ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1059.003
Windows Command Shell
MalwareZebrocy

Zebrocy uses cmd.exe to execute commands on the system.

T1059.003
Windows Command Shell
MalwareCobalt Strike

Cobalt Strike uses a command-line interface to interact with systems.

T1059.003
Windows Command Shell
MalwareSampleCheck5000

SampleCheck5000 can call cmd.exe to execute C2 command line strings.

T1059.003
Windows Command Shell
MalwareEvilBunny

EvilBunny has an integrated scripting engine to download and execute Lua scripts.

T1059.003
Windows Command Shell
MalwareCobian RAT

Cobian RAT can launch a remote command shell interface for executing commands.

T1059.003
Windows Command Shell
MalwareHotCroissant

HotCroissant can remotely open applications on the infected host with the ShellExecuteA command.

T1059.003
Windows Command Shell
MalwareServHelper

ServHelper can execute shell commands against cmd.

T1059.003
Windows Command Shell
MalwareJCry

JCry has used cmd.exe to launch PowerShell.

T1059.003
Windows Command Shell
MalwareREvil

REvil can use the Windows command line to delete volume shadow copies and disable recovery.

T1059.003
Windows Command Shell
MalwareSamurai

Samurai can use a remote command module for execution via the Windows command line.

T1059.003
Windows Command Shell
MalwareMilan

Milan can use `cmd.exe` for discovery actions on a targeted system.

T1059.003
Windows Command Shell
MalwareOilBooster

OilBooster has the ability to execute shell commands and exfiltrate the results.

T1059.003
Windows Command Shell
MalwareTaidoor

Taidoor can copy cmd.exe into the system temp folder.

T1059.003
Windows Command Shell
MalwarePoisonIvy

PoisonIvy creates a backdoor through which remote attackers can open a command-line interface.

T1059.003
Windows Command Shell
MalwareSeasalt

Seasalt uses cmd.exe to create a reverse shell on the infected endpoint.

T1059.003
Windows Command Shell
MalwareNanoCore

NanoCore can open a remote command-line interface and execute commands. NanoCore uses JavaScript files.

T1059.003
Windows Command Shell
MalwarePLEAD

PLEAD has the ability to execute shell commands on the compromised host.

T1059.003
Windows Command Shell
MalwareIPsec Helper

IPsec Helper can run arbitrary commands passed to it through cmd.exe.

T1059.003
Windows Command Shell
MalwareDaserf

Daserf can execute shell commands.

T1059.003
Windows Command Shell
MalwareCardinal RAT

Cardinal RAT can execute commands.

T1059.003
Windows Command Shell
MalwareDanBot

DanBot has the ability to execute arbitrary commands via `cmd.exe`.

T1059.003
Windows Command Shell
MalwareBISCUIT

BISCUIT has a command to launch a command shell on the system.

T1059.003
Windows Command Shell
MalwarePisloader

Pisloader uses cmd.exe to set the Registry Run key value. It also has a command to spawn a command shell.

T1059.003
Windows Command Shell
MalwareGoldenSpy

GoldenSpy can execute remote commands via the command-line interface.

T1059.003
Windows Command Shell
MalwareGold Dragon

Gold Dragon uses cmd.exe to execute commands for discovery.

T1059.003
Windows Command Shell
MalwareRGDoor

RGDoor uses cmd.exe to execute commands on the victim’s machine.

T1059.003
Windows Command Shell
MalwareHARDRAIN

HARDRAIN uses cmd.exe to execute netshcommands.

T1059.003
Windows Command Shell
MalwareRevenge RAT

Revenge RAT uses cmd.exe to execute commands and run scripts on the victim's machine.

T1059.003
Windows Command Shell
MalwareFunnyDream

FunnyDream can use `cmd.exe` for execution on remote hosts.

T1059.003
Windows Command Shell
MalwareROADSWEEP

ROADSWEEP can open cmd.exe to enable command execution.

T1059.003
Windows Command Shell
MalwareMore_eggs

More_eggs has used cmd.exe for execution.

T1059.003
Windows Command Shell
MalwareTinyZBot

TinyZBot supports execution from the command-line.

T1059.003
Windows Command Shell
MalwareOutSteel

OutSteel has used `cmd.exe` to scan a compromised host for specific file extensions.

T1059.003
Windows Command Shell
MalwareBackConfig

BackConfig can download and run batch files to execute commands on a compromised host.

T1059.003
Windows Command Shell
MalwareDEADEYE

DEADEYE can run `cmd /c copy /y /b C:\Users\public\syslog_6-*.dat C:\Users\public\syslog.dll` to combine separated sections of code into a single DLL prior to execution.

T1059.003
Windows Command Shell
MalwareLAMEHUG

LAMEHUG can use `cmd.exe` to display a decoy file to spearphishing victims.

T1059.003
Windows Command Shell
MalwareInnaputRAT

InnaputRAT launches a shell to execute commands on the victim’s machine.

T1059.003
Windows Command Shell
MalwareGrimAgent

GrimAgent can use the Windows Command Shell to execute commands, including its own removal.

T1059.003
Windows Command Shell
MalwareLookBack

LookBack executes the cmd.exe command.

T1059.003
Windows Command Shell
MalwareClop

Clop can use cmd.exe to help execute commands on the system.

T1059.003
Windows Command Shell
MalwareLokibot

Lokibot has used cmd /c commands embedded within batch scripts.

T1059.003
Windows Command Shell
MalwareEgregor

Egregor has used batch files for execution and can launch Internet Explorer from cmd.exe.

T1059.003
Windows Command Shell
MalwarePoetRAT

PoetRAT has called cmd through a Word document macro.

T1059.003
Windows Command Shell
MalwareFELIXROOT

FELIXROOT executes batch scripts on the victim’s machine, and can launch a reverse shell for command execution.

T1059.003
Windows Command Shell
MalwareZxShell

ZxShell can launch a reverse command shell.

T1059.003
Windows Command Shell
MalwareCoinTicker

CoinTicker executes a bash script to establish a reverse shell.

T1059.003
Windows Command Shell
MalwareBabyShark

BabyShark has used cmd.exe to execute commands.

T1059.003
Windows Command Shell
MalwareBONDUPDATER

BONDUPDATER can read batch commands in a file sent from its C2 server and execute them with cmd.exe.

T1059.003
Windows Command Shell
MalwareTroll Stealer

Troll Stealer can create and execute Windows batch scripts.

T1059.003
Windows Command Shell
MalwareBLACKCOFFEE

BLACKCOFFEE has the capability to create a reverse shell.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.