Real-world descriptions of how a group, tool or campaign used a technique.
1146 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1074.001 Local Data Staging |
CampaignAPT28 Nearest Neighbor Campaign | During APT28 Nearest Neighbor Campaign, APT28 staged captured credential information in the |
| T1074.001 Local Data Staging |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries compiled discovery data locally on the victim host in a file located within `C:\Windows\TEMP\outlog.txt`. |
| T1074.001 Local Data Staging |
CampaignAPT41 DUST | APT41 DUST involved exporting data from Oracle databases to local CSV files prior to exfiltration. |
| T1074.001 Local Data Staging |
CampaignOperation Wocao | During Operation Wocao, threat actors staged archived files in a temporary directory prior to exfiltration. |
| T1074.001 Local Data Staging |
CampaignLeviathan Australian Intrusions | Leviathan stored captured credential material on local log files on victim systems during Leviathan Australian Intrusions. |
| T1074.001 Local Data Staging |
CampaignC0017 | During C0017, APT41 copied the local `SAM` and `SYSTEM` Registry hives to a staging directory. |
| T1074.002 Remote Data Staging |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 staged data and files in password-protected archives on a victim's OWA server. |
| T1074.002 Remote Data Staging |
CampaignNight Dragon | During Night Dragon, threat actors copied files to company web servers and subsequently downloaded them. |
| T1078 Valid Accounts |
CampaignRedPenguin | During RedPenguin, UNC3886 used legitimate credentials to gain priviliged access to Juniper routers. |
| T1078 Valid Accounts |
CampaignOperation MidnightEclipse | During Operation MidnightEclipse, threat actors extracted sensitive credentials while moving laterally through compromised networks. |
| T1078 Valid Accounts |
Campaign2015 Ukraine Electric Power Attack | During the 2015 Ukraine Electric Power Attack, Sandworm Team used valid accounts on the corporate network to escalate privileges, move laterally, and establish persistence within the corporate network. |
| T1078 Valid Accounts |
Campaign3CX Supply Chain Attack | During 3CX Supply Chain Attack, AppleJeus has gained access to the 3CX corporate environment through legitimate VPN credentials. |
| T1078 Valid Accounts |
CampaignAnthropic AI-orchestrated Campaign | During the Anthropic AI-orchestrated Campaign, the adversary used harvested credentials to authenticate against internal APIs, database systems, container registries, and logging infrastructure across targeted networks. |
| T1078 Valid Accounts |
CampaignHomeLand Justice | During HomeLand Justice, threat actors used a compromised Exchange account to search mailboxes and create new Exchange accounts. |
| T1078 Valid Accounts |
CampaignC0032 | During the C0032 campaign, TEMP.Veles used compromised VPN accounts. |
| T1078 Valid Accounts |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used different compromised credentials for remote access and to move laterally. |
| T1078 Valid Accounts |
CampaignNight Dragon | During Night Dragon, threat actors used compromised VPN accounts to gain access to victim systems. |
| T1078 Valid Accounts |
CampaignOperation Wocao | During Operation Wocao, threat actors used valid VPN credentials to gain initial access. |
| T1078 Valid Accounts |
CampaignLeviathan Australian Intrusions | Leviathan used captured, valid account information to log into victim web applications and appliances during Leviathan Australian Intrusions. |
| T1078.001 Default Accounts |
CampaignHomeLand Justice | During HomeLand Justice, threat actors used the built-in administrator account to move laterally using RDP and Impacket. |
| T1078.002 Domain Accounts |
CampaignOperation MidnightEclipse | During Operation MidnightEclipse, threat actors used a compromised domain admin account to move laterally. |
| T1078.002 Domain Accounts |
CampaignCutting Edge | During Cutting Edge, threat actors used compromised VPN accounts for lateral movement on targeted networks. |
| T1078.002 Domain Accounts |
CampaignOperation Ghost | For Operation Ghost, APT29 used stolen administrator credentials for lateral movement on compromised networks. |
| T1078.002 Domain Accounts |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used domain administrators' accounts to help facilitate lateral movement on compromised networks. |
| T1078.002 Domain Accounts |
CampaignOperation CuckooBees | During Operation CuckooBees, the threat actors used compromised domain administrator credentials as part of their lateral movement. |
| T1078.002 Domain Accounts |
CampaignSalesforce Data Exfiltration | During Salesforce Data Exfiltration, threat actors used compromised credentials for lateral movement. |
| T1078.002 Domain Accounts |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, threat actors utilized privileged accounts to access the FortiGate VPN solution and subsequent subnets. |
| T1078.002 Domain Accounts |
CampaignNight Dragon | During Night Dragon, threat actors used domain accounts to gain further access to victim systems. |
| T1078.002 Domain Accounts |
CampaignOperation Wocao | During Operation Wocao, threat actors used domain credentials, including domain admin, for lateral movement and privilege escalation. |
| T1078.002 Domain Accounts |
CampaignLeviathan Australian Intrusions | Leviathan compromised domain credentials during Leviathan Australian Intrusions. |
| T1078.003 Local Accounts |
CampaignAnthropic AI-orchestrated Campaign | During the Anthropic AI-orchestrated Campaign, the adversary used Claude Code to test credentials harvested against discovered devices. |
| T1078.003 Local Accounts |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used compromised local accounts to access victims' networks. |
| T1078.003 Local Accounts |
CampaignOperation Wocao | During Operation Wocao, threat actors used local account credentials found during the intrusion for lateral movement and privilege escalation. |
| T1078.003 Local Accounts |
CampaignLeviathan Australian Intrusions | Leviathan used captured local account information, such as service accounts, for actions during Leviathan Australian Intrusions. |
| T1078.004 Cloud Accounts |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used a compromised O365 administrator account to create a new Service Principal. |
| T1078.004 Cloud Accounts |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries leveraged stolen credentials from on-premises environments to access cloud services. |
| T1078.004 Cloud Accounts |
CampaignC0027 | During C0027, Scattered Spider leveraged compromised credentials from victim users to authenticate to Azure tenants. |
| T1082 System Information Discovery |
CampaignKV Botnet Activity | KV Botnet Activity includes use of native system tools, such as |
| T1082 System Information Discovery |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors fingerprinted targeted SharePoint servers to identify OS version and running processes. |
| T1082 System Information Discovery |
CampaignFrankenstein | During Frankenstein, the threat actors used Empire to obtain the compromised machine's name. |
| T1082 System Information Discovery |
CampaignRedDelta Modified PlugX Infection Chain Operations | Mustang Panda captured victim operating system type via User Agent analysis during RedDelta Modified PlugX Infection Chain Operations. |
| T1082 System Information Discovery |
CampaignOperation Honeybee | During Operation Honeybee, the threat actors collected the computer name, OS, and other system information using `cmd /c systeminfo > %temp%\ temp.ini`. |
| T1082 System Information Discovery |
CampaignCutting Edge | During Cutting Edge, threat actors used the ENUM4LINUX Perl script for discovery on Windows and Samba hosts. |
| T1082 System Information Discovery |
CampaignAnthropic AI-orchestrated Campaign | During the Anthropic AI-orchestrated Campaign, the adversary tasked Claude Code to query databases and systems in order to identify proprietary information, including system configurations and database types. |
| T1082 System Information Discovery |
CampaignJuicy Mix | During Juicy Mix, OilRig used a script to send the name of the compromised host via HTTP `POST` to register it with C2. |
| T1082 System Information Discovery |
CampaignOperation AkaiRyū | During Operation AkaiRyū, MirrorFace collected system information. |
| T1082 System Information Discovery |
CampaignFunnyDream | During FunnyDream, the threat actors used Systeminfo to collect information on targeted hosts. |
| T1082 System Information Discovery |
CampaignOperation CuckooBees | During Operation CuckooBees, the threat actors used the `systeminfo` command to gather details about a compromised system. |
| T1082 System Information Discovery |
CampaignArcaneDoor | ArcaneDoor included collection of victim device configuration information. |
| T1082 System Information Discovery |
CampaignOperation Wocao | During Operation Wocao, threat actors discovered the OS versions of systems connected to a targeted network. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.