Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1047 Windows Management Instrumentation |
MalwareQakBot | QakBot can execute WMI queries to gather information. |
| T1047 Windows Management Instrumentation |
MalwarejRAT | jRAT uses WMIC to identify anti-virus products installed on the victim’s machine and to obtain firewall details. |
| T1047 Windows Management Instrumentation |
MalwareINC Ransomware | INC Ransomware has the ability to use wmic.exe to spread to multiple endpoints within a compromised environment. |
| T1047 Windows Management Instrumentation |
MalwareFIVEHANDS | FIVEHANDS can use WMI to delete files on a target machine. |
| T1047 Windows Management Instrumentation |
MalwareHermeticWizard | HermeticWizard can use WMI to create a new process on a remote machine via `C:\windows\system32\cmd.exe /c start C:\windows\system32\\regsvr32.exe /s /iC:\windows\<filename>.dll`. |
| T1047 Windows Management Instrumentation |
ToolCovenant | Covenant can utilize WMI to install new Grunt listeners through XSL files or command one-liners. |
| T1047 Windows Management Instrumentation |
ToolSILENTTRINITY | SILENTTRINITY can use WMI for lateral movement. |
| T1047 Windows Management Instrumentation |
ToolPowerSploit | PowerSploit's |
| T1047 Windows Management Instrumentation |
ToolImpacket | Impacket's `wmiexec` module can be used to execute commands through WMI. |
| T1047 Windows Management Instrumentation |
ToolEmpire | Empire can use WMI to deliver a payload to a remote host. |
| T1047 Windows Management Instrumentation |
ToolPoshC2 | PoshC2 has a number of modules that use WMI to execute tasks. |
| T1047 Windows Management Instrumentation |
ToolBrute Ratel C4 | Brute Ratel C4 can use WMI to move laterally. |
| T1047 Windows Management Instrumentation |
ToolCrackMapExec | CrackMapExec can execute remote commands using Windows Management Instrumentation. |
| T1047 Windows Management Instrumentation |
ToolKoadic | Koadic can use WMI to execute commands. |
| T1048 Exfiltration Over Alternative Protocol |
GroupTeamTNT | TeamTNT has sent locally staged files with collected credentials to C2 servers using cURL. |
| T1048 Exfiltration Over Alternative Protocol |
GroupPlay | Play has used WinSCP to exfiltrate data to actor-controlled accounts. |
| T1048 Exfiltration Over Alternative Protocol |
MalwareFrameworkPOS | FrameworkPOS can use DNS tunneling for exfiltration of credit card data. |
| T1048 Exfiltration Over Alternative Protocol |
MalwareHydraq | Hydraq connects to a predefined domain on port 443 to exfil gathered information. |
| T1048 Exfiltration Over Alternative Protocol |
MalwareChaes | Chaes has exfiltrated its collected data from the infected machine to the C2, sometimes using the MIME protocol. |
| T1048 Exfiltration Over Alternative Protocol |
MalwareBundlore | Bundlore uses the |
| T1048 Exfiltration Over Alternative Protocol |
MalwareKobalos | Kobalos can exfiltrate credentials over the network via UDP. |
| T1048 Exfiltration Over Alternative Protocol |
MalwarePoetRAT | PoetRAT has used a .NET tool named dog.exe to exiltrate information over an e-mail account. |
| T1048 Exfiltration Over Alternative Protocol |
ToolAADInternals | AADInternals can directly download cloud user data such as OneDrive files. |
| T1048.002 Exfiltration Over Asymmetric Encrypted Non-C2 Protocol |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 exfiltrated collected data over a simple HTTPS request to a password-protected archive staged on a victim's OWA servers. |
| T1048.002 Exfiltration Over Asymmetric Encrypted Non-C2 Protocol |
GroupStorm-1811 | Storm-1811 has exfiltrated captured user credentials via Secure Copy Protocol (SCP). |
| T1048.002 Exfiltration Over Asymmetric Encrypted Non-C2 Protocol |
GroupCURIUM | CURIUM has used SMTPS to exfiltrate collected data from victims. |
| T1048.002 Exfiltration Over Asymmetric Encrypted Non-C2 Protocol |
GroupMirrorFace | MirrorFace has used Secure File Transfer Protocol (SFTP) for file exfiltration. |
| T1048.002 Exfiltration Over Asymmetric Encrypted Non-C2 Protocol |
GroupAPT28 | APT28 has exfiltrated archives of collected data previously staged on a target's OWA server via HTTPS. |
| T1048.002 Exfiltration Over Asymmetric Encrypted Non-C2 Protocol |
MalwareIcedID | IcedID has exfiltrated collected data via HTTPS. |
| T1048.002 Exfiltration Over Asymmetric Encrypted Non-C2 Protocol |
MalwareBRUSHFIRE | BRUSHFIRE has the ability to exfiltrate data on-demand through executing commands obtained via monitoring for specially crafted packets and sending output back in an embedded SSL response. |
| T1048.002 Exfiltration Over Asymmetric Encrypted Non-C2 Protocol |
ToolRclone | Rclone can exfiltrate data over SFTP or HTTPS via WebDAV. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries exfiltrated data to an actor-controlled infrastructure using HTTP POSTs. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
CampaignC0017 | During C0017, APT41 exfiltrated victim data via DNS lookups by encoding and prepending it as subdomains to the attacker-controlled domain. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
GroupSalt Typhoon | Salt Typhoon has exfiltrated configuration files from exploited network devices over FTP and TFTP. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
GroupAPT32 | APT32's backdoor can exfiltrate data by encoding it in the subdomain field of DNS packets. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
GroupFIN6 | FIN6 has sent stolen payment card data to remote servers via HTTP POSTs. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
GroupMustang Panda | Mustang Panda has used FTP to exfiltrate archive files. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
GroupContagious Interview | Contagious Interview has exfiltrated victim information using FTP. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
GroupOilRig | OilRig has exfiltrated data via Microsoft Exchange and over FTP separately from its primary C2 channel over DNS. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
GroupLazarus Group | Lazarus Group malware SierraBravo-Two generates an email message via SMTP containing information about newly infected victims. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
GroupThrip | Thrip has used WinSCP to exfiltrate data from a targeted organization over FTP. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
GroupWizard Spider | Wizard Spider has exfiltrated victim information using FTP. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
GroupAPT33 | APT33 has used FTP to exfiltrate files (separately from the C2 channel). |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
GroupFIN8 | FIN8 has used FTP to exfiltrate collected data. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
MalwareWindTail | WindTail has the ability to automatically exfiltrate files using the macOS built-in utility /usr/bin/curl. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
MalwareInvisibleFerret | InvisibleFerret has used FTP to exfiltrate files and directories using the command `ssh_upload` which contains with six subcommands of `.sdira`, `sdir`, `sfile`, `sfinda`, `sfindr` and `sfind` that had varying functions. InvisibleFerret has exfiltrated stolen files and data to the C2 servers over ports 1224, 2245 and 8637. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
MalwareBrave Prince | Some Brave Prince variants have used South Korea's Daum email service to exfiltrate information, and later variants have posted the data to a web server via an HTTP post command. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
MalwareCosmicDuke | CosmicDuke exfiltrates collected files over FTP or WebDAV. Exfiltration servers can be separately configured from C2 servers. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
MalwarePUBLOAD | PUBLOAD has leveraged `curl` for data exfiltration over FTP by uploading RAR archives containing targeted files (.doc, .docx, .xls, .xlsx, .pdf, .ppt, .pptx) to an adversary-owned FTP site. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
MalwareSocGholish | SocGholish can exfiltrate data directly to its C2 domain via HTTP. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.