ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1059.003
Windows Command Shell
MalwareConti

Conti can utilize command line options to allow an attacker control over how it scans and encrypts files.

T1059.003
Windows Command Shell
MalwareRaspberry Robin

Raspberry Robin uses cmd.exe to read and execute a file stored on an infected USB device as part of initial installation.

T1059.003
Windows Command Shell
MalwareMegazord

Megazord can execute multiple commands post infection via `cmd.exe`.

T1059.003
Windows Command Shell
MalwareTEXTMATE

TEXTMATE executes cmd.exe to provide a reverse shell to adversaries.

T1059.003
Windows Command Shell
MalwareSiloscape

Siloscape can run cmd through an IRC channel.

T1059.003
Windows Command Shell
MalwareBlackCat

BlackCat can execute commands on a compromised network with the use of `cmd.exe`.

T1059.003
Windows Command Shell
MalwareUBoatRAT

UBoatRAT can start a command shell.

T1059.003
Windows Command Shell
MalwareNightdoor

Nightdoor creates a cmd.exe shell to send and receive commands from the command and control server via open pipes.

T1059.003
Windows Command Shell
MalwareHTTPTroy

HTTPTroy has the ability to generate a reverse shell using the command `conn <IP_ADDRESS> <PORT>`.

T1059.003
Windows Command Shell
MalwareMarkiRAT

MarkiRAT can utilize cmd.exe to execute commands in a victim's environment.

T1059.003
Windows Command Shell
MalwareKazuar

Kazuar uses cmd.exe to execute commands on the victim’s machine.

T1059.003
Windows Command Shell
MalwareNavRAT

NavRAT leverages cmd.exe to perform discovery techniques. NavRAT loads malicious shellcode and executes it in memory.

T1059.003
Windows Command Shell
MalwareDarkComet

DarkComet can launch a remote shell to execute commands on the victim’s machine.

T1059.003
Windows Command Shell
MalwareNETEAGLE

NETEAGLE allows adversaries to execute shell commands on the infected host.

T1059.003
Windows Command Shell
MalwareRagnar Locker

Ragnar Locker has used cmd.exe and batch scripts to execute commands.

T1059.003
Windows Command Shell
MalwareLucifer

Lucifer can issue shell commands to download and execute additional payloads.

T1059.003
Windows Command Shell
MalwarezwShell

zwShell can launch command-line shells.

T1059.003
Windows Command Shell
MalwareRising Sun

Rising Sun has executed commands using `cmd.exe /c “<command> > <%temp%>\AM<random>. tmp” 2>&1`.

T1059.003
Windows Command Shell
MalwareShimRat

ShimRat can be issued a command shell function from the C2.

T1059.003
Windows Command Shell
MalwareFlagpro

Flagpro can use `cmd.exe` to execute commands received from C2.

T1059.003
Windows Command Shell
MalwareHi-Zor

Hi-Zor has the ability to create a reverse shell.

T1059.003
Windows Command Shell
MalwareChina Chopper

China Chopper's server component is capable of opening a command terminal.

T1059.003
Windows Command Shell
MalwareCALENDAR

CALENDAR has a command to run cmd.exe to execute commands.

T1059.003
Windows Command Shell
MalwareGoldMax

GoldMax can spawn a command shell, and execute native commands.

T1059.003
Windows Command Shell
MalwareKeyBoy

KeyBoy can launch interactive shells for communicating with the victim machine.

T1059.003
Windows Command Shell
MalwareAnchor

Anchor has used cmd.exe to run its self deletion routine.

T1059.003
Windows Command Shell
MalwarePteranodon

Pteranodon can use `cmd.exe` for execution on victim systems.

T1059.003
Windows Command Shell
MalwareDarkTortilla

DarkTortilla can use `cmd.exe` to add registry keys for persistence.

T1059.003
Windows Command Shell
MalwareRunningRAT

RunningRAT uses a batch file to kill a security program task and then attempts to remove itself.

T1059.003
Windows Command Shell
MalwareBabuk

Babuk has the ability to use the command line to control execution on compromised hosts.

T1059.003
Windows Command Shell
MalwareDarkWatchman

DarkWatchman can use `cmd.exe` to execute commands.

T1059.003
Windows Command Shell
MalwareBlackMould

BlackMould can run cmd.exe with parameters.

T1059.003
Windows Command Shell
MalwarePlugX

PlugX allows actors to spawn a reverse shell on a victim.

T1059.003
Windows Command Shell
MalwareBisonal

Bisonal has launched cmd.exe and used the ShellExecuteW() API function to execute commands on the system.

T1059.003
Windows Command Shell
MalwareMultiLayer Wiper

MultiLayer Wiper uses a batch script launched via a scheduled task to delete Windows Event Logs.

T1059.003
Windows Command Shell
MalwareS-Type

S-Type has provided the ability to execute shell commands on a compromised host.

T1059.003
Windows Command Shell
MalwareSeaDuke

SeaDuke is capable of executing commands.

T1059.003
Windows Command Shell
MalwareLightNeuron

LightNeuron is capable of executing commands via cmd.exe.

T1059.003
Windows Command Shell
MalwarePeppy

Peppy has the ability to execute shell commands.

T1059.003
Windows Command Shell
MalwareCuba

Cuba has used cmd.exe /c and batch files for execution.

T1059.003
Windows Command Shell
MalwareClambling

Clambling can use cmd.exe for command execution.

T1059.003
Windows Command Shell
MalwareAkira

Akira executes from the Windows command line and can take various arguments for execution.

T1059.003
Windows Command Shell
MalwareDarkGate

DarkGate uses a malicious Windows Batch script to run the Windows code utility to retrieve follow-on script payloads. DarkGate has also used `cmd.exe` to create a remote shell.

T1059.003
Windows Command Shell
MalwareCarbanak

Carbanak has a command to create a reverse shell.

T1059.003
Windows Command Shell
MalwareXTunnel

XTunnel has been used to execute remote commands.

T1059.003
Windows Command Shell
MalwareHOMEFRY

HOMEFRY uses a command-line interface.

T1059.003
Windows Command Shell
MalwareCaterpillar WebShell

Caterpillar WebShell can run commands on the compromised asset with CMD functions.

T1059.003
Windows Command Shell
MalwareNetwalker

Operators deploying Netwalker have used batch scripts to retrieve the Netwalker payload.

T1059.003
Windows Command Shell
MalwareUSBferry

USBferry can execute various Windows commands.

T1059.003
Windows Command Shell
MalwareTSCookie

TSCookie has the ability to execute shell commands on the infected host.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.