Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1059.003 Windows Command Shell |
MalwareHavoc | Havoc can execute commands via `cmd.exe`. |
| T1059.003 Windows Command Shell |
MalwareCARROTBAT | CARROTBAT has the ability to execute command line arguments on a compromised host. |
| T1059.003 Windows Command Shell |
MalwareGravityRAT | GravityRAT executes commands remotely on the infected host. |
| T1059.003 Windows Command Shell |
MalwareWEBC2 | WEBC2 can open an interactive command shell. |
| T1059.003 Windows Command Shell |
MalwareBankshot | Bankshot uses the command-line interface to execute arbitrary commands. |
| T1059.003 Windows Command Shell |
MalwareSharpDisco | SharpDisco can use `cmd.exe` to execute plugins and to send command output to specified SMB shares. |
| T1059.003 Windows Command Shell |
MalwarexCaon | xCaon has a command to start an interactive shell. |
| T1059.003 Windows Command Shell |
MalwarePLAINTEE | PLAINTEE uses cmd.exe to execute commands on the victim’s machine. |
| T1059.003 Windows Command Shell |
MalwarePony | Pony has used batch scripts to delete itself after execution. |
| T1059.003 Windows Command Shell |
MalwareNebulae | Nebulae can use CMD to execute a process. |
| T1059.003 Windows Command Shell |
MalwareAuditCred | AuditCred can open a reverse shell on the system to execute commands. |
| T1059.003 Windows Command Shell |
MalwareTONESHELL | TONESHELL has created a reverse shell using `cmd.exe`. |
| T1059.003 Windows Command Shell |
MalwareKasidet | Kasidet can execute commands using cmd.exe. |
| T1059.003 Windows Command Shell |
MalwareHannotog | Hannotog can execute various `cmd.exe /c %s` commands. |
| T1059.003 Windows Command Shell |
MalwareOceanSalt | OceanSalt can create a reverse shell on the infected endpoint using cmd.exe. OceanSalt has been executed via malicious macros. |
| T1059.003 Windows Command Shell |
MalwareMedusa Ransomware | Medusa Ransomware has used `cmd.exe` to execute command on an infected host. |
| T1059.003 Windows Command Shell |
MalwareRainyDay | RainyDay can use the Windows Command Shell for execution. |
| T1059.003 Windows Command Shell |
MalwareNETWIRE | NETWIRE can issue commands using cmd.exe. |
| T1059.003 Windows Command Shell |
MalwareTinyTurla | TinyTurla has been installed using a .bat file. |
| T1059.003 Windows Command Shell |
MalwarePyDCrypt | PyDCrypt has used `cmd.exe` for execution. |
| T1059.003 Windows Command Shell |
MalwareEnvyScout | EnvyScout can use cmd.exe to execute malicious files on compromised hosts. |
| T1059.003 Windows Command Shell |
MalwareGreyEnergy | GreyEnergy uses cmd.exe to execute itself in-memory. |
| T1059.003 Windows Command Shell |
MalwareEmotet | Emotet has used cmd.exe to run a PowerShell script. |
| T1059.003 Windows Command Shell |
MalwareSNUGRIDE | SNUGRIDE is capable of executing commands and spawning a reverse shell. |
| T1059.003 Windows Command Shell |
MalwareCrimson | Crimson has the ability to execute commands with the COMSPEC environment variable. |
| T1059.003 Windows Command Shell |
MalwareDUSTTRAP | DUSTTRAP can execute commands via `cmd.exe`. |
| T1059.003 Windows Command Shell |
MalwareTurian | Turian can create a remote shell and execute commands using cmd. |
| T1059.003 Windows Command Shell |
MalwareBADHATCH | BADHATCH can use `cmd.exe` to execute commands on a compromised host. |
| T1059.003 Windows Command Shell |
MalwareAction RAT | Action RAT can use `cmd.exe` to execute commands on an infected host. |
| T1059.003 Windows Command Shell |
MalwarePUBLOAD | PUBLOAD has used several commands executed in sequence via `cmd`. |
| T1059.003 Windows Command Shell |
MalwareSystemBC | SystemBC has used `cmd.exe` to execute VBS scripts, BAT scripts and CMD scripts. |
| T1059.003 Windows Command Shell |
MalwarePingPull | PingPull can use `cmd.exe` to run various commands as a reverse shell. |
| T1059.003 Windows Command Shell |
MalwareWellMess | WellMess can execute command line scripts received from C2. |
| T1059.003 Windows Command Shell |
MalwareDropBook | DropBook can execute arbitrary shell commands on the victims' machines. |
| T1059.003 Windows Command Shell |
MalwareWoody RAT | Woody RAT can execute commands using `cmd.exe`. |
| T1059.003 Windows Command Shell |
MalwareMafalda | Mafalda can execute shell commands using `cmd.exe`. |
| T1059.003 Windows Command Shell |
MalwareSquirrelwaffle | Squirrelwaffle has used `cmd.exe` for execution. |
| T1059.003 Windows Command Shell |
MalwareUmbreon | Umbreon provides access using both standard facilities like SSH and additional access using its backdoor Espeon, providing a reverse shell upon receipt of a special packet |
| T1059.003 Windows Command Shell |
MalwareAuTo Stealer | AuTo Stealer can use `cmd.exe` to execute a created batch file. |
| T1059.003 Windows Command Shell |
MalwareODAgent | ODAgent can execute a specified command line passed via API. |
| T1059.003 Windows Command Shell |
MalwareFlawedAmmyy | FlawedAmmyy has used `cmd` to execute commands on a compromised host. |
| T1059.003 Windows Command Shell |
MalwareSUGARUSH | SUGARUSH has used `cmd` for execution on an infected host. |
| T1059.003 Windows Command Shell |
MalwareHOPLIGHT | HOPLIGHT can launch cmd.exe to execute commands on the system. |
| T1059.003 Windows Command Shell |
MalwareWastedLocker | WastedLocker has used cmd to execute commands on the system. |
| T1059.003 Windows Command Shell |
MalwareInvisiMole | InvisiMole can launch a remote shell to execute commands. |
| T1059.003 Windows Command Shell |
MalwareVolgmer | Volgmer can execute commands on the victim's machine. |
| T1059.003 Windows Command Shell |
MalwareWhisperGate | WhisperGate can use `cmd.exe` to execute commands. |
| T1059.003 Windows Command Shell |
MalwareRDAT | RDAT has executed commands using |
| T1059.003 Windows Command Shell |
MalwareOkrum | Okrum's backdoor has used cmd.exe to execute arbitrary commands as well as batch scripts to update itself to a newer version. |
| T1059.003 Windows Command Shell |
MalwareSamSam | SamSam uses custom batch scripts to execute some of its components. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.