compromise host over its C2 channel.

T1041
Exfiltration Over C2 Channel
MalwarePHASEJAM

PHASEJAM has the ability to exfiltrate data from the victim appliance.

T1041
Exfiltration Over C2 Channel
MalwareLokibot

Lokibot has the ability to initiate contact with command and control (C2) to exfiltrate stolen data.

T1041
Exfiltration Over C2 Channel
MalwareCallMe

CallMe exfiltrates data to its C2 server over the same protocol as C2 communications.

T1041
Exfiltration Over C2 Channel
MalwarePoetRAT

PoetRAT has exfiltrated data over the C2 channel.

T1041
Exfiltration Over C2 Channel
MalwarePenquin

Penquin can execute the command code do_upload to send files to C2.

T1041
Exfiltration Over C2 Channel
MalwareCannon

Cannon exfiltrates collected data over email via SMTP/S and POP3/S C2 channels.

T1041
Exfiltration Over C2 Channel
MalwareCreepySnail

CreepySnail can connect to C2 for data exfiltration.

T1041
Exfiltration Over C2 Channel
MalwareTroll Stealer

Troll Stealer exfiltrates collected information to its command and control infrastructure.

T1041
Exfiltration Over C2 Channel
MalwareEbury

Ebury exfiltrates a list of outbound and inbound SSH sessions using OpenSSH's `known_host` files and `wtmp` records. Ebury can exfiltrate SSH credentials through custom DNS queries or use the command `Xcat` to send the process's ssh session's credentials to the C2 server.

T1041
Exfiltration Over C2 Channel
MalwarenjRAT

njRAT has used C2 infrastructure to receive stolen information from the infected machine including screenshots and other system information.

T1041
Exfiltration Over C2 Channel
MalwareManjusaka

Manjusaka data exfiltration takes place over HTTP channels.

T1041
Exfiltration Over C2 Channel
MalwareIceApple

IceApple's Multi File Exfiltrator module can exfiltrate multiple files from a compromised host as an HTTP response over C2.

T1041
Exfiltration Over C2 Channel
MalwareShai-Hulud

Shai-Hulud has used POST to exfiltrate secrets from the victim environment to an attacker-controlled URL.

T1041
Exfiltration Over C2 Channel
MalwaremetaMain

metaMain can upload collected files and data to its C2 server.

T1041
Exfiltration Over C2 Channel
MalwareSideTwist

SideTwist has exfiltrated data over its C2 channel.

T1041
Exfiltration Over C2 Channel
MalwareMechaFlounder

MechaFlounder has the ability to send the compromised user's account name and hostname within a URL to C2.

T1041
Exfiltration Over C2 Channel
MalwarePsylo

Psylo exfiltrates data to its C2 server over the same protocol as C2 communications.

T1041
Exfiltration Over C2 Channel
MalwareMis-Type

Mis-Type has transmitted collected files and data to its C2 server.

T1041
Exfiltration Over C2 Channel
MalwareXCSSET

XCSSET retrieves files that match the pattern defined in the INAME_QUERY variable within the user's home directory, such as `*test.txt`, and are below a specific size limit. It then archives the files and exfiltrates the data over its C2 channel.

T1041
Exfiltration Over C2 Channel
MalwareOctopus

Octopus has uploaded stolen files and data from a victim's machine over its C2 channel.

T1041
Exfiltration Over C2 Channel
MalwareAppleJeus

AppleJeus has exfiltrated collected host information to a C2 server.

T1041
Exfiltration Over C2 Channel
MalwareSTARWHALE

STARWHALE can exfiltrate collected data to its C2 servers.

T1041
Exfiltration Over C2 Channel
MalwareIndustroyer

Industroyer sends information about hardware profiles and previously-received commands back to the C2 server in a POST-request.

T1041
Exfiltration Over C2 Channel
MalwareKevin

Kevin can send data from the victim host through a DNS C2 channel.

T1041
Exfiltration Over C2 Channel
MalwareGoopy

Goopy has the ability to exfiltrate data over the Microsoft Outlook C2 channel.

T1041
Exfiltration Over C2 Channel
MalwareRemexi

Remexi performs exfiltration over BITSAdmin, which is also used for the C2 channel.

T1041
Exfiltration Over C2 Channel
MalwareAstaroth

Astaroth exfiltrates collected information from its r1.log file to the external C2 server.

T1041
Exfiltration Over C2 Channel
MalwareQakBot

QakBot can send stolen information to C2 nodes including passwords, accounts, and emails.

T1041
Exfiltration Over C2 Channel
MalwareBACKSPACE

Adversaries can direct BACKSPACE to upload files to the C2 Server.

T1041
Exfiltration Over C2 Channel
MalwareADVSTORESHELL

ADVSTORESHELL exfiltrates data over the same channel used for C2.

T1041
Exfiltration Over C2 Channel
MalwareStrifeWater

StrifeWater can send data and files from a compromised host to its C2 server.

T1041
Exfiltration Over C2 Channel
MalwareWarzoneRAT

WarzoneRAT can send collected victim data to its C2 server.

T1041
Exfiltration Over C2 Channel
MalwareSLOTHFULMEDIA

SLOTHFULMEDIA has sent system information to a C2 server via HTTP and HTTPS POST requests.

T1041
Exfiltration Over C2 Channel
MalwareXORIndex Loader

XORIndex Loader has exfiltrated victim data using HTTPS POST requests to its C2 servers.

T1041
Exfiltration Over C2 Channel
ToolShimRatReporter

ShimRatReporter sent generated reports to the C2 via HTTP POST requests.

T1041
Exfiltration Over C2 Channel
ToolSliver

Sliver can exfiltrate files from the victim using the download command.

T1041
Exfiltration Over C2 Channel
ToolSILENTTRINITY

SILENTTRINITY can transfer files from an infected host to the C2 server.

T1041
Exfiltration Over C2 Channel
ToolEmpire

Empire can send data gathered from a target through the command and control channel.

T1041
Exfiltration Over C2 Channel
ToolPcShare

PcShare can upload files and information from a compromised host to its C2 servers.

T1041
Exfiltration Over C2 Channel
ToolImminent Monitor

Imminent Monitor has uploaded a file containing debugger logs, network information and system information to the C2.

T1041
Exfiltration Over C2 Channel
ToolPupy

Pupy can send screenshots files, keylogger data, files, and recorded audio back to the C2 server.

T1041
Exfiltration Over C2 Channel
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer has exfiltrated collected data to typosquat C2 domains including scan.aquasecurtiy[.]org.

T1041
Exfiltration Over C2 Channel
MalwareMini Shai-Hulud

Mini Shai-Hulud has exfiltrated encrypted archives over C2 domains.

T1046
Network Service Discovery
CampaignC0018

During C0018, the threat actors used the SoftPerfect Network Scanner for network scanning.

T1046
Network Service Discovery
CampaignAnthropic AI-orchestrated Campaign

During the Anthropic AI-orchestrated Campaign, the adversary used Claude Code to enumerate internal network services and endpoints across targeted environments using browser automation via MCP, including databases, container registries, admin interfaces, and workflow orchestration platforms.

T1046
Network Service Discovery
CampaignHomeLand Justice

During HomeLand Justice, threat actors executed the Advanced Port Scanner tool on compromised systems.

T1046
Network Service Discovery
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries utilized Ping, the Advanced Port Scanner and Advanced IP Scanner to enumerate network devices.

T1046
Network Service Discovery
CampaignOperation Wocao

During Operation Wocao, threat actors scanned for open ports and used nbtscan to find NETBIOS nameservers.

T1046
Network Service Discovery
CampaignC0027

During C0027, used RustScan to scan for open ports on targeted ESXi appliances.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.