Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1059.003 Windows Command Shell |
GroupMetador | Metador has used the Windows command line to execute commands. |
| T1059.003 Windows Command Shell |
GroupAPT5 | APT5 has used cmd.exe for execution on compromised systems. |
| T1059.003 Windows Command Shell |
GroupFox Kitten | Fox Kitten has used cmd.exe likely as a password changing mechanism. |
| T1059.003 Windows Command Shell |
GroupLazarus Group | Lazarus Group malware uses cmd.exe to execute commands on a compromised host. A Destover-like variant used by Lazarus Group uses a batch file mechanism to delete its binaries from the system. |
| T1059.003 Windows Command Shell |
GroupINC Ransom | INC Ransom has used `cmd.exe` to launch malicious payloads. |
| T1059.003 Windows Command Shell |
GroupSilence | Silence has used Windows command-line to run commands. |
| T1059.003 Windows Command Shell |
GroupSowbug | Sowbug has used command line during its intrusions. |
| T1059.003 Windows Command Shell |
GroupThreat Group-1314 | Threat Group-1314 actors spawned shells on remote systems on a victim network to execute commands. |
| T1059.003 Windows Command Shell |
GroupCobalt Group | Cobalt Group has used a JavaScript backdoor that is capable of launching cmd.exe to execute shell commands. The group has used an exploit toolkit known as Threadkit that launches .bat files. |
| T1059.003 Windows Command Shell |
GroupWizard Spider | Wizard Spider has used `cmd.exe` to execute commands on a victim's machine. |
| T1059.003 Windows Command Shell |
GroupPlay | Play has used a batch script to remove indicators of its presence on compromised hosts. |
| T1059.003 Windows Command Shell |
GroupRancor | Rancor has used cmd.exe to execute commmands. |
| T1059.003 Windows Command Shell |
GroupWIRTE | WIRTE has used the Windows command line as part of infection chains to open documents. |
| T1059.003 Windows Command Shell |
GroupMagic Hound | Magic Hound has used the command-line interface for code execution. |
| T1059.003 Windows Command Shell |
GroupThreat Group-3390 | Threat Group-3390 has used command-line interfaces for execution. |
| T1059.003 Windows Command Shell |
GroupFIN10 | FIN10 has executed malicious .bat files containing PowerShell commands. |
| T1059.003 Windows Command Shell |
GroupFIN8 | FIN8 has used a Batch file to automate frequently executed post compromise cleanup activities. FIN8 has also executed commands remotely via `cmd.exe`. |
| T1059.003 Windows Command Shell |
GroupFIN13 | FIN13 has leveraged `xp_cmdshell` and Windows Command Shell to execute commands on a compromised machine. FIN13 has also attempted to leverage the ‘xp_cmdshell’ SQL procedure to execute remote commands on internal MS-SQL servers. |
| T1059.003 Windows Command Shell |
GroupNomadic Octopus | Nomadic Octopus used |
| T1059.003 Windows Command Shell |
MalwareTrickBot | TrickBot has used macros in Excel documents to download and deploy the malware on the user’s machine. |
| T1059.003 Windows Command Shell |
MalwarePowerDuke | PowerDuke runs |
| T1059.003 Windows Command Shell |
MalwareBLINDINGCAN | BLINDINGCAN has executed commands via cmd.exe. |
| T1059.003 Windows Command Shell |
MalwarePikabot | Pikabot can execute Windows shell commands via |
| T1059.003 Windows Command Shell |
MalwareWiarp | Wiarp creates a backdoor through which remote attackers can open a command line interface. |
| T1059.003 Windows Command Shell |
MalwareRCSession | RCSession can use `cmd.exe` for execution on compromised hosts. |
| T1059.003 Windows Command Shell |
MalwareSpark | Spark can use cmd.exe to run commands. |
| T1059.003 Windows Command Shell |
MalwareBumblebee | Bumblebee can use `cmd.exe` to drop and run files. |
| T1059.003 Windows Command Shell |
MalwareMURKYTOP | MURKYTOP uses the command-line interface. |
| T1059.003 Windows Command Shell |
MalwareExaramel for Windows | Exaramel for Windows has a command to launch a remote shell and executes commands on the victim’s machine. |
| T1059.003 Windows Command Shell |
MalwareProxysvc | Proxysvc executes a binary on the system and logs the results into a temp file by using: |
| T1059.003 Windows Command Shell |
MalwareOrz | Orz can execute shell commands. Orz can execute commands with JavaScript. |
| T1059.003 Windows Command Shell |
MalwareIronWind | IronWind has used the Windows command shell to execute malicious files. |
| T1059.003 Windows Command Shell |
MalwareSEASHARPEE | SEASHARPEE can execute commands on victims. |
| T1059.003 Windows Command Shell |
MalwarePOWRUNER | POWRUNER can execute commands from its C2 server. |
| T1059.003 Windows Command Shell |
MalwareRobbinHood | RobbinHood uses cmd.exe on the victim's computer. |
| T1059.003 Windows Command Shell |
MalwareTDTESS | TDTESS provides a reverse shell on the victim. |
| T1059.003 Windows Command Shell |
MalwareSharpStage | SharpStage can execute arbitrary commands with the command line. |
| T1059.003 Windows Command Shell |
MalwareSardonic | Sardonic has the ability to run `cmd.exe` or other interactive processes on a compromised computer. |
| T1059.003 Windows Command Shell |
MalwareMisdat | Misdat is capable of providing shell functionality to the attacker to execute commands. |
| T1059.003 Windows Command Shell |
Malwareadbupd | adbupd can run a copy of cmd.exe. |
| T1059.003 Windows Command Shell |
MalwareEmissary | Emissary has the capability to create a remote shell and execute specified commands. |
| T1059.003 Windows Command Shell |
MalwareKEYMARBLE | KEYMARBLE can execute shell commands using cmd.exe. |
| T1059.003 Windows Command Shell |
MalwareHAWKBALL | HAWKBALL has created a cmd.exe reverse shell, executed commands, and uploaded output via the command line. |
| T1059.003 Windows Command Shell |
MalwareTAMECAT | TAMECAT has used `cmd.exe` to run the `curl` command. |
| T1059.003 Windows Command Shell |
MalwareHeartCrypt | HeartCrypt can use the `reg add` command via `cmd.exe` for Registry modification. |
| T1059.003 Windows Command Shell |
MalwareRansomHub | RansomHub can use `cmd.exe` to execute multiple commands on infected hosts. |
| T1059.003 Windows Command Shell |
MalwareZLib | ZLib has the ability to execute shell commands. |
| T1059.003 Windows Command Shell |
MalwareRedLeaves | RedLeaves can receive and execute commands with cmd.exe. It can also provide a reverse shell. |
| T1059.003 Windows Command Shell |
MalwareFelismus | Felismus uses command line for execution. |
| T1059.003 Windows Command Shell |
MalwareZeus Panda | Zeus Panda can launch an interface where it can execute several commands on the victim’s PC. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.