Real-world descriptions of how a group, tool or campaign used a technique.
21 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1190 Exploit Public-Facing Application |
CampaignFrostyGoop Incident | FrostyGoop Incident was likely enabled by the adversary exploiting an unknown vulnerability in an external-facing router. |
| T1190 Exploit Public-Facing Application |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors exploited authentication bypass and remote code execution vulnerabilities (CVE-2025-49706 and CVE-2025-49704) against on-premises SharePoint servers. This activity was characterized by crafted `POST` requests to the ToolPane endpoint `/_layouts/15/ToolPane.aspx`. |
| T1190 Exploit Public-Facing Application |
CampaignOperation MidnightEclipse | During Operation MidnightEclipse, threat actors exploited CVE-2024-3400 in Palo Alto Networks GlobalProtect. |
| T1190 Exploit Public-Facing Application |
CampaignCutting Edge | During Cutting Edge, threat actors exploited CVE-2023-46805 and CVE-2024-21887 in Ivanti Connect Secure VPN appliances to enable authentication bypass and command injection. A server-side request forgery (SSRF) vulnerability, CVE-2024-21893, was identified later and used to bypass mitigations for the initial two vulnerabilities by chaining with CVE-2024-21887. |
| T1190 Exploit Public-Facing Application |
CampaignC0018 | During C0018, the threat actors exploited VMWare Horizon Unified Access Gateways that were vulnerable to several Log4Shell vulnerabilities, including CVE-2021-44228, CVE-2021-45046, CVE-2021-45105, and CVE-2021-44832. |
| T1190 Exploit Public-Facing Application |
CampaignShadowRay | During ShadowRay, threat actors exploited CVE-2023-48022 on publicly exposed Ray servers to steal computing power and to expose sensitive data. |
| T1190 Exploit Public-Facing Application |
CampaignAnthropic AI-orchestrated Campaign | During the Anthropic AI-orchestrated Campaign, the adversary used Claude Code to deploy a custom exploit payload targeting an identified SSRF vulnerability to gain initial access to a targeted environment. |
| T1190 Exploit Public-Facing Application |
CampaignOperation Digital Eye | During Operation Digital Eye, threat actors used SQL injection to compromise publicly exposed web and database servers. |
| T1190 Exploit Public-Facing Application |
CampaignHomeLand Justice | For HomeLand Justice, threat actors exploited CVE-2019-0604 in Microsoft SharePoint for initial access. |
| T1190 Exploit Public-Facing Application |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 exploited CVE-2020-0688 against the Microsoft Exchange Control Panel to regain access to a network. |
| T1190 Exploit Public-Facing Application |
CampaignSPACEHOP Activity | SPACEHOP Activity has enabled the exploitation of CVE-2022-27518 and CVE-2022-27518 for illegitimate access. |
| T1190 Exploit Public-Facing Application |
CampaignOperation CuckooBees | During Operation CuckooBees, the threat actors exploited multiple vulnerabilities in externally facing servers. |
| T1190 Exploit Public-Facing Application |
CampaignArcaneDoor | ArcaneDoor abused WebVPN traffic to targeted devices to achieve unauthorized remote code execution. |
| T1190 Exploit Public-Facing Application |
CampaignNight Dragon | During Night Dragon, threat actors used SQL injection exploits against extranet web servers to gain access. |
| T1190 Exploit Public-Facing Application |
CampaignVersa Director Zero Day Exploitation | Versa Director Zero Day Exploitation involved exploitation of a vulnerability in Versa Director servers, since identified as CVE-2024-39717, for initial access and code execution. |
| T1190 Exploit Public-Facing Application |
CampaignOperation Wocao | During Operation Wocao, threat actors gained initial access by exploiting vulnerabilities in JBoss webservers. |
| T1190 Exploit Public-Facing Application |
CampaignLeviathan Australian Intrusions | Leviathan exploited public-facing web applications and appliances for initial access during Leviathan Australian Intrusions. |
| T1190 Exploit Public-Facing Application |
CampaignC0017 | During C0017, APT41 exploited CVE-2021-44207 in the USAHerds application and CVE-2021-44228 in Log4j, as well as other .NET deserialization, SQL injection, and directory traversal vulnerabilities to gain initial access. |
| T1190 Exploit Public-Facing Application |
CampaignC0027 | During C0027, Scattered Spider exploited CVE-2021-35464 in the ForgeRock Open Access Management (OpenAM) application server to gain initial access. |
| T1190 Exploit Public-Facing Application |
CampaignQuad7 Activity | Quad7 Activity has enabled the exploitation of vulnerabilities for remote code execution capabilities in SOHO routers including CVE-2023-50224 and CVE-2025-9377 in TP-Link devices. |
| T1190 Exploit Public-Facing Application |
CampaignFLORAHOX Activity | FLORAHOX Activity has exploited and infected vulnerable routers to recruit additional network devices into the ORB. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.