ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1059.003
Windows Command Shell
GroupMetador

Metador has used the Windows command line to execute commands.

T1059.003
Windows Command Shell
GroupAPT5

APT5 has used cmd.exe for execution on compromised systems.

T1059.003
Windows Command Shell
GroupFox Kitten

Fox Kitten has used cmd.exe likely as a password changing mechanism.

T1059.003
Windows Command Shell
GroupLazarus Group

Lazarus Group malware uses cmd.exe to execute commands on a compromised host. A Destover-like variant used by Lazarus Group uses a batch file mechanism to delete its binaries from the system.

T1059.003
Windows Command Shell
GroupINC Ransom

INC Ransom has used `cmd.exe` to launch malicious payloads.

T1059.003
Windows Command Shell
GroupSilence

Silence has used Windows command-line to run commands.

T1059.003
Windows Command Shell
GroupSowbug

Sowbug has used command line during its intrusions.

T1059.003
Windows Command Shell
GroupThreat Group-1314

Threat Group-1314 actors spawned shells on remote systems on a victim network to execute commands.

T1059.003
Windows Command Shell
GroupCobalt Group

Cobalt Group has used a JavaScript backdoor that is capable of launching cmd.exe to execute shell commands. The group has used an exploit toolkit known as Threadkit that launches .bat files.

T1059.003
Windows Command Shell
GroupWizard Spider

Wizard Spider has used `cmd.exe` to execute commands on a victim's machine.

T1059.003
Windows Command Shell
GroupPlay

Play has used a batch script to remove indicators of its presence on compromised hosts.

T1059.003
Windows Command Shell
GroupRancor

Rancor has used cmd.exe to execute commmands.

T1059.003
Windows Command Shell
GroupWIRTE

WIRTE has used the Windows command line as part of infection chains to open documents.

T1059.003
Windows Command Shell
GroupMagic Hound

Magic Hound has used the command-line interface for code execution.

T1059.003
Windows Command Shell
GroupThreat Group-3390

Threat Group-3390 has used command-line interfaces for execution.

T1059.003
Windows Command Shell
GroupFIN10

FIN10 has executed malicious .bat files containing PowerShell commands.

T1059.003
Windows Command Shell
GroupFIN8

FIN8 has used a Batch file to automate frequently executed post compromise cleanup activities. FIN8 has also executed commands remotely via `cmd.exe`.

T1059.003
Windows Command Shell
GroupFIN13

FIN13 has leveraged `xp_cmdshell` and Windows Command Shell to execute commands on a compromised machine. FIN13 has also attempted to leverage the ‘xp_cmdshell’ SQL procedure to execute remote commands on internal MS-SQL servers.

T1059.003
Windows Command Shell
GroupNomadic Octopus

Nomadic Octopus used cmd.exe /c within a malicious macro.

T1059.003
Windows Command Shell
MalwareTrickBot

TrickBot has used macros in Excel documents to download and deploy the malware on the user’s machine.

T1059.003
Windows Command Shell
MalwarePowerDuke

PowerDuke runs cmd.exe /c and sends the output to its C2.

T1059.003
Windows Command Shell
MalwareBLINDINGCAN

BLINDINGCAN has executed commands via cmd.exe.

T1059.003
Windows Command Shell
MalwarePikabot

Pikabot can execute Windows shell commands via cmd.exe.

T1059.003
Windows Command Shell
MalwareWiarp

Wiarp creates a backdoor through which remote attackers can open a command line interface.

T1059.003
Windows Command Shell
MalwareRCSession

RCSession can use `cmd.exe` for execution on compromised hosts.

T1059.003
Windows Command Shell
MalwareSpark

Spark can use cmd.exe to run commands.

T1059.003
Windows Command Shell
MalwareBumblebee

Bumblebee can use `cmd.exe` to drop and run files.

T1059.003
Windows Command Shell
MalwareMURKYTOP

MURKYTOP uses the command-line interface.

T1059.003
Windows Command Shell
MalwareExaramel for Windows

Exaramel for Windows has a command to launch a remote shell and executes commands on the victim’s machine.

T1059.003
Windows Command Shell
MalwareProxysvc

Proxysvc executes a binary on the system and logs the results into a temp file by using: cmd.exe /c "<file_path> > %temp%\PM* .tmp 2>&1".

T1059.003
Windows Command Shell
MalwareOrz

Orz can execute shell commands. Orz can execute commands with JavaScript.

T1059.003
Windows Command Shell
MalwareIronWind

IronWind has used the Windows command shell to execute malicious files.

T1059.003
Windows Command Shell
MalwareSEASHARPEE

SEASHARPEE can execute commands on victims.

T1059.003
Windows Command Shell
MalwarePOWRUNER

POWRUNER can execute commands from its C2 server.

T1059.003
Windows Command Shell
MalwareRobbinHood

RobbinHood uses cmd.exe on the victim's computer.

T1059.003
Windows Command Shell
MalwareTDTESS

TDTESS provides a reverse shell on the victim.

T1059.003
Windows Command Shell
MalwareSharpStage

SharpStage can execute arbitrary commands with the command line.

T1059.003
Windows Command Shell
MalwareSardonic

Sardonic has the ability to run `cmd.exe` or other interactive processes on a compromised computer.

T1059.003
Windows Command Shell
MalwareMisdat

Misdat is capable of providing shell functionality to the attacker to execute commands.

T1059.003
Windows Command Shell
Malwareadbupd

adbupd can run a copy of cmd.exe.

T1059.003
Windows Command Shell
MalwareEmissary

Emissary has the capability to create a remote shell and execute specified commands.

T1059.003
Windows Command Shell
MalwareKEYMARBLE

KEYMARBLE can execute shell commands using cmd.exe.

T1059.003
Windows Command Shell
MalwareHAWKBALL

HAWKBALL has created a cmd.exe reverse shell, executed commands, and uploaded output via the command line.

T1059.003
Windows Command Shell
MalwareTAMECAT

TAMECAT has used `cmd.exe` to run the `curl` command.

T1059.003
Windows Command Shell
MalwareHeartCrypt

HeartCrypt can use the `reg add` command via `cmd.exe` for Registry modification.

T1059.003
Windows Command Shell
MalwareRansomHub

RansomHub can use `cmd.exe` to execute multiple commands on infected hosts.

T1059.003
Windows Command Shell
MalwareZLib

ZLib has the ability to execute shell commands.

T1059.003
Windows Command Shell
MalwareRedLeaves

RedLeaves can receive and execute commands with cmd.exe. It can also provide a reverse shell.

T1059.003
Windows Command Shell
MalwareFelismus

Felismus uses command line for execution.

T1059.003
Windows Command Shell
MalwareZeus Panda

Zeus Panda can launch an interface where it can execute several commands on the victim’s PC.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.