Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1518.001 Security Software Discovery |
MalwareComnie | Comnie attempts to detect several anti-virus products. |
| T1518.001 Security Software Discovery |
MalwareLizar | Lizar can search for processes associated with an anti-virus product from list. |
| T1518.001 Security Software Discovery |
ToolSILENTTRINITY | SILENTTRINITY can determine if an anti-virus product is installed through the resolution of the service's virtual SID. |
| T1518.001 Security Software Discovery |
ToolPacu | Pacu can enumerate AWS security services, including WAF rules and GuardDuty detectors. |
| T1518.001 Security Software Discovery |
ToolTasklist | Tasklist can be used to enumerate security software currently running on a system by process name of known products. |
| T1518.001 Security Software Discovery |
ToolEmpire | Empire can enumerate antivirus software on the target. |
| T1518.001 Security Software Discovery |
Toolnetsh | netsh can be used to discover system firewall settings. |
| T1518.001 Security Software Discovery |
ToolBrute Ratel C4 | Brute Ratel C4 can detect EDR userland hooks. |
| T1518.001 Security Software Discovery |
MalwareFlame | Flame identifies security software such as antivirus through the Security module. |
| T1518.002 Backup Software Discovery |
GroupWizard Spider | Wizard Spider has utilized the PowerShell script `Get-DataInfo.ps1` to collect installed backup software information from a compromised machine. |
| T1526 Cloud Service Discovery |
GroupStorm-0501 | Storm-0501 has discovered the victim environment’s protections to include Azure policies, resource locks, and Azure Storage immutability policies. |
| T1526 Cloud Service Discovery |
ToolPacu | Pacu can enumerate AWS services, such as CloudTrail and CloudWatch. |
| T1526 Cloud Service Discovery |
ToolAADInternals | AADInternals can enumerate information about a variety of cloud services, such as Office 365 and Sharepoint instances or OpenID Configurations. |
| T1526 Cloud Service Discovery |
ToolROADTools | ROADTools can enumerate Azure AD applications and service principals. |
| T1526 Cloud Service Discovery |
ToolTruffleHog | TruffleHog has the ability to scan code repositories and CI/CD platforms. |
| T1526 Cloud Service Discovery |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer can search GitHub for Actions runner processes. |
| T1528 Steal Application Access Token |
CampaignLeviathan Australian Intrusions | Leviathan abused access to compromised appliances to collect JSON Web Tokens (JWTs), used for creating virtual desktop sessions, during Leviathan Australian Intrusions. |
| T1528 Steal Application Access Token |
GroupAPT29 | APT29 uses stolen tokens to access victim accounts, without needing a password. |
| T1528 Steal Application Access Token |
GroupAPT28 | APT28 has used several malicious applications to steal user OAuth access tokens including applications masquerading as "Google Defender" "Google Email Protection," and "Google Scanner" for Gmail users. They also targeted Yahoo users with applications masquerading as "Delivery Service" and "McAfee Email Protection". |
| T1528 Steal Application Access Token |
MalwareShai-Hulud | Shai-Hulud has stolen access tokens and API tokens from with CI/CD pipeline solutions and repositories. |
| T1528 Steal Application Access Token |
ToolAADInternals | AADInternals can steal users’ access tokens via phishing emails containing malicious links. |
| T1528 Steal Application Access Token |
ToolTruffleHog | TruffleHog has gathered access tokens and API tokens from CI/CD pipeline solutions and repositories. |
| T1528 Steal Application Access Token |
ToolPeirates | Peirates gathers Kubernetes service account tokens using a variety of techniques. |
| T1528 Steal Application Access Token |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer can read runner.worker process memory to extract plaintext tokens. |
| T1528 Steal Application Access Token |
MalwareMini Shai-Hulud | Mini Shai-Hulud has stolen application access tokens and other tokens to include those associated with CI/CD. |
| T1528 Steal Application Access Token |
MalwareCanisterWorm | CanisterWorm has gathered cloud access tokens. |
| T1528 Steal Application Access Token |
GroupTeamPCP | TeamPCP has used malware to steal access tokens from targeted cloud and developer environments. |
| T1528 Steal Application Access Token |
GroupShinyHunters | ShinyHunters has stolen valid OAuth credentials from DevOps personnel or a company GitHub repository. Additionally, ShinyHunters has stolen application access tokens to access cloud services and to bypass authentication mechanisms. |
| T1528 Steal Application Access Token |
MalwareKali365 | Kali365 has obtained OAuth access and refresh tokens by deceiving victims into completing actor-initiated device authorization requests, and intercepting authentication sessions with legitimate identity providers through adversary-in-the-middle reverse proxy infrastructure. |
| T1529 System Shutdown/Reboot |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries forced victim devices to reboot to finalize destruction of impacted systems. |
| T1529 System Shutdown/Reboot |
GroupAPT38 | APT38 has used a custom MBR wiper named BOOTWRECK, which will initiate a system reboot after wiping the victim's MBR. |
| T1529 System Shutdown/Reboot |
GroupAPT37 | APT37 has used malware that will issue the command |
| T1529 System Shutdown/Reboot |
GroupMedusa Group | Medusa Group has manually turned off and encrypted virtual machines. |
| T1529 System Shutdown/Reboot |
GroupLazarus Group | Lazarus Group has rebooted systems after destroying files and wiping the MBR on infected systems. |
| T1529 System Shutdown/Reboot |
MalwareAcidRain | AcidRain reboots the target system once the various wiping processes are complete. |
| T1529 System Shutdown/Reboot |
MalwareAvosLocker | AvosLocker’s Linux variant has terminated ESXi virtual machines. |
| T1529 System Shutdown/Reboot |
MalwareOlympic Destroyer | Olympic Destroyer will shut down the compromised system after it is done modifying system configuration settings. |
| T1529 System Shutdown/Reboot |
MalwareDynoWiper | DynoWiper has used the Microsoft Windows native `ExitWindowsEx()` function to log off the interactive user and shutdown the system. |
| T1529 System Shutdown/Reboot |
MalwareShrinkLocker | ShrinkLocker can restart the victim system if it encounters an error during execution, and will forcibly shutdown the system following encryption to lock out victim users. |
| T1529 System Shutdown/Reboot |
MalwareApostle | Apostle reboots the victim machine following wiping and related activity. |
| T1529 System Shutdown/Reboot |
MalwareWhisperGate | WhisperGate can shutdown a compromised host through execution of `ExitWindowsEx` with the `EXW_SHUTDOWN` flag. |
| T1529 System Shutdown/Reboot |
MalwareAcidPour | AcidPour includes functionality to reboot the victim system following wiping actions, similar to AcidRain. |
| T1529 System Shutdown/Reboot |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP can reboot or shutdown the targeted system or logoff the current user. |
| T1529 System Shutdown/Reboot |
MalwareDCSrv | DCSrv has a function to sleep for two hours before rebooting the system. |
| T1529 System Shutdown/Reboot |
MalwareNotPetya | NotPetya will reboot the system one hour after infection. |
| T1529 System Shutdown/Reboot |
MalwareLockerGoga | LockerGoga has been observed shutting down infected systems. |
| T1529 System Shutdown/Reboot |
MalwareMultiLayer Wiper | MultiLayer Wiper reboots the infected system following wiping and related tasks to prevent system recovery. |
| T1529 System Shutdown/Reboot |
MalwareDarkGate | DarkGate has used the `shutdown`command to shut down and/or restart the victim system. |
| T1529 System Shutdown/Reboot |
MalwareLatrodectus | Latrodectus has the ability to restart compromised hosts. |
| T1529 System Shutdown/Reboot |
MalwareShamoon | Shamoon will reboot the infected system once the wiping functionality has been completed. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.