ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1595.002×

15 examples

TechniqueUsed byProcedure example
T1595.002
Vulnerability Scanning
GroupAPT41

APT41 used the Acunetix SQL injection vulnerability scanner in target reconnaissance operations, as well as the JexBoss tool to identify vulnerabilities in Java applications.

T1595.002
Vulnerability Scanning
GroupDragonfly

Dragonfly has scanned targeted systems for vulnerable Citrix and Microsoft Exchange services.

T1595.002
Vulnerability Scanning
GroupTeamTNT

TeamTNT has scanned for vulnerabilities in IoT devices and other related resources such as the Docker API.

T1595.002
Vulnerability Scanning
GroupSandworm Team

Sandworm Team has scanned network infrastructure for vulnerabilities as part of its operational planning.

T1595.002
Vulnerability Scanning
GroupAquatic Panda

Aquatic Panda has used publicly accessible DNS logging services to identify servers vulnerable to Log4j (CVE 2021-44228).

T1595.002
Vulnerability Scanning
GroupLeviathan

Leviathan has conducted reconnaissance against target networks of interest looking for vulnerable, end-of-life, or no longer maintainted devices against which to rapidly deploy exploits.

T1595.002
Vulnerability Scanning
GroupWinter Vivern

Winter Vivern has used remotely-hosted instances of the Acunetix vulnerability scanner.

T1595.002
Vulnerability Scanning
GroupAPT29

APT29 has conducted widespread scanning of target environments to identify vulnerabilities for exploit.

T1595.002
Vulnerability Scanning
GroupEmber Bear

Ember Bear has used publicly available tools such as MASSCAN and Acunetix for vulnerability scanning of public-facing infrastructure.

T1595.002
Vulnerability Scanning
GroupVolatile Cedar

Volatile Cedar has performed vulnerability scans of the target server.

T1595.002
Vulnerability Scanning
GroupAPT28

APT28 has performed large-scale scans in an attempt to find vulnerable servers.

T1595.002
Vulnerability Scanning
GroupEarth Lusca

Earth Lusca has scanned for vulnerabilities in the public-facing servers of their targets.

T1595.002
Vulnerability Scanning
GroupVOID MANTICORE

VOID MANTICORE has scanned victim environments for susceptibility to vulnerability exploitation.

T1595.002
Vulnerability Scanning
GroupMagic Hound

Magic Hound has conducted widespread scanning to identify public-facing systems vulnerable to CVE-2021-44228 in Log4j and ProxyShell vulnerabilities; CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065 in on-premises MS Exchange Servers; and CVE-2018-13379 in Fortinet FortiOS SSL VPNs.

T1595.002
Vulnerability Scanning
GroupShinyHunters

ShinyHunters has searched through victim companies’ GitHub repositories for vulnerabilities.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.