Real-world descriptions of how a group, tool or campaign used a technique.
131 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1059.001 PowerShell |
MalwareTrickBot | TrickBot has been known to use PowerShell to download new payloads, open documents, and upload data to command and control servers. |
| T1059.001 PowerShell |
MalwareBumblebee | Bumblebee can use PowerShell for execution. |
| T1059.001 PowerShell |
MalwareGRIFFON | GRIFFON has used PowerShell to execute the Meterpreter downloader TinyMet. |
| T1059.001 PowerShell |
MalwarePOWRUNER | POWRUNER is written in PowerShell. |
| T1059.001 PowerShell |
MalwareSharpStage | SharpStage can execute arbitrary commands with PowerShell. |
| T1059.001 PowerShell |
MalwareSardonic | Sardonic has the ability to execute PowerShell commands on a compromised machine. |
| T1059.001 PowerShell |
MalwareHALFBAKED | HALFBAKED can execute PowerShell scripts. |
| T1059.001 PowerShell |
MalwareTAMECAT | TAMECAT has used PowerShell to download and run additional content. |
| T1059.001 PowerShell |
MalwarePS1 | PS1 can utilize a PowerShell loader. |
| T1059.001 PowerShell |
MalwareUrsnif | Ursnif droppers have used PowerShell in download cradles to download and execute the malware's full executable payload. |
| T1059.001 PowerShell |
MalwareRansomHub | RansomHub can use PowerShell to delete volume shadow copies. |
| T1059.001 PowerShell |
MalwarePOWERSOURCE | POWERSOURCE is a PowerShell backdoor. |
| T1059.001 PowerShell |
MalwareTsundere Botnet | Tsundere Botnet has been distributed via a PowerShell script. |
| T1059.001 PowerShell |
MalwareZeus Panda | Zeus Panda uses PowerShell to download and execute the payload. |
| T1059.001 PowerShell |
MalwareHavoc | Havoc can facilitate the execution of PowerShell commands. |
| T1059.001 PowerShell |
MalwarePrestige | Prestige can use PowerShell for payload execution on targeted systems. |
| T1059.001 PowerShell |
MalwareInvisibleFerret | InvisibleFerret has utilized a PowerShell script created in the victim’s home directory named “conf.ps1” that is used to modify configuration files for AnyDesk remote services. |
| T1059.001 PowerShell |
MalwareStrongPity | StrongPity can use PowerShell to add files to the Windows Defender exclusions list. |
| T1059.001 PowerShell |
MalwareMedusa Ransomware | Medusa Ransomware has launched PowerShell scripts for execution and defense evasion. |
| T1059.001 PowerShell |
MalwareAppleSeed | AppleSeed has the ability to execute its payload via PowerShell. |
| T1059.001 PowerShell |
MalwareNETWIRE | The NETWIRE binary has been executed via PowerShell script. |
| T1059.001 PowerShell |
MalwarePyDCrypt | PyDCrypt has attempted to execute with PowerShell. |
| T1059.001 PowerShell |
MalwarePowerExchange | PowerExchange can use PowerShell to execute commands received from C2. |
| T1059.001 PowerShell |
MalwareHAMMERTOSS | HAMMERTOSS is known to use PowerShell. |
| T1059.001 PowerShell |
MalwareEmotet | Emotet has used Powershell to retrieve the malicious payload and download additional resources like Mimikatz. |
| T1059.001 PowerShell |
MalwareBADHATCH | BADHATCH can utilize `powershell.exe` to execute commands on a compromised host. |
| T1059.001 PowerShell |
MalwarePowerLess | PowerLess is written in and executed via PowerShell without using powershell.exe. |
| T1059.001 PowerShell |
MalwareSystemBC | SystemBC has used hidden scheduled tasks to execute PowerShell commands by adding the following: `-WindowStyle Hidden -ep bypass -file `. |
| T1059.001 PowerShell |
MalwareGootloader | Gootloader can use an encoded PowerShell stager to write to the Registry for persistence. |
| T1059.001 PowerShell |
MalwareWellMess | WellMess can execute PowerShell scripts received from C2. |
| T1059.001 PowerShell |
MalwareWoody RAT | Woody RAT can execute PowerShell commands and scripts with the use of .NET DLL, `WoodyPowerSession`. |
| T1059.001 PowerShell |
MalwareMafalda | Mafalda can execute PowerShell commands on a compromised machine. |
| T1059.001 PowerShell |
MalwareSquirrelwaffle | Squirrelwaffle has used PowerShell to execute its payload. |
| T1059.001 PowerShell |
MalwareShrinkLocker | ShrinkLocker uses PowerShell to disable protectors used to secure the BitLocker encryption key on victim machines and then delete the key from the system. |
| T1059.001 PowerShell |
MalwareFlawedAmmyy | FlawedAmmyy has used PowerShell to execute commands. |
| T1059.001 PowerShell |
MalwareSnip3 | Snip3 can use a PowerShell script for second-stage execution. |
| T1059.001 PowerShell |
MalwareRegDuke | RegDuke can extract and execute PowerShell scripts from C2 communications. |
| T1059.001 PowerShell |
MalwareWhisperGate | WhisperGate can use PowerShell to support multiple actions including execution and defense evasion. |
| T1059.001 PowerShell |
MalwareTRANSLATEXT | TRANSLATEXT has used PowerShell to collect system information and to upload the collected data to a Github repository. |
| T1059.001 PowerShell |
MalwarePowerShower | PowerShower is a backdoor written in PowerShell. |
| T1059.001 PowerShell |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP can invoke the PowerShell command `[Reflection.Assembly]::LoadFile(\"%s\")\n$i=\"\"\n$r=[%s]::%s(\"%s\",[ref] $i)\necho $r,$i\n` to execute secondary payloads. |
| T1059.001 PowerShell |
MalwareFatDuke | FatDuke has the ability to execute PowerShell scripts. |
| T1059.001 PowerShell |
MalwareGLASSTOKEN | GLASSTOKEN can use PowerShell for command execution. |
| T1059.001 PowerShell |
MalwarePUNCHBUGGY | PUNCHBUGGY has used PowerShell scripts. |
| T1059.001 PowerShell |
MalwareKeyBoy | KeyBoy uses PowerShell commands to download and execute payloads. |
| T1059.001 PowerShell |
MalwarePOSHSPY | POSHSPY uses PowerShell to execute various commands, one to execute its payload. |
| T1059.001 PowerShell |
MalwareDarkWatchman | DarkWatchman can execute PowerShell commands and has used PowerShell to execute a keylogger. |
| T1059.001 PowerShell |
MalwareLumma Stealer | Lumma Stealer has used PowerShell for initial user execution and other fuctions. |
| T1059.001 PowerShell |
MalwareSeaDuke | SeaDuke uses a module to execute Mimikatz with PowerShell to perform Pass the Ticket. |
| T1059.001 PowerShell |
MalwareXbash | Xbash can use scripts to invoke PowerShell to download a malicious PE executable or PE DLL for execution. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.