Real-world descriptions of how a group, tool or campaign used a technique.
13 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1074.001 Local Data Staging |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors staged stolen data from web.config files to debug_dev.js. |
| T1074.001 Local Data Staging |
CampaignOperation Honeybee | During Operation Honeybee, stolen data was copied into a text file using the format `From <COMPUTER-NAME> (<Month>-<Day> <Hour>-<Minute>-<Second>).txt` prior to compression, encoding, and exfiltration. |
| T1074.001 Local Data Staging |
CampaignOperation MidnightEclipse | During Operation MidnightEclipse, threat actors copied files to the web application folder on compromised devices for exfiltration. |
| T1074.001 Local Data Staging |
CampaignAnthropic AI-orchestrated Campaign | During the Anthropic AI-orchestrated Campaign, the adversary used Claude Code to stage extracted data and operational documentation in structured markdown files on local systems prior to exfiltration. |
| T1074.001 Local Data Staging |
CampaignC0015 | During C0015, PowerView's file share enumeration results were stored in the file `c:\ProgramData\found_shares.txt`. |
| T1074.001 Local Data Staging |
CampaignJuicy Mix | During Juicy Mix, OilRig used browser data and credential stealer tools to stage stolen files named Cupdate, Eupdate, and IUpdate in the %TEMP% directory. |
| T1074.001 Local Data Staging |
CampaignC0032 | During the C0032 campaign, TEMP.Veles used staging folders that are infrequently used by legitimate users or processes to store data for exfiltration and tool deployment. |
| T1074.001 Local Data Staging |
CampaignAPT28 Nearest Neighbor Campaign | During APT28 Nearest Neighbor Campaign, APT28 staged captured credential information in the |
| T1074.001 Local Data Staging |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries compiled discovery data locally on the victim host in a file located within `C:\Windows\TEMP\outlog.txt`. |
| T1074.001 Local Data Staging |
CampaignAPT41 DUST | APT41 DUST involved exporting data from Oracle databases to local CSV files prior to exfiltration. |
| T1074.001 Local Data Staging |
CampaignOperation Wocao | During Operation Wocao, threat actors staged archived files in a temporary directory prior to exfiltration. |
| T1074.001 Local Data Staging |
CampaignLeviathan Australian Intrusions | Leviathan stored captured credential material on local log files on victim systems during Leviathan Australian Intrusions. |
| T1074.001 Local Data Staging |
CampaignC0017 | During C0017, APT41 copied the local `SAM` and `SYSTEM` Registry hives to a staging directory. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.