Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1059.003 Windows Command Shell |
MalwareLatrodectus | The Latrodectus command handler can use `cmdexe` to run multiple discovery commands. |
| T1059.003 Windows Command Shell |
MalwareSaint Bot | Saint Bot has used `cmd.exe` and `.bat` scripts for execution. |
| T1059.003 Windows Command Shell |
MalwareChaes | |
| T1059.003 Windows Command Shell |
MalwareCharmPower | The C# implementation of the CharmPower command execution module can use |
| T1059.003 Windows Command Shell |
MalwareMuddyViper | MuddyViper has used cmd.exe to launch a reverse shell. |
| T1059.003 Windows Command Shell |
MalwareTYPEFRAME | TYPEFRAME can uninstall malware components using a batch script. TYPEFRAME can execute commands using a shell. |
| T1059.003 Windows Command Shell |
MalwareKOMPROGO | KOMPROGO is capable of creating a reverse shell. |
| T1059.003 Windows Command Shell |
MalwareQUADAGENT | QUADAGENT uses cmd.exe to execute scripts and commands on the victim’s machine. |
| T1059.003 Windows Command Shell |
MalwareTAINTEDSCRIBE | TAINTEDSCRIBE can enable Windows CLI access and execute files. |
| T1059.003 Windows Command Shell |
MalwareUroburos | Uroburos has the ability to use the command line for execution on the targeted system. |
| T1059.003 Windows Command Shell |
MalwareMetamorfo | Metamorfo has used |
| T1059.003 Windows Command Shell |
MalwareEmbargo | Embargo has utilized a BAT script to disable security solutions. |
| T1059.003 Windows Command Shell |
MalwareTrojan.Karagany | Trojan.Karagany can perform reconnaissance commands on a victim machine via a cmd.exe process. |
| T1059.003 Windows Command Shell |
MalwareBandook | Bandook is capable of spawning a Windows command shell. |
| T1059.003 Windows Command Shell |
MalwareMagicRAT | MagicRAT allows for the execution of arbitrary commands on the victim system. |
| T1059.003 Windows Command Shell |
MalwareKONNI | KONNI has used cmd.exe to execute arbitrary commands on the infected host across different stages of the infection chain. |
| T1059.003 Windows Command Shell |
MalwareDnsSystem | DnsSystem can use `cmd.exe` for execution. |
| T1059.003 Windows Command Shell |
MalwareMoleNet | MoleNet can execute commands via the command line utility. |
| T1059.003 Windows Command Shell |
MalwareJHUHUGIT | JHUHUGIT uses a .bat file to execute a .dll. |
| T1059.003 Windows Command Shell |
MalwareKGH_SPY | KGH_SPY has the ability to set a Registry key to run a cmd.exe command. |
| T1059.003 Windows Command Shell |
MalwareIxeshe | |
| T1059.003 Windows Command Shell |
MalwareMicropsia | Micropsia creates a command-line shell using cmd.exe. |
| T1059.003 Windows Command Shell |
MalwareRedLine Stealer | RedLine Stealer has executed windows cmd using `ErrorHandler.cmd` to create scheduled tasks. |
| T1059.003 Windows Command Shell |
MalwareBlack Basta | Black Basta can use `cmd.exe` to enable shadow copy deletion. |
| T1059.003 Windows Command Shell |
MalwareOopsIE | OopsIE uses the command prompt to execute commands on the victim's machine. |
| T1059.003 Windows Command Shell |
Malware4H RAT | 4H RAT has the capability to create a remote shell. |
| T1059.003 Windows Command Shell |
MalwareRogueRobin | RogueRobin uses Windows Script Components. |
| T1059.003 Windows Command Shell |
MalwareDealersChoice | DealersChoice makes modifications to open-source scripts from GitHub and executes them on the victim’s machine. |
| T1059.003 Windows Command Shell |
MalwareSQLRat | SQLRat has used SQL to execute JavaScript and VB scripts on the host system. |
| T1059.003 Windows Command Shell |
MalwareMegaCortex | MegaCortex has used |
| T1059.003 Windows Command Shell |
MalwareStreamEx | StreamEx has the ability to remotely execute commands. |
| T1059.003 Windows Command Shell |
MalwareBoxCaon | BoxCaon can execute arbitrary commands and utilize the "ComSpec" environment variable. |
| T1059.003 Windows Command Shell |
MalwareSDBbot | SDBbot has the ability to use the command shell to execute commands on a compromised host. |
| T1059.003 Windows Command Shell |
MalwareMosquito | Mosquito executes cmd.exe and uses a pipe to read the results and send back the output to the C2 server. |
| T1059.003 Windows Command Shell |
MalwareRTM | RTM uses the command line and rundll32.exe to execute. |
| T1059.003 Windows Command Shell |
MalwareHikit | Hikit has the ability to create a remote shell and run given commands. |
| T1059.003 Windows Command Shell |
MalwareStrelaStealer | StrelaStealer has included BAT files in some instances for installation. |
| T1059.003 Windows Command Shell |
MalwareSakula | Sakula calls cmd.exe to run various DLL files via rundll32 and also to perform file cleanup. Sakula also has the capability to invoke a reverse shell. |
| T1059.003 Windows Command Shell |
MalwareTarrask | Tarrask may abuse the Windows schtasks command-line tool to create "hidden" scheduled tasks. |
| T1059.003 Windows Command Shell |
MalwareShark | Shark has the ability to use `CMD` to execute commands. |
| T1059.003 Windows Command Shell |
MalwareBazar | Bazar can launch cmd.exe to perform reconnaissance commands. |
| T1059.003 Windows Command Shell |
MalwareRATANKBA | RATANKBA uses cmd.exe to execute commands. |
| T1059.003 Windows Command Shell |
MalwarehcdLoader | hcdLoader provides command-line access to the compromised system. |
| T1059.003 Windows Command Shell |
MalwareMoonWind | MoonWind can execute commands via an interactive command shell. MoonWind uses batch scripts for various purposes, including to restart and uninstall itself. |
| T1059.003 Windows Command Shell |
MalwareRyuk | Ryuk has used |
| T1059.003 Windows Command Shell |
MalwareHermeticWiper | HermeticWiper can use `cmd.exe /Q/c move CSIDL_SYSTEM_DRIVE\temp\sys.tmp1 CSIDL_WINDOWS\policydefinitions\postgresql.exe 1> \\127.0.0.1\ADMIN$\_1636727589.6007507 2>&1` to deploy on an infected system. |
| T1059.003 Windows Command Shell |
MalwareABK | ABK has the ability to use cmd to run a Portable Executable (PE) on the compromised host. |
| T1059.003 Windows Command Shell |
Malwareccf32 | ccf32 has used `cmd.exe` for archiving data and deleting files. |
| T1059.003 Windows Command Shell |
MalwareKapeka | Kapeka allows for arbitrary Windows command execution. |
| T1059.003 Windows Command Shell |
MalwareLockBit 2.0 | LockBit 2.0 can use the Windows command shell for multiple post-compromise actions on objective. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.