ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1588.002×

26 examples

TechniqueUsed byProcedure example
T1588.002
Tool
CampaignOperation Dream Job

For Operation Dream Job, Lazarus Group obtained tools such as Wake-On-Lan, Responder, ChromePass, and dbxcli.

T1588.002
Tool
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors leveraged tools including Impacket, PsExec, and Mimikatz.

T1588.002
Tool
CampaignFrankenstein

For Frankenstein, the threat actors obtained and used Empire.

T1588.002
Tool
CampaignOperation MidnightEclipse

During Operation MidnightEclipse, threat actors used the GO Simple Tunnel (GOST) reverse proxy tool.

T1588.002
Tool
CampaignTriton Safety Instrumented System Attack

In the Triton Safety Instrumented System Attack, TEMP.Veles used tools such as Mimikatz and other open-source software.

T1588.002
Tool
CampaignOperation Spalax

For Operation Spalax, the threat actors obtained packers such as CyaX.

T1588.002
Tool
CampaignCutting Edge

During Cutting Edge, threat actors leveraged tools including Interactsh to identify vulnerable targets, PySoxy to simultaneously dispatch traffic between multiple endpoints, BusyBox to enable post exploitation activities, and Kubo Injector to inject shared objects into process memory.

T1588.002
Tool
CampaignC0018

For C0018, the threat actors acquired a variety of open source tools, including Mimikatz, Sliver, SoftPerfect Network Scanner, AnyDesk, and PDQ Deploy.

T1588.002
Tool
CampaignShadowRay

During ShadowRay, threat actors used tools including the XMRig miner and Interactsh.

T1588.002
Tool
CampaignAnthropic AI-orchestrated Campaign

During the Anthropic AI-orchestrated Campaign, the adversary obtained open-source penetration testing tools including network scanners, database exploitation frameworks, password crackers, and binary analysis suites.

T1588.002
Tool
CampaignC0021

For C0021, the threat actors used Cobalt Strike configured with a modified variation of the publicly available Pandora Malleable C2 Profile.

T1588.002
Tool
CampaignOperation Digital Eye

During Operation Digital Eye, threat actors used third party tools including custom implementations of Mimikatz.

T1588.002
Tool
CampaignC0015

For C0015, the threat actors obtained a variety of tools, including AdFind, AnyDesk, and Process Hacker.

T1588.002
Tool
CampaignHomeLand Justice

During HomeLand Justice, threat actors used tools including Advanced Port Scanner, Mimikatz, and Impacket.

T1588.002
Tool
CampaignC0032

During the C0032 campaign, TEMP.Veles obtained and used tools such as Mimikatz and PsExec.

T1588.002
Tool
CampaignSPACEHOP Activity

SPACEHOP Activity leverages a C2 framework sourced from a publicly-available Github repository for administration of relay nodes.

T1588.002
Tool
CampaignOperation AkaiRyū

During Operation AkaiRyū, MirrorFace deployed multiple publicly available tools including PuTTY, FRP, and Rubeus.

T1588.002
Tool
CampaignFunnyDream

For FunnyDream, the threat actors used a modified version of the open source PcShare remote administration tool.

T1588.002
Tool
CampaignOperation CuckooBees

For Operation CuckooBees, the threat actors obtained publicly-available JSP code that was used to deploy a webshell onto a compromised server.

T1588.002
Tool
CampaignSalesforce Data Exfiltration

During Salesforce Data Exfiltration, threat actors initially relied on the legitimate Salesforce Data Loader app for data exfiltration.

T1588.002
Tool
CampaignC0010

For C0010, UNC3890 actors obtained multiple publicly-available tools, including METASPLOIT, UNICORN, and NorthStar C2.

T1588.002
Tool
CampaignNight Dragon

During Night Dragon, threat actors obtained and used tools such as gsecdump.

T1588.002
Tool
CampaignOperation Wocao

For Operation Wocao, the threat actors obtained a variety of open source tools, including JexBoss, KeeThief, and BloodHound.

T1588.002
Tool
CampaignC0017

For C0017, APT41 obtained publicly available tools such as YSoSerial.NET, ConfuserEx, and BadPotato.

T1588.002
Tool
CampaignC0027

During C0027, Scattered Spider obtained and used multiple tools including the LINpeas privilege escalation utility, aws_consoler, rsocx reverse proxy, Level RMM tool, and RustScan port scanner.

T1588.002
Tool
CampaignCostaRicto

During CostaRicto, the threat actors obtained open source tools to use in their operations.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.