ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1049
System Network Connections Discovery
MalwareSLOTHFULMEDIA

SLOTHFULMEDIA can enumerate open ports on a victim machine.

T1049
System Network Connections Discovery
ToolNet

Commands such as net use and net session can be used in Net to gather information about network connections from a particular host.

T1049
System Network Connections Discovery
ToolShimRatReporter

ShimRatReporter used the Windows function GetExtendedUdpTable to detect connected UDP endpoints.

T1049
System Network Connections Discovery
ToolSliver

Sliver can collect network connection information.

T1049
System Network Connections Discovery
ToolPacu

Once inside a Virtual Private Cloud, Pacu can attempt to identify DirectConnect, VPN, or VPC Peering.

T1049
System Network Connections Discovery
ToolEmpire

Empire can enumerate the current network connections of a host.

T1049
System Network Connections Discovery
ToolFRP

FRP can use a dashboard and U/I to display the status of connections from the FRP client and server.

T1049
System Network Connections Discovery
Toolnetstat

netstat can be used to enumerate local network connections, including active TCP connections and other network statistics.

T1049
System Network Connections Discovery
ToolPoshC2

PoshC2 contains an implementation of netstat to enumerate TCP and UDP connections.

T1049
System Network Connections Discovery
Toolnbtstat

nbtstat can be used to discover current NetBIOS sessions.

T1049
System Network Connections Discovery
ToolCrackMapExec

CrackMapExec can discover active sessions for a targeted system.

T1049
System Network Connections Discovery
ToolPupy

Pupy has a built-in utility command for netstat, can do net session through PowerView, and has an interactive shell which can be used to discover additional information.

T1049
System Network Connections Discovery
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer can search compromised systems for webhook URLs connecting to Slack and Discord.

T1049
System Network Connections Discovery
MalwareDuqu

The discovery modules used with Duqu can collect information on network connections.

T1052.001
Exfiltration over USB
GroupMustang Panda

Mustang Panda has used a customized PlugX variant which could exfiltrate documents from air-gapped networks.

T1052.001
Exfiltration over USB
GroupTropic Trooper

Tropic Trooper has exfiltrated data using USB storage devices.

T1052.001
Exfiltration over USB
MalwareMachete

Machete has a feature to copy files from every drive onto a removable drive in a hidden folder.

T1052.001
Exfiltration over USB
MalwareAgent.btz

Agent.btz creates a file named thumb.dd on all USB flash drives connected to the victim. This file contains information about the infected system and activity logs.

T1052.001
Exfiltration over USB
MalwareRemsec

Remsec contains a module to move data from airgapped networks to Internet-connected systems by using a removable USB device.

T1052.001
Exfiltration over USB
MalwareSPACESHIP

SPACESHIP copies staged data to removable drives when they are inserted into the system.

T1052.001
Exfiltration over USB
MalwareUSBStealer

USBStealer exfiltrates collected files via removable media from air-gapped victims.

T1053
Scheduled Task/Job
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries set FortiGate scheduled tasks to run the adversary generated CLI scripts weekly.

T1053
Scheduled Task/Job
MalwareLokibot

Lokibot's second stage DLL has set a timer using “timeSetEvent” to schedule its next execution.

T1053.002
At
GroupAPT18

APT18 actors used the native at Windows task scheduler tool to use scheduled tasks for execution on a victim network.

T1053.002
At
GroupBRONZE BUTLER

BRONZE BUTLER has used at to register a scheduled task to execute malware during lateral movement.

T1053.002
At
GroupThreat Group-3390

Threat Group-3390 actors use at to schedule tasks to run self-extracting RAR archives, which install HTTPBrowser or PlugX on other victims on a network.

T1053.002
At
MalwareMURKYTOP

MURKYTOP has the capability to schedule remote AT jobs.

T1053.002
At
Toolat

at can be used to schedule a task on a system to be executed at a specific date or time.

T1053.002
At
ToolCrackMapExec

CrackMapExec can set a scheduled task on the target system to execute commands remotely using at.

T1053.003
Cron
CampaignOperation MidnightEclipse

During Operation MidnightEclipse, threat actors configured cron jobs to retrieve payloads from actor-controlled infrastructure.

T1053.003
Cron
GroupAPT38

APT38 has used cron to create pre-scheduled and periodic background jobs on a Linux system.

T1053.003
Cron
GroupRocke

Rocke installed a cron job that downloaded and executed files from the C2.

T1053.003
Cron
GroupAPT5

APT5 has made modifications to the crontab file including in `/var/cron/tabs/`.

T1053.003
Cron
MalwareExaramel for Linux

Exaramel for Linux uses crontab for persistence if it does not have root privileges.

T1053.003
Cron
MalwareJanicab

Janicab used a cron job for persistence on Mac devices.

T1053.003
Cron
MalwareNETWIRE

NETWIRE can use crontabs to establish persistence.

T1053.003
Cron
MalwareGomir

Gomir will configure a crontab for process execution to start the backdoor on reboot if it is not initially running under group 0 privileges.

T1053.003
Cron
MalwareSkidmap

Skidmap has installed itself via crontab.

T1053.003
Cron
MalwareGoldMax

The GoldMax Linux variant has used a crontab entry with a @reboot line to gain persistence.

T1053.003
Cron
MalwareAnchor

Anchor can install itself as a cron job.

T1053.003
Cron
MalwareXbash

Xbash can create a cronjob for persistence if it determines it is on a Linux system.

T1053.003
Cron
MalwareSpeakUp

SpeakUp uses cron tasks to ensure persistence.

T1053.003
Cron
MalwareNKAbuse

NKAbuse uses a Cron job to establish persistence when infecting Linux hosts.

T1053.003
Cron
MalwarePenquin

Penquin can use Cron to create periodic and pre-scheduled background jobs.

T1053.003
Cron
MalwareKinsing

Kinsing has used crontab to download and run shell scripts every minute to ensure persistence.

T1053.005
Scheduled Task
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group created scheduled tasks to set a periodic execution of a remote XSL script.

T1053.005
Scheduled Task
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors used scheduled tasks to help establish persistence.

T1053.005
Scheduled Task
CampaignFrankenstein

During Frankenstein, the threat actors established persistence through a scheduled task using the command: `/Create /F /SC DAILY /ST 09:00 /TN WinUpdate /TR`, named "WinUpdate"

T1053.005
Scheduled Task
CampaignTriton Safety Instrumented System Attack

In the Triton Safety Instrumented System Attack, TEMP.Veles installed scheduled tasks defined in XML files.

T1053.005
Scheduled Task
CampaignJuicy Mix

During Juicy Mix, OilRig used VBS droppers to schedule tasks for persistence.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.