Real-world descriptions of how a group, tool or campaign used a technique.
26 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1588.002 Tool |
CampaignOperation Dream Job | For Operation Dream Job, Lazarus Group obtained tools such as Wake-On-Lan, Responder, ChromePass, and dbxcli. |
| T1588.002 Tool |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors leveraged tools including Impacket, PsExec, and Mimikatz. |
| T1588.002 Tool |
CampaignFrankenstein | For Frankenstein, the threat actors obtained and used Empire. |
| T1588.002 Tool |
CampaignOperation MidnightEclipse | During Operation MidnightEclipse, threat actors used the GO Simple Tunnel (GOST) reverse proxy tool. |
| T1588.002 Tool |
CampaignTriton Safety Instrumented System Attack | In the Triton Safety Instrumented System Attack, TEMP.Veles used tools such as Mimikatz and other open-source software. |
| T1588.002 Tool |
CampaignOperation Spalax | For Operation Spalax, the threat actors obtained packers such as CyaX. |
| T1588.002 Tool |
CampaignCutting Edge | During Cutting Edge, threat actors leveraged tools including Interactsh to identify vulnerable targets, PySoxy to simultaneously dispatch traffic between multiple endpoints, BusyBox to enable post exploitation activities, and Kubo Injector to inject shared objects into process memory. |
| T1588.002 Tool |
CampaignC0018 | For C0018, the threat actors acquired a variety of open source tools, including Mimikatz, Sliver, SoftPerfect Network Scanner, AnyDesk, and PDQ Deploy. |
| T1588.002 Tool |
CampaignShadowRay | During ShadowRay, threat actors used tools including the XMRig miner and Interactsh. |
| T1588.002 Tool |
CampaignAnthropic AI-orchestrated Campaign | During the Anthropic AI-orchestrated Campaign, the adversary obtained open-source penetration testing tools including network scanners, database exploitation frameworks, password crackers, and binary analysis suites. |
| T1588.002 Tool |
CampaignC0021 | For C0021, the threat actors used Cobalt Strike configured with a modified variation of the publicly available Pandora Malleable C2 Profile. |
| T1588.002 Tool |
CampaignOperation Digital Eye | During Operation Digital Eye, threat actors used third party tools including custom implementations of Mimikatz. |
| T1588.002 Tool |
CampaignC0015 | For C0015, the threat actors obtained a variety of tools, including AdFind, AnyDesk, and Process Hacker. |
| T1588.002 Tool |
CampaignHomeLand Justice | During HomeLand Justice, threat actors used tools including Advanced Port Scanner, Mimikatz, and Impacket. |
| T1588.002 Tool |
CampaignC0032 | During the C0032 campaign, TEMP.Veles obtained and used tools such as Mimikatz and PsExec. |
| T1588.002 Tool |
CampaignSPACEHOP Activity | SPACEHOP Activity leverages a C2 framework sourced from a publicly-available Github repository for administration of relay nodes. |
| T1588.002 Tool |
CampaignOperation AkaiRyū | During Operation AkaiRyū, MirrorFace deployed multiple publicly available tools including PuTTY, FRP, and Rubeus. |
| T1588.002 Tool |
CampaignFunnyDream | For FunnyDream, the threat actors used a modified version of the open source PcShare remote administration tool. |
| T1588.002 Tool |
CampaignOperation CuckooBees | For Operation CuckooBees, the threat actors obtained publicly-available JSP code that was used to deploy a webshell onto a compromised server. |
| T1588.002 Tool |
CampaignSalesforce Data Exfiltration | During Salesforce Data Exfiltration, threat actors initially relied on the legitimate Salesforce Data Loader app for data exfiltration. |
| T1588.002 Tool |
CampaignC0010 | For C0010, UNC3890 actors obtained multiple publicly-available tools, including METASPLOIT, UNICORN, and NorthStar C2. |
| T1588.002 Tool |
CampaignNight Dragon | During Night Dragon, threat actors obtained and used tools such as gsecdump. |
| T1588.002 Tool |
CampaignOperation Wocao | For Operation Wocao, the threat actors obtained a variety of open source tools, including JexBoss, KeeThief, and BloodHound. |
| T1588.002 Tool |
CampaignC0017 | For C0017, APT41 obtained publicly available tools such as YSoSerial.NET, ConfuserEx, and BadPotato. |
| T1588.002 Tool |
CampaignC0027 | During C0027, Scattered Spider obtained and used multiple tools including the LINpeas privilege escalation utility, aws_consoler, rsocx reverse proxy, Level RMM tool, and RustScan port scanner. |
| T1588.002 Tool |
CampaignCostaRicto | During CostaRicto, the threat actors obtained open source tools to use in their operations. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.