ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

1146 examples

TechniqueUsed byProcedure example
T1074.001
Local Data Staging
CampaignAPT28 Nearest Neighbor Campaign

During APT28 Nearest Neighbor Campaign, APT28 staged captured credential information in the C:\ProgramData directory.

T1074.001
Local Data Staging
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries compiled discovery data locally on the victim host in a file located within `C:\Windows\TEMP\outlog.txt`.

T1074.001
Local Data Staging
CampaignAPT41 DUST

APT41 DUST involved exporting data from Oracle databases to local CSV files prior to exfiltration.

T1074.001
Local Data Staging
CampaignOperation Wocao

During Operation Wocao, threat actors staged archived files in a temporary directory prior to exfiltration.

T1074.001
Local Data Staging
CampaignLeviathan Australian Intrusions

Leviathan stored captured credential material on local log files on victim systems during Leviathan Australian Intrusions.

T1074.001
Local Data Staging
CampaignC0017

During C0017, APT41 copied the local `SAM` and `SYSTEM` Registry hives to a staging directory.

T1074.002
Remote Data Staging
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 staged data and files in password-protected archives on a victim's OWA server.

T1074.002
Remote Data Staging
CampaignNight Dragon

During Night Dragon, threat actors copied files to company web servers and subsequently downloaded them.

T1078
Valid Accounts
CampaignRedPenguin

During RedPenguin, UNC3886 used legitimate credentials to gain priviliged access to Juniper routers.

T1078
Valid Accounts
CampaignOperation MidnightEclipse

During Operation MidnightEclipse, threat actors extracted sensitive credentials while moving laterally through compromised networks.

T1078
Valid Accounts
Campaign2015 Ukraine Electric Power Attack

During the 2015 Ukraine Electric Power Attack, Sandworm Team used valid accounts on the corporate network to escalate privileges, move laterally, and establish persistence within the corporate network.

T1078
Valid Accounts
Campaign3CX Supply Chain Attack

During 3CX Supply Chain Attack, AppleJeus has gained access to the 3CX corporate environment through legitimate VPN credentials.

T1078
Valid Accounts
CampaignAnthropic AI-orchestrated Campaign

During the Anthropic AI-orchestrated Campaign, the adversary used harvested credentials to authenticate against internal APIs, database systems, container registries, and logging infrastructure across targeted networks.

T1078
Valid Accounts
CampaignHomeLand Justice

During HomeLand Justice, threat actors used a compromised Exchange account to search mailboxes and create new Exchange accounts.

T1078
Valid Accounts
CampaignC0032

During the C0032 campaign, TEMP.Veles used compromised VPN accounts.

T1078
Valid Accounts
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used different compromised credentials for remote access and to move laterally.

T1078
Valid Accounts
CampaignNight Dragon

During Night Dragon, threat actors used compromised VPN accounts to gain access to victim systems.

T1078
Valid Accounts
CampaignOperation Wocao

During Operation Wocao, threat actors used valid VPN credentials to gain initial access.

T1078
Valid Accounts
CampaignLeviathan Australian Intrusions

Leviathan used captured, valid account information to log into victim web applications and appliances during Leviathan Australian Intrusions.

T1078.001
Default Accounts
CampaignHomeLand Justice

During HomeLand Justice, threat actors used the built-in administrator account to move laterally using RDP and Impacket.

T1078.002
Domain Accounts
CampaignOperation MidnightEclipse

During Operation MidnightEclipse, threat actors used a compromised domain admin account to move laterally.

T1078.002
Domain Accounts
CampaignCutting Edge

During Cutting Edge, threat actors used compromised VPN accounts for lateral movement on targeted networks.

T1078.002
Domain Accounts
CampaignOperation Ghost

For Operation Ghost, APT29 used stolen administrator credentials for lateral movement on compromised networks.

T1078.002
Domain Accounts
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used domain administrators' accounts to help facilitate lateral movement on compromised networks.

T1078.002
Domain Accounts
CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors used compromised domain administrator credentials as part of their lateral movement.

T1078.002
Domain Accounts
CampaignSalesforce Data Exfiltration

During Salesforce Data Exfiltration, threat actors used compromised credentials for lateral movement.

T1078.002
Domain Accounts
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, threat actors utilized privileged accounts to access the FortiGate VPN solution and subsequent subnets.

T1078.002
Domain Accounts
CampaignNight Dragon

During Night Dragon, threat actors used domain accounts to gain further access to victim systems.

T1078.002
Domain Accounts
CampaignOperation Wocao

During Operation Wocao, threat actors used domain credentials, including domain admin, for lateral movement and privilege escalation.

T1078.002
Domain Accounts
CampaignLeviathan Australian Intrusions

Leviathan compromised domain credentials during Leviathan Australian Intrusions.

T1078.003
Local Accounts
CampaignAnthropic AI-orchestrated Campaign

During the Anthropic AI-orchestrated Campaign, the adversary used Claude Code to test credentials harvested against discovered devices.

T1078.003
Local Accounts
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used compromised local accounts to access victims' networks.

T1078.003
Local Accounts
CampaignOperation Wocao

During Operation Wocao, threat actors used local account credentials found during the intrusion for lateral movement and privilege escalation.

T1078.003
Local Accounts
CampaignLeviathan Australian Intrusions

Leviathan used captured local account information, such as service accounts, for actions during Leviathan Australian Intrusions.

T1078.004
Cloud Accounts
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used a compromised O365 administrator account to create a new Service Principal.

T1078.004
Cloud Accounts
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries leveraged stolen credentials from on-premises environments to access cloud services.

T1078.004
Cloud Accounts
CampaignC0027

During C0027, Scattered Spider leveraged compromised credentials from victim users to authenticate to Azure tenants.

T1082
System Information Discovery
CampaignKV Botnet Activity

KV Botnet Activity includes use of native system tools, such as uname, to obtain information about victim device architecture, as well as gathering other system information such as the victim's hosts file and CPU utilization.

T1082
System Information Discovery
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors fingerprinted targeted SharePoint servers to identify OS version and running processes.

T1082
System Information Discovery
CampaignFrankenstein

During Frankenstein, the threat actors used Empire to obtain the compromised machine's name.

T1082
System Information Discovery
CampaignRedDelta Modified PlugX Infection Chain Operations

Mustang Panda captured victim operating system type via User Agent analysis during RedDelta Modified PlugX Infection Chain Operations.

T1082
System Information Discovery
CampaignOperation Honeybee

During Operation Honeybee, the threat actors collected the computer name, OS, and other system information using `cmd /c systeminfo > %temp%\ temp.ini`.

T1082
System Information Discovery
CampaignCutting Edge

During Cutting Edge, threat actors used the ENUM4LINUX Perl script for discovery on Windows and Samba hosts.

T1082
System Information Discovery
CampaignAnthropic AI-orchestrated Campaign

During the Anthropic AI-orchestrated Campaign, the adversary tasked Claude Code to query databases and systems in order to identify proprietary information, including system configurations and database types.

T1082
System Information Discovery
CampaignJuicy Mix

During Juicy Mix, OilRig used a script to send the name of the compromised host via HTTP `POST` to register it with C2.

T1082
System Information Discovery
CampaignOperation AkaiRyū

During Operation AkaiRyū, MirrorFace collected system information.

T1082
System Information Discovery
CampaignFunnyDream

During FunnyDream, the threat actors used Systeminfo to collect information on targeted hosts.

T1082
System Information Discovery
CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors used the `systeminfo` command to gather details about a compromised system.

T1082
System Information Discovery
CampaignArcaneDoor

ArcaneDoor included collection of victim device configuration information.

T1082
System Information Discovery
CampaignOperation Wocao

During Operation Wocao, threat actors discovered the OS versions of systems connected to a targeted network.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.