ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1047
Windows Management Instrumentation
MalwareQakBot

QakBot can execute WMI queries to gather information.

T1047
Windows Management Instrumentation
MalwarejRAT

jRAT uses WMIC to identify anti-virus products installed on the victim’s machine and to obtain firewall details.

T1047
Windows Management Instrumentation
MalwareINC Ransomware

INC Ransomware has the ability to use wmic.exe to spread to multiple endpoints within a compromised environment.

T1047
Windows Management Instrumentation
MalwareFIVEHANDS

FIVEHANDS can use WMI to delete files on a target machine.

T1047
Windows Management Instrumentation
MalwareHermeticWizard

HermeticWizard can use WMI to create a new process on a remote machine via `C:\windows\system32\cmd.exe /c start C:\windows\system32\\regsvr32.exe /s /iC:\windows\<filename>.dll`.

T1047
Windows Management Instrumentation
ToolCovenant

Covenant can utilize WMI to install new Grunt listeners through XSL files or command one-liners.

T1047
Windows Management Instrumentation
ToolSILENTTRINITY

SILENTTRINITY can use WMI for lateral movement.

T1047
Windows Management Instrumentation
ToolPowerSploit

PowerSploit's Invoke-WmiCommand CodeExecution module uses WMI to execute and retrieve the output from a PowerShell payload.

T1047
Windows Management Instrumentation
ToolImpacket

Impacket's `wmiexec` module can be used to execute commands through WMI.

T1047
Windows Management Instrumentation
ToolEmpire

Empire can use WMI to deliver a payload to a remote host.

T1047
Windows Management Instrumentation
ToolPoshC2

PoshC2 has a number of modules that use WMI to execute tasks.

T1047
Windows Management Instrumentation
ToolBrute Ratel C4

Brute Ratel C4 can use WMI to move laterally.

T1047
Windows Management Instrumentation
ToolCrackMapExec

CrackMapExec can execute remote commands using Windows Management Instrumentation.

T1047
Windows Management Instrumentation
ToolKoadic

Koadic can use WMI to execute commands.

T1048
Exfiltration Over Alternative Protocol
GroupTeamTNT

TeamTNT has sent locally staged files with collected credentials to C2 servers using cURL.

T1048
Exfiltration Over Alternative Protocol
GroupPlay

Play has used WinSCP to exfiltrate data to actor-controlled accounts.

T1048
Exfiltration Over Alternative Protocol
MalwareFrameworkPOS

FrameworkPOS can use DNS tunneling for exfiltration of credit card data.

T1048
Exfiltration Over Alternative Protocol
MalwareHydraq

Hydraq connects to a predefined domain on port 443 to exfil gathered information.

T1048
Exfiltration Over Alternative Protocol
MalwareChaes

Chaes has exfiltrated its collected data from the infected machine to the C2, sometimes using the MIME protocol.

T1048
Exfiltration Over Alternative Protocol
MalwareBundlore

Bundlore uses the curl -s -L -o command to exfiltrate archived data to a URL.

T1048
Exfiltration Over Alternative Protocol
MalwareKobalos

Kobalos can exfiltrate credentials over the network via UDP.

T1048
Exfiltration Over Alternative Protocol
MalwarePoetRAT

PoetRAT has used a .NET tool named dog.exe to exiltrate information over an e-mail account.

T1048
Exfiltration Over Alternative Protocol
ToolAADInternals

AADInternals can directly download cloud user data such as OneDrive files.

T1048.002
Exfiltration Over Asymmetric Encrypted Non-C2 Protocol
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 exfiltrated collected data over a simple HTTPS request to a password-protected archive staged on a victim's OWA servers.

T1048.002
Exfiltration Over Asymmetric Encrypted Non-C2 Protocol
GroupStorm-1811

Storm-1811 has exfiltrated captured user credentials via Secure Copy Protocol (SCP).

T1048.002
Exfiltration Over Asymmetric Encrypted Non-C2 Protocol
GroupCURIUM

CURIUM has used SMTPS to exfiltrate collected data from victims.

T1048.002
Exfiltration Over Asymmetric Encrypted Non-C2 Protocol
GroupMirrorFace

MirrorFace has used Secure File Transfer Protocol (SFTP) for file exfiltration.

T1048.002
Exfiltration Over Asymmetric Encrypted Non-C2 Protocol
GroupAPT28

APT28 has exfiltrated archives of collected data previously staged on a target's OWA server via HTTPS.

T1048.002
Exfiltration Over Asymmetric Encrypted Non-C2 Protocol
MalwareIcedID

IcedID has exfiltrated collected data via HTTPS.

T1048.002
Exfiltration Over Asymmetric Encrypted Non-C2 Protocol
MalwareBRUSHFIRE

BRUSHFIRE has the ability to exfiltrate data on-demand through executing commands obtained via monitoring for specially crafted packets and sending output back in an embedded SSL response.

T1048.002
Exfiltration Over Asymmetric Encrypted Non-C2 Protocol
ToolRclone

Rclone can exfiltrate data over SFTP or HTTPS via WebDAV.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries exfiltrated data to an actor-controlled infrastructure using HTTP POSTs.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
CampaignC0017

During C0017, APT41 exfiltrated victim data via DNS lookups by encoding and prepending it as subdomains to the attacker-controlled domain.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
GroupSalt Typhoon

Salt Typhoon has exfiltrated configuration files from exploited network devices over FTP and TFTP.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
GroupAPT32

APT32's backdoor can exfiltrate data by encoding it in the subdomain field of DNS packets.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
GroupFIN6

FIN6 has sent stolen payment card data to remote servers via HTTP POSTs.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
GroupMustang Panda

Mustang Panda has used FTP to exfiltrate archive files.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
GroupContagious Interview

Contagious Interview has exfiltrated victim information using FTP.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
GroupOilRig

OilRig has exfiltrated data via Microsoft Exchange and over FTP separately from its primary C2 channel over DNS.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
GroupLazarus Group

Lazarus Group malware SierraBravo-Two generates an email message via SMTP containing information about newly infected victims.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
GroupThrip

Thrip has used WinSCP to exfiltrate data from a targeted organization over FTP.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
GroupWizard Spider

Wizard Spider has exfiltrated victim information using FTP.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
GroupAPT33

APT33 has used FTP to exfiltrate files (separately from the C2 channel).

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
GroupFIN8

FIN8 has used FTP to exfiltrate collected data.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
MalwareWindTail

WindTail has the ability to automatically exfiltrate files using the macOS built-in utility /usr/bin/curl.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
MalwareInvisibleFerret

InvisibleFerret has used FTP to exfiltrate files and directories using the command `ssh_upload` which contains with six subcommands of `.sdira`, `sdir`, `sfile`, `sfinda`, `sfindr` and `sfind` that had varying functions. InvisibleFerret has exfiltrated stolen files and data to the C2 servers over ports 1224, 2245 and 8637.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
MalwareBrave Prince

Some Brave Prince variants have used South Korea's Daum email service to exfiltrate information, and later variants have posted the data to a web server via an HTTP post command.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
MalwareCosmicDuke

CosmicDuke exfiltrates collected files over FTP or WebDAV. Exfiltration servers can be separately configured from C2 servers.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
MalwarePUBLOAD

PUBLOAD has leveraged `curl` for data exfiltration over FTP by uploading RAR archives containing targeted files (.doc, .docx, .xls, .xlsx, .pdf, .ppt, .pptx) to an adversary-owned FTP site.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
MalwareSocGholish

SocGholish can exfiltrate data directly to its C2 domain via HTTP.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.