ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1059.003
Windows Command Shell
MalwareLatrodectus

The Latrodectus command handler can use `cmdexe` to run multiple discovery commands.

T1059.003
Windows Command Shell
MalwareSaint Bot

Saint Bot has used `cmd.exe` and `.bat` scripts for execution.

T1059.003
Windows Command Shell
MalwareChaes

Chaes has used cmd to execute tasks on the system.

T1059.003
Windows Command Shell
MalwareCharmPower

The C# implementation of the CharmPower command execution module can use cmd.

T1059.003
Windows Command Shell
MalwareMuddyViper

MuddyViper has used cmd.exe to launch a reverse shell.

T1059.003
Windows Command Shell
MalwareTYPEFRAME

TYPEFRAME can uninstall malware components using a batch script. TYPEFRAME can execute commands using a shell.

T1059.003
Windows Command Shell
MalwareKOMPROGO

KOMPROGO is capable of creating a reverse shell.

T1059.003
Windows Command Shell
MalwareQUADAGENT

QUADAGENT uses cmd.exe to execute scripts and commands on the victim’s machine.

T1059.003
Windows Command Shell
MalwareTAINTEDSCRIBE

TAINTEDSCRIBE can enable Windows CLI access and execute files.

T1059.003
Windows Command Shell
MalwareUroburos

Uroburos has the ability to use the command line for execution on the targeted system.

T1059.003
Windows Command Shell
MalwareMetamorfo

Metamorfo has used cmd.exe /c to execute files.

T1059.003
Windows Command Shell
MalwareEmbargo

Embargo has utilized a BAT script to disable security solutions.

T1059.003
Windows Command Shell
MalwareTrojan.Karagany

Trojan.Karagany can perform reconnaissance commands on a victim machine via a cmd.exe process.

T1059.003
Windows Command Shell
MalwareBandook

Bandook is capable of spawning a Windows command shell.

T1059.003
Windows Command Shell
MalwareMagicRAT

MagicRAT allows for the execution of arbitrary commands on the victim system.

T1059.003
Windows Command Shell
MalwareKONNI

KONNI has used cmd.exe to execute arbitrary commands on the infected host across different stages of the infection chain.

T1059.003
Windows Command Shell
MalwareDnsSystem

DnsSystem can use `cmd.exe` for execution.

T1059.003
Windows Command Shell
MalwareMoleNet

MoleNet can execute commands via the command line utility.

T1059.003
Windows Command Shell
MalwareJHUHUGIT

JHUHUGIT uses a .bat file to execute a .dll.

T1059.003
Windows Command Shell
MalwareKGH_SPY

KGH_SPY has the ability to set a Registry key to run a cmd.exe command.

T1059.003
Windows Command Shell
MalwareIxeshe

Ixeshe is capable of executing commands via cmd.

T1059.003
Windows Command Shell
MalwareMicropsia

Micropsia creates a command-line shell using cmd.exe.

T1059.003
Windows Command Shell
MalwareRedLine Stealer

RedLine Stealer has executed windows cmd using `ErrorHandler.cmd` to create scheduled tasks.

T1059.003
Windows Command Shell
MalwareBlack Basta

Black Basta can use `cmd.exe` to enable shadow copy deletion.

T1059.003
Windows Command Shell
MalwareOopsIE

OopsIE uses the command prompt to execute commands on the victim's machine.

T1059.003
Windows Command Shell
Malware4H RAT

4H RAT has the capability to create a remote shell.

T1059.003
Windows Command Shell
MalwareRogueRobin

RogueRobin uses Windows Script Components.

T1059.003
Windows Command Shell
MalwareDealersChoice

DealersChoice makes modifications to open-source scripts from GitHub and executes them on the victim’s machine.

T1059.003
Windows Command Shell
MalwareSQLRat

SQLRat has used SQL to execute JavaScript and VB scripts on the host system.

T1059.003
Windows Command Shell
MalwareMegaCortex

MegaCortex has used .cmd scripts on the victim's system.

T1059.003
Windows Command Shell
MalwareStreamEx

StreamEx has the ability to remotely execute commands.

T1059.003
Windows Command Shell
MalwareBoxCaon

BoxCaon can execute arbitrary commands and utilize the "ComSpec" environment variable.

T1059.003
Windows Command Shell
MalwareSDBbot

SDBbot has the ability to use the command shell to execute commands on a compromised host.

T1059.003
Windows Command Shell
MalwareMosquito

Mosquito executes cmd.exe and uses a pipe to read the results and send back the output to the C2 server.

T1059.003
Windows Command Shell
MalwareRTM

RTM uses the command line and rundll32.exe to execute.

T1059.003
Windows Command Shell
MalwareHikit

Hikit has the ability to create a remote shell and run given commands.

T1059.003
Windows Command Shell
MalwareStrelaStealer

StrelaStealer has included BAT files in some instances for installation.

T1059.003
Windows Command Shell
MalwareSakula

Sakula calls cmd.exe to run various DLL files via rundll32 and also to perform file cleanup. Sakula also has the capability to invoke a reverse shell.

T1059.003
Windows Command Shell
MalwareTarrask

Tarrask may abuse the Windows schtasks command-line tool to create "hidden" scheduled tasks.

T1059.003
Windows Command Shell
MalwareShark

Shark has the ability to use `CMD` to execute commands.

T1059.003
Windows Command Shell
MalwareBazar

Bazar can launch cmd.exe to perform reconnaissance commands.

T1059.003
Windows Command Shell
MalwareRATANKBA

RATANKBA uses cmd.exe to execute commands.

T1059.003
Windows Command Shell
MalwarehcdLoader

hcdLoader provides command-line access to the compromised system.

T1059.003
Windows Command Shell
MalwareMoonWind

MoonWind can execute commands via an interactive command shell. MoonWind uses batch scripts for various purposes, including to restart and uninstall itself.

T1059.003
Windows Command Shell
MalwareRyuk

Ryuk has used cmd.exe to create a Registry entry to establish persistence.

T1059.003
Windows Command Shell
MalwareHermeticWiper

HermeticWiper can use `cmd.exe /Q/c move CSIDL_SYSTEM_DRIVE\temp\sys.tmp1 CSIDL_WINDOWS\policydefinitions\postgresql.exe 1> \\127.0.0.1\ADMIN$\_1636727589.6007507 2>&1` to deploy on an infected system.

T1059.003
Windows Command Shell
MalwareABK

ABK has the ability to use cmd to run a Portable Executable (PE) on the compromised host.

T1059.003
Windows Command Shell
Malwareccf32

ccf32 has used `cmd.exe` for archiving data and deleting files.

T1059.003
Windows Command Shell
MalwareKapeka

Kapeka allows for arbitrary Windows command execution.

T1059.003
Windows Command Shell
MalwareLockBit 2.0

LockBit 2.0 can use the Windows command shell for multiple post-compromise actions on objective.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.