ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1059.003
Windows Command Shell
MalwareMeteor

Meteor can run `set.bat`, `update.bat`, `cache.bat`, `bcd.bat`, `msrun.bat`, and similar scripts.

T1059.003
Windows Command Shell
MalwarenjRAT

njRAT can launch a command shell interface for executing commands.

T1059.003
Windows Command Shell
MalwareMaze

The Maze encryption process has used batch scripts with various commands.

T1059.003
Windows Command Shell
MalwareComRAT

ComRAT has used cmd.exe to execute commands.

T1059.003
Windows Command Shell
MalwareTURNEDUP

TURNEDUP is capable of creating a reverse shell.

T1059.003
Windows Command Shell
MalwareManjusaka

Manjusaka can execute arbitrary commands passed to it from the C2 controller via `cmd.exe /c`.

T1059.003
Windows Command Shell
MalwareJPIN

JPIN can use the command-line utility cacls.exe to change file permissions.

T1059.003
Windows Command Shell
MalwareSideTwist

SideTwist can execute shell commands on a compromised host.

T1059.003
Windows Command Shell
MalwareKOCTOPUS

KOCTOPUS has used `cmd.exe` and batch files for execution.

T1059.003
Windows Command Shell
MalwareMechaFlounder

MechaFlounder has the ability to run commands on a compromised host.

T1059.003
Windows Command Shell
MalwareHTTPBrowser

HTTPBrowser is capable of spawning a reverse shell on a victim.

T1059.003
Windows Command Shell
MalwareMis-Type

Mis-Type has used `cmd.exe` to run commands on a compromised host.

T1059.003
Windows Command Shell
MalwareLunarWeb

LunarWeb can run shell commands using a BAT file with a name matching `%TEMP%\<⁠random_9_alnum_chars>.batfile` or through cmd.exe with the `/c` and `/U` option for Unicode output.

T1059.003
Windows Command Shell
MalwareDipsind

Dipsind can spawn remote shells.

T1059.003
Windows Command Shell
MalwareQilin

Qilin has run `cmd /C [PsExec] -accepteula \\IP Address -c -f -h -d -i
C:\Users\xxx\<encryptor_1>.exe --password [PASSWORD] --spread --spread-process` to execute its encryptor to target multiple network shares.

T1059.003
Windows Command Shell
MalwareSTARWHALE

STARWHALE has the ability to execute commands via `cmd.exe`.

T1059.003
Windows Command Shell
MalwareMirageFox

MirageFox has the capability to execute commands using cmd.exe.

T1059.003
Windows Command Shell
MalwareDownPaper

DownPaper uses the command line.

T1059.003
Windows Command Shell
MalwareCozyCar

A module in CozyCar allows arbitrary commands to be executed by invoking C:\Windows\System32\cmd.exe.

T1059.003
Windows Command Shell
MalwareKevin

Kevin can use a renamed image of `cmd.exe` for execution.

T1059.003
Windows Command Shell
Malwarehttpclient

httpclient opens cmd.exe on the victim.

T1059.003
Windows Command Shell
MalwareECCENTRICBANDWAGON

ECCENTRICBANDWAGON can use cmd to execute commands on a victim’s machine.

T1059.003
Windows Command Shell
MalwareBADNEWS

BADNEWS is capable of executing commands via cmd.exe.

T1059.003
Windows Command Shell
MalwareLinfo

Linfo creates a backdoor through which remote attackers can start a remote shell.

T1059.003
Windows Command Shell
MalwareGoopy

Goopy has the ability to use cmd.exe to execute commands passed from an Outlook C2 channel.

T1059.003
Windows Command Shell
MalwareRemexi

Remexi silently executes received commands with cmd.exe.

T1059.003
Windows Command Shell
MalwareAstaroth

Astaroth spawns a CMD process to execute commands.

T1059.003
Windows Command Shell
MalwareQakBot

QakBot can use cmd.exe to launch itself and to execute multiple C2 commands.

T1059.003
Windows Command Shell
MalwareSYSCON

SYSCON has the ability to execute commands through cmd on a compromised host.

T1059.003
Windows Command Shell
MalwareGelsemium

Gelsemium can use a batch script to delete itself.

T1059.003
Windows Command Shell
MalwarejRAT

jRAT has command line access.

T1059.003
Windows Command Shell
MalwareHelminth

Helminth can provide a remote shell. One version of Helminth uses batch scripting.

T1059.003
Windows Command Shell
MalwareBBK

BBK has the ability to use cmd to run a Portable Executable (PE) on the compromised host.

T1059.003
Windows Command Shell
MalwareDenis

Denis can launch a remote shell to execute arbitrary commands on the victim’s machine.

T1059.003
Windows Command Shell
MalwareComnie

Comnie executes BAT scripts.

T1059.003
Windows Command Shell
MalwarePHOREAL

PHOREAL is capable of creating reverse shell.

T1059.003
Windows Command Shell
MalwareLizar

Lizar has a command to open the command-line on the infected system.

T1059.003
Windows Command Shell
MalwareDtrack

Dtrack has used cmd.exe to add a persistent service.

T1059.003
Windows Command Shell
MalwareH1N1

H1N1 kills and disables services by using cmd.exe.

T1059.003
Windows Command Shell
MalwareSeth-Locker

Seth-Locker can execute commands via the command line shell.

T1059.003
Windows Command Shell
MalwareLoudMiner

LoudMiner used a batch script to run the Linux virtual machine as a service.

T1059.003
Windows Command Shell
MalwareBACKSPACE

Adversaries can direct BACKSPACE to execute from the command line on infected hosts, or have BACKSPACE create a reverse shell.

T1059.003
Windows Command Shell
MalwareUPPERCUT

UPPERCUT uses cmd.exe to execute commands on the victim’s machine.

T1059.003
Windows Command Shell
MalwareADVSTORESHELL

ADVSTORESHELL can create a remote shell and run a given command.

T1059.003
Windows Command Shell
MalwareStrifeWater

StrifeWater can execute shell commands using `cmd.exe`.

T1059.003
Windows Command Shell
MalwareMivast

Mivast has the capability to open a remote shell and run basic commands.

T1059.003
Windows Command Shell
MalwareHiddenWasp

HiddenWasp uses a script to automate tasks on the victim's machine and to assist in execution.

T1059.003
Windows Command Shell
MalwareWarzoneRAT

WarzoneRAT can use `cmd.exe` to execute malicious code.

T1059.003
Windows Command Shell
MalwareSLOTHFULMEDIA

SLOTHFULMEDIA can open a command line to execute commands.

T1059.003
Windows Command Shell
MalwareSmall Sieve

Small Sieve can use `cmd.exe` to execute commands on a victim's system.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.