ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1074.001×

13 examples

TechniqueUsed byProcedure example
T1074.001
Local Data Staging
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors staged stolen data from web.config files to debug_dev.js.

T1074.001
Local Data Staging
CampaignOperation Honeybee

During Operation Honeybee, stolen data was copied into a text file using the format `From <COMPUTER-NAME> (<Month>-<Day> <Hour>-<Minute>-<Second>).txt` prior to compression, encoding, and exfiltration.

T1074.001
Local Data Staging
CampaignOperation MidnightEclipse

During Operation MidnightEclipse, threat actors copied files to the web application folder on compromised devices for exfiltration.

T1074.001
Local Data Staging
CampaignAnthropic AI-orchestrated Campaign

During the Anthropic AI-orchestrated Campaign, the adversary used Claude Code to stage extracted data and operational documentation in structured markdown files on local systems prior to exfiltration.

T1074.001
Local Data Staging
CampaignC0015

During C0015, PowerView's file share enumeration results were stored in the file `c:\ProgramData\found_shares.txt`.

T1074.001
Local Data Staging
CampaignJuicy Mix

During Juicy Mix, OilRig used browser data and credential stealer tools to stage stolen files named Cupdate, Eupdate, and IUpdate in the %TEMP% directory.

T1074.001
Local Data Staging
CampaignC0032

During the C0032 campaign, TEMP.Veles used staging folders that are infrequently used by legitimate users or processes to store data for exfiltration and tool deployment.

T1074.001
Local Data Staging
CampaignAPT28 Nearest Neighbor Campaign

During APT28 Nearest Neighbor Campaign, APT28 staged captured credential information in the C:\ProgramData directory.

T1074.001
Local Data Staging
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries compiled discovery data locally on the victim host in a file located within `C:\Windows\TEMP\outlog.txt`.

T1074.001
Local Data Staging
CampaignAPT41 DUST

APT41 DUST involved exporting data from Oracle databases to local CSV files prior to exfiltration.

T1074.001
Local Data Staging
CampaignOperation Wocao

During Operation Wocao, threat actors staged archived files in a temporary directory prior to exfiltration.

T1074.001
Local Data Staging
CampaignLeviathan Australian Intrusions

Leviathan stored captured credential material on local log files on victim systems during Leviathan Australian Intrusions.

T1074.001
Local Data Staging
CampaignC0017

During C0017, APT41 copied the local `SAM` and `SYSTEM` Registry hives to a staging directory.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.