Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1529 System Shutdown/Reboot |
MalwareBlack Basta | Black Basta has used `ShellExecuteA` to shut down and restart the victim system. |
| T1529 System Shutdown/Reboot |
MalwareXLoader | XLoader can initiate a system reboot or shutdown. |
| T1529 System Shutdown/Reboot |
MalwareHermeticWiper | HermeticWiper can initiate a system shutdown. |
| T1529 System Shutdown/Reboot |
MalwareLookBack | LookBack can shutdown and reboot the victim machine. |
| T1529 System Shutdown/Reboot |
MalwareBFG Agonizer | BFG Agonizer uses elevated privileges to call |
| T1529 System Shutdown/Reboot |
MalwareMaze | Maze has issued a shutdown command on a victim machine that, upon reboot, will run the ransomware within a VM. |
| T1529 System Shutdown/Reboot |
MalwareKillDisk | KillDisk attempts to reboot the machine by terminating specific processes. |
| T1529 System Shutdown/Reboot |
MalwareQilin | Qilin can initiate a reboot of the backup server to hinder recovery. |
| T1529 System Shutdown/Reboot |
ToolRemcos | Remcos can shutdown and restart remote devices. |
| T1529 System Shutdown/Reboot |
MalwareCanisterWorm | CanisterWorm has forced the target system to reboot after file deletion. |
| T1530 Data from Cloud Storage |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries leveraged stolen credentials within cloud services to download targeted data from SharePoint, and Teams. |
| T1530 Data from Cloud Storage |
CampaignC0027 | During C0027, Scattered Spider accessed victim OneDrive environments to search for VPN and MFA enrollment information, help desk instructions, and new hire guides. |
| T1530 Data from Cloud Storage |
GroupHAFNIUM | HAFNIUM has exfitrated data from OneDrive. |
| T1530 Data from Cloud Storage |
GroupScattered Spider | Scattered Spider enumerates data stored in cloud resources for collection and exfiltration purposes. |
| T1530 Data from Cloud Storage |
GroupStorm-0501 | Storm-0501 had modified Azure Storage account resources through the `Microsoft.Storage/storageAccounts/write` operation to expose non-remotely accessible accounts for data exfiltration. |
| T1530 Data from Cloud Storage |
GroupAPT42 | APT42 has collected data from Microsoft 365 environments. |
| T1530 Data from Cloud Storage |
GroupFox Kitten | Fox Kitten has obtained files from the victim's cloud storage instances. |
| T1530 Data from Cloud Storage |
ToolPacu | Pacu can enumerate and download files stored in AWS storage services, such as S3 buckets. |
| T1530 Data from Cloud Storage |
ToolAADInternals | AADInternals can collect files from a user’s OneDrive. |
| T1530 Data from Cloud Storage |
ToolTruffleHog | TruffleHog has the ability to scan cloud storage services for credentials to include Amazon (AWS) S3 and Google Cloud Storage. |
| T1530 Data from Cloud Storage |
ToolPeirates | Peirates can dump the contents of AWS S3 buckets. It can also retrieve service account tokens from kOps buckets in Google Cloud Storage or S3. |
| T1530 Data from Cloud Storage |
GroupShinyHunters | ShinyHunters has collected data from insecure cloud buckets. |
| T1531 Account Access Removal |
GroupAkira | Akira deletes administrator accounts in victim networks prior to encryption. |
| T1531 Account Access Removal |
GroupLAPSUS$ | LAPSUS$ has removed a targeted organization's global admin accounts to lock the organization out of all access. |
| T1531 Account Access Removal |
MalwareLockerGoga | LockerGoga has been observed changing account passwords and logging off current users. |
| T1531 Account Access Removal |
MalwareMegaCortex | MegaCortex has changed user account passwords and logged users off the system. |
| T1531 Account Access Removal |
MalwareMeteor | Meteor has the ability to change the password of local users on compromised hosts and can log off users. |
| T1531 Account Access Removal |
MalwareDEADWOOD | DEADWOOD changes the password for local and domain users via |
| T1534 Internal Spearphishing |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group conducted internal spearphishing from within a compromised organization. |
| T1534 Internal Spearphishing |
GroupKimsuky | Kimsuky has sent internal spearphishing emails for lateral movement after stealing victim information. |
| T1534 Internal Spearphishing |
GroupMuddyWater | MuddyWater has used compromised mailboxes within target organizations to send spearphishing emails. |
| T1534 Internal Spearphishing |
GroupGamaredon Group | Gamaredon Group has used an Outlook VBA module on infected systems to send phishing emails with malicious attachments to other employees within the organization. |
| T1534 Internal Spearphishing |
GroupLeviathan | Leviathan has conducted internal spearphishing within the victim's environment for lateral movement. |
| T1534 Internal Spearphishing |
GroupAPT-C-36 | APT-C-36 has used a compromised account to send a phishing email to an address likely used and monitored by the IT team within the same targeted organization. |
| T1534 Internal Spearphishing |
GroupHEXANE | HEXANE has conducted internal spearphishing attacks against executives, HR, and IT personnel to gain information and access. |
| T1534 Internal Spearphishing |
MalwareSameCoin | SameCoin can send its Setup.exe file as an attachment to other addresses in the same compromised organization. |
| T1537 Transfer Data to Cloud Account |
GroupStorm-0501 | Storm-0501 has copied data from the victims environment to their own infrastructure leveraging AzCopy CLI. |
| T1537 Transfer Data to Cloud Account |
GroupRedCurl | RedCurl has used cloud storage to exfiltrate data, in particular the megatools utilities were used to exfiltrate data to Mega, a file storage service. |
| T1537 Transfer Data to Cloud Account |
GroupINC Ransom | INC Ransom has used Megasync to exfiltrate data to the cloud. |
| T1538 Cloud Service Dashboard |
GroupScattered Spider | Scattered Spider abused AWS Systems Manager Inventory to identify targets on the compromised network prior to lateral movement. |
| T1539 Steal Web Session Cookie |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 stole Chrome browser cookies by copying the Chrome profile directories of targeted users. |
| T1539 Steal Web Session Cookie |
GroupKimsuky | Kimsuky has used malware, such as TRANSLATEXT, to steal and exfiltrate browser cookies. |
| T1539 Steal Web Session Cookie |
GroupEvilnum | Evilnum can steal cookies and session information from browsers. |
| T1539 Steal Web Session Cookie |
GroupSandworm Team | Sandworm Team used information stealer malware to collect browser session cookies. |
| T1539 Steal Web Session Cookie |
GroupScattered Spider | Scattered Spider retrieves browser cookies via Raccoon Stealer. |
| T1539 Steal Web Session Cookie |
GroupLotus Blossom | Lotus Blossom has used publicly-available tools to steal cookies from browsers such as Chrome. |
| T1539 Steal Web Session Cookie |
GroupStar Blizzard | Star Blizzard has used EvilGinx to steal the session cookies of victims directed to |
| T1539 Steal Web Session Cookie |
GroupLuminousMoth | LuminousMoth has used an unnamed post-exploitation tool to steal cookies from the Chrome browser. |
| T1539 Steal Web Session Cookie |
GroupAPT42 | APT42 has used custom malware to steal login and cookie data from common browsers. |
| T1539 Steal Web Session Cookie |
MalwareTRANSLATEXT | TRANSLATEXT has exfiltrated updated cookies from Google, Naver, Kakao or Daum to the C2 server. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.