ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1021.001×

9 examples

TechniqueUsed byProcedure example
T1021.001
Remote Desktop Protocol
CampaignCutting Edge

During Cutting Edge, threat actors used RDP with compromised credentials for lateral movement.

T1021.001
Remote Desktop Protocol
CampaignC0018

During C0018, the threat actors opened a variety of ports to establish RDP connections, including ports 28035, 32467, 41578, and 46892.

T1021.001
Remote Desktop Protocol
CampaignOperation Digital Eye

During Operation Digital Eye, threat actors moved laterally using RDP.

T1021.001
Remote Desktop Protocol
CampaignC0015

During C0015, the threat actors used RDP to access specific network hosts of interest.

T1021.001
Remote Desktop Protocol
CampaignHomeLand Justice

During HomeLand Justice, threat actors primarily used RDP for lateral movement in the victim environment.

T1021.001
Remote Desktop Protocol
CampaignC0032

During the C0032 campaign, TEMP.Veles utilized RDP throughout an operation.

T1021.001
Remote Desktop Protocol
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used RDP sessions from public-facing systems to internal servers.

T1021.001
Remote Desktop Protocol
CampaignAPT28 Nearest Neighbor Campaign

During APT28 Nearest Neighbor Campaign, APT28 used RDP for lateral movement.

T1021.001
Remote Desktop Protocol
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, adversaries utilized RDP to log into jump hosts and then moved laterally to other victim devices to include a domain controller.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.