Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1049 System Network Connections Discovery |
MalwareSLOTHFULMEDIA | SLOTHFULMEDIA can enumerate open ports on a victim machine. |
| T1049 System Network Connections Discovery |
ToolNet | Commands such as |
| T1049 System Network Connections Discovery |
ToolShimRatReporter | ShimRatReporter used the Windows function |
| T1049 System Network Connections Discovery |
ToolSliver | Sliver can collect network connection information. |
| T1049 System Network Connections Discovery |
ToolPacu | Once inside a Virtual Private Cloud, Pacu can attempt to identify DirectConnect, VPN, or VPC Peering. |
| T1049 System Network Connections Discovery |
ToolEmpire | Empire can enumerate the current network connections of a host. |
| T1049 System Network Connections Discovery |
ToolFRP | FRP can use a dashboard and U/I to display the status of connections from the FRP client and server. |
| T1049 System Network Connections Discovery |
Toolnetstat | netstat can be used to enumerate local network connections, including active TCP connections and other network statistics. |
| T1049 System Network Connections Discovery |
ToolPoshC2 | PoshC2 contains an implementation of netstat to enumerate TCP and UDP connections. |
| T1049 System Network Connections Discovery |
Toolnbtstat | nbtstat can be used to discover current NetBIOS sessions. |
| T1049 System Network Connections Discovery |
ToolCrackMapExec | CrackMapExec can discover active sessions for a targeted system. |
| T1049 System Network Connections Discovery |
ToolPupy | Pupy has a built-in utility command for |
| T1049 System Network Connections Discovery |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer can search compromised systems for webhook URLs connecting to Slack and Discord. |
| T1049 System Network Connections Discovery |
MalwareDuqu | The discovery modules used with Duqu can collect information on network connections. |
| T1052.001 Exfiltration over USB |
GroupMustang Panda | Mustang Panda has used a customized PlugX variant which could exfiltrate documents from air-gapped networks. |
| T1052.001 Exfiltration over USB |
GroupTropic Trooper | Tropic Trooper has exfiltrated data using USB storage devices. |
| T1052.001 Exfiltration over USB |
MalwareMachete | Machete has a feature to copy files from every drive onto a removable drive in a hidden folder. |
| T1052.001 Exfiltration over USB |
MalwareAgent.btz | Agent.btz creates a file named thumb.dd on all USB flash drives connected to the victim. This file contains information about the infected system and activity logs. |
| T1052.001 Exfiltration over USB |
MalwareRemsec | Remsec contains a module to move data from airgapped networks to Internet-connected systems by using a removable USB device. |
| T1052.001 Exfiltration over USB |
MalwareSPACESHIP | SPACESHIP copies staged data to removable drives when they are inserted into the system. |
| T1052.001 Exfiltration over USB |
MalwareUSBStealer | USBStealer exfiltrates collected files via removable media from air-gapped victims. |
| T1053 Scheduled Task/Job |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries set FortiGate scheduled tasks to run the adversary generated CLI scripts weekly. |
| T1053 Scheduled Task/Job |
MalwareLokibot | Lokibot's second stage DLL has set a timer using “timeSetEvent” to schedule its next execution. |
| T1053.002 At |
GroupAPT18 | APT18 actors used the native at Windows task scheduler tool to use scheduled tasks for execution on a victim network. |
| T1053.002 At |
GroupBRONZE BUTLER | BRONZE BUTLER has used at to register a scheduled task to execute malware during lateral movement. |
| T1053.002 At |
GroupThreat Group-3390 | Threat Group-3390 actors use at to schedule tasks to run self-extracting RAR archives, which install HTTPBrowser or PlugX on other victims on a network. |
| T1053.002 At |
MalwareMURKYTOP | MURKYTOP has the capability to schedule remote AT jobs. |
| T1053.002 At |
Toolat | at can be used to schedule a task on a system to be executed at a specific date or time. |
| T1053.002 At |
ToolCrackMapExec | CrackMapExec can set a scheduled task on the target system to execute commands remotely using at. |
| T1053.003 Cron |
CampaignOperation MidnightEclipse | During Operation MidnightEclipse, threat actors configured cron jobs to retrieve payloads from actor-controlled infrastructure. |
| T1053.003 Cron |
GroupAPT38 | APT38 has used cron to create pre-scheduled and periodic background jobs on a Linux system. |
| T1053.003 Cron |
GroupRocke | Rocke installed a cron job that downloaded and executed files from the C2. |
| T1053.003 Cron |
GroupAPT5 | APT5 has made modifications to the crontab file including in `/var/cron/tabs/`. |
| T1053.003 Cron |
MalwareExaramel for Linux | Exaramel for Linux uses crontab for persistence if it does not have root privileges. |
| T1053.003 Cron |
MalwareJanicab | Janicab used a cron job for persistence on Mac devices. |
| T1053.003 Cron |
MalwareNETWIRE | NETWIRE can use crontabs to establish persistence. |
| T1053.003 Cron |
MalwareGomir | Gomir will configure a crontab for process execution to start the backdoor on reboot if it is not initially running under group 0 privileges. |
| T1053.003 Cron |
MalwareSkidmap | Skidmap has installed itself via crontab. |
| T1053.003 Cron |
MalwareGoldMax | The GoldMax Linux variant has used a crontab entry with a |
| T1053.003 Cron |
MalwareAnchor | Anchor can install itself as a cron job. |
| T1053.003 Cron |
MalwareXbash | Xbash can create a cronjob for persistence if it determines it is on a Linux system. |
| T1053.003 Cron |
MalwareSpeakUp | SpeakUp uses cron tasks to ensure persistence. |
| T1053.003 Cron |
MalwareNKAbuse | NKAbuse uses a Cron job to establish persistence when infecting Linux hosts. |
| T1053.003 Cron |
MalwarePenquin | Penquin can use Cron to create periodic and pre-scheduled background jobs. |
| T1053.003 Cron |
MalwareKinsing | Kinsing has used crontab to download and run shell scripts every minute to ensure persistence. |
| T1053.005 Scheduled Task |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group created scheduled tasks to set a periodic execution of a remote XSL script. |
| T1053.005 Scheduled Task |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors used scheduled tasks to help establish persistence. |
| T1053.005 Scheduled Task |
CampaignFrankenstein | During Frankenstein, the threat actors established persistence through a scheduled task using the command: `/Create /F /SC DAILY /ST 09:00 /TN WinUpdate /TR`, named "WinUpdate" |
| T1053.005 Scheduled Task |
CampaignTriton Safety Instrumented System Attack | In the Triton Safety Instrumented System Attack, TEMP.Veles installed scheduled tasks defined in XML files. |
| T1053.005 Scheduled Task |
CampaignJuicy Mix | During Juicy Mix, OilRig used VBS droppers to schedule tasks for persistence. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.