Real-world descriptions of how a group, tool or campaign used a technique.
9 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1021.001 Remote Desktop Protocol |
CampaignCutting Edge | During Cutting Edge, threat actors used RDP with compromised credentials for lateral movement. |
| T1021.001 Remote Desktop Protocol |
CampaignC0018 | During C0018, the threat actors opened a variety of ports to establish RDP connections, including ports 28035, 32467, 41578, and 46892. |
| T1021.001 Remote Desktop Protocol |
CampaignOperation Digital Eye | During Operation Digital Eye, threat actors moved laterally using RDP. |
| T1021.001 Remote Desktop Protocol |
CampaignC0015 | During C0015, the threat actors used RDP to access specific network hosts of interest. |
| T1021.001 Remote Desktop Protocol |
CampaignHomeLand Justice | During HomeLand Justice, threat actors primarily used RDP for lateral movement in the victim environment. |
| T1021.001 Remote Desktop Protocol |
CampaignC0032 | During the C0032 campaign, TEMP.Veles utilized RDP throughout an operation. |
| T1021.001 Remote Desktop Protocol |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used RDP sessions from public-facing systems to internal servers. |
| T1021.001 Remote Desktop Protocol |
CampaignAPT28 Nearest Neighbor Campaign | During APT28 Nearest Neighbor Campaign, APT28 used RDP for lateral movement. |
| T1021.001 Remote Desktop Protocol |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, adversaries utilized RDP to log into jump hosts and then moved laterally to other victim devices to include a domain controller. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.