Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
MalwareRemsec | Remsec can exfiltrate data via a DNS tunnel or email, separately from its C2 channel. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
MalwareCharmPower | CharmPower can send victim data via FTP with credentials hardcoded in the script. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
MalwareKONNI | KONNI has used FTP to exfiltrate reconnaissance data out. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
MalwareCORALDECK | CORALDECK has exfiltrated data in HTTP POST headers. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
Malwareccf32 | ccf32 can upload collected data and files to an FTP server. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
MalwareWARPWIRE | WARPWIRE can send captured credentials to C2 via HTTP `GET` or `POST` requests. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
MalwareCherry Picker | Cherry Picker exfiltrates files over FTP. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
MalwareCarbon | Carbon uses HTTP to send data to the C2 server. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
MalwareKessel | Kessel can exfiltrate credentials and other information via HTTP POST request, TCP, and DNS. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
MalwarePoetRAT | |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
MalwareAgent Tesla | Agent Tesla has routines for exfiltration over SMTP, FTP, and HTTP. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
MalwareCookieMiner | CookieMiner has used the |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
MalwareDok | Dok exfiltrates logs of its execution stored in the |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
ToolRclone | Rclone can exfiltrate data over FTP or HTTP, including HTTP via WebDAV. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
ToolBITSAdmin | BITSAdmin can be used to create BITS Jobs to upload files from a compromised host. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
Toolftp | ftp may be used to exfiltrate data separate from the main command and control protocol. |
| T1049 System Network Connections Discovery |
CampaignAnthropic AI-orchestrated Campaign | During the Anthropic AI-orchestrated Campaign, the adversary used Claude Code to map internal network architecture and access relationships. |
| T1049 System Network Connections Discovery |
CampaignFunnyDream | During FunnyDream, the threat actors used netstat to discover network connections on remote systems. |
| T1049 System Network Connections Discovery |
CampaignOperation CuckooBees | During Operation CuckooBees, the threat actors used the `net session`, `net use`, and `netstat` commands as part of their advanced reconnaissance. |
| T1049 System Network Connections Discovery |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries identified network connections utilizing `netstat -nao` and `netstat -r`. |
| T1049 System Network Connections Discovery |
CampaignOperation Wocao | During Operation Wocao, threat actors collected a list of open connections on the infected system using `netstat` and checks whether it has an internet connection. |
| T1049 System Network Connections Discovery |
GroupAPT38 | APT38 installed a port monitoring tool, MAPMAKER, to print the active TCP connections on the local system. |
| T1049 System Network Connections Discovery |
GroupGALLIUM | GALLIUM used |
| T1049 System Network Connections Discovery |
GroupAPT3 | APT3 has a tool that can enumerate current network connections. |
| T1049 System Network Connections Discovery |
Groupadmin@338 | admin@338 actors used the following command following exploitation of a machine with LOWBALL malware to display network connections: |
| T1049 System Network Connections Discovery |
GroupVolt Typhoon | Volt Typhoon has used `netstat -ano` on compromised hosts to enumerate network connections. |
| T1049 System Network Connections Discovery |
GroupAPT41 | APT41 has enumerated IP addresses of network resources and used the |
| T1049 System Network Connections Discovery |
GroupmenuPass | menuPass has used |
| T1049 System Network Connections Discovery |
GroupAPT32 | APT32 used the |
| T1049 System Network Connections Discovery |
GroupMuddyWater | MuddyWater has used a PowerShell backdoor to check for Skype connections on the target machine. |
| T1049 System Network Connections Discovery |
GroupTeamTNT | TeamTNT has run |
| T1049 System Network Connections Discovery |
GroupSandworm Team | Sandworm Team had gathered user, IP address, and server data related to RDP sessions on a compromised host. It has also accessed network diagram files useful for understanding how a host's network was configured. |
| T1049 System Network Connections Discovery |
GroupAndariel | Andariel has used the |
| T1049 System Network Connections Discovery |
GroupMustang Panda | Mustang Panda has used |
| T1049 System Network Connections Discovery |
GroupOilRig | OilRig has used |
| T1049 System Network Connections Discovery |
GroupTropic Trooper | Tropic Trooper has tested if the localhost network is available and other connection capability on an infected system using command scripts. |
| T1049 System Network Connections Discovery |
GroupKe3chang | Ke3chang performs local network connection discovery using |
| T1049 System Network Connections Discovery |
GroupAPT1 | APT1 used the |
| T1049 System Network Connections Discovery |
GroupTurla | Turla surveys a system upon check-in to discover active local network connections using the |
| T1049 System Network Connections Discovery |
GroupPoseidon Group | Poseidon Group obtains and saves information about victim network interfaces and addresses. |
| T1049 System Network Connections Discovery |
GroupLotus Blossom | Lotus Blossom has used commands such as `netstat` to identify system network connections. |
| T1049 System Network Connections Discovery |
GroupChimera | Chimera has used |
| T1049 System Network Connections Discovery |
GroupBackdoorDiplomacy | BackdoorDiplomacy has used NetCat and PortQry to enumerate network connections and display the status of related TCP and UDP ports. |
| T1049 System Network Connections Discovery |
GroupToddyCat | ToddyCat has used `netstat -anop tcp` to discover TCP connections to compromised hosts. |
| T1049 System Network Connections Discovery |
GroupAPT5 | APT5 has used the BLOODMINE utility to collect data on web requests from Pulse Secure Connect logs. |
| T1049 System Network Connections Discovery |
GroupLazarus Group | Lazarus Group has used |
| T1049 System Network Connections Discovery |
GroupINC Ransom | INC Ransom has used RDP to test network connections. |
| T1049 System Network Connections Discovery |
GroupEarth Lusca | Earth Lusca employed a PowerShell script called RDPConnectionParser to read and filter the Windows event log “Microsoft-Windows-TerminalServices-RDPClient/Operational” |
| T1049 System Network Connections Discovery |
GroupVelvet Ant | Velvet Ant has enumerated existing network connections on victim devices. |
| T1049 System Network Connections Discovery |
GroupHEXANE | HEXANE has used netstat to monitor connections to specific ports. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.