Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1059.003 Windows Command Shell |
MalwareMeteor | Meteor can run `set.bat`, `update.bat`, `cache.bat`, `bcd.bat`, `msrun.bat`, and similar scripts. |
| T1059.003 Windows Command Shell |
MalwarenjRAT | njRAT can launch a command shell interface for executing commands. |
| T1059.003 Windows Command Shell |
MalwareMaze | The Maze encryption process has used batch scripts with various commands. |
| T1059.003 Windows Command Shell |
MalwareComRAT | ComRAT has used |
| T1059.003 Windows Command Shell |
MalwareTURNEDUP | TURNEDUP is capable of creating a reverse shell. |
| T1059.003 Windows Command Shell |
MalwareManjusaka | Manjusaka can execute arbitrary commands passed to it from the C2 controller via `cmd.exe /c`. |
| T1059.003 Windows Command Shell |
MalwareJPIN | JPIN can use the command-line utility cacls.exe to change file permissions. |
| T1059.003 Windows Command Shell |
MalwareSideTwist | SideTwist can execute shell commands on a compromised host. |
| T1059.003 Windows Command Shell |
MalwareKOCTOPUS | KOCTOPUS has used `cmd.exe` and batch files for execution. |
| T1059.003 Windows Command Shell |
MalwareMechaFlounder | MechaFlounder has the ability to run commands on a compromised host. |
| T1059.003 Windows Command Shell |
MalwareHTTPBrowser | HTTPBrowser is capable of spawning a reverse shell on a victim. |
| T1059.003 Windows Command Shell |
MalwareMis-Type | Mis-Type has used `cmd.exe` to run commands on a compromised host. |
| T1059.003 Windows Command Shell |
MalwareLunarWeb | LunarWeb can run shell commands using a BAT file with a name matching `%TEMP%\<random_9_alnum_chars>.batfile` or through cmd.exe with the `/c` and `/U` option for Unicode output. |
| T1059.003 Windows Command Shell |
MalwareDipsind | Dipsind can spawn remote shells. |
| T1059.003 Windows Command Shell |
MalwareQilin | Qilin has run `cmd /C [PsExec] -accepteula \\IP Address -c -f -h -d -i |
| T1059.003 Windows Command Shell |
MalwareSTARWHALE | STARWHALE has the ability to execute commands via `cmd.exe`. |
| T1059.003 Windows Command Shell |
MalwareMirageFox | MirageFox has the capability to execute commands using cmd.exe. |
| T1059.003 Windows Command Shell |
MalwareDownPaper | DownPaper uses the command line. |
| T1059.003 Windows Command Shell |
MalwareCozyCar | A module in CozyCar allows arbitrary commands to be executed by invoking |
| T1059.003 Windows Command Shell |
MalwareKevin | Kevin can use a renamed image of `cmd.exe` for execution. |
| T1059.003 Windows Command Shell |
Malwarehttpclient | httpclient opens cmd.exe on the victim. |
| T1059.003 Windows Command Shell |
MalwareECCENTRICBANDWAGON | ECCENTRICBANDWAGON can use cmd to execute commands on a victim’s machine. |
| T1059.003 Windows Command Shell |
MalwareBADNEWS | BADNEWS is capable of executing commands via cmd.exe. |
| T1059.003 Windows Command Shell |
MalwareLinfo | Linfo creates a backdoor through which remote attackers can start a remote shell. |
| T1059.003 Windows Command Shell |
MalwareGoopy | Goopy has the ability to use cmd.exe to execute commands passed from an Outlook C2 channel. |
| T1059.003 Windows Command Shell |
MalwareRemexi | Remexi silently executes received commands with cmd.exe. |
| T1059.003 Windows Command Shell |
MalwareAstaroth | Astaroth spawns a CMD process to execute commands. |
| T1059.003 Windows Command Shell |
MalwareQakBot | QakBot can use cmd.exe to launch itself and to execute multiple C2 commands. |
| T1059.003 Windows Command Shell |
MalwareSYSCON | SYSCON has the ability to execute commands through cmd on a compromised host. |
| T1059.003 Windows Command Shell |
MalwareGelsemium | Gelsemium can use a batch script to delete itself. |
| T1059.003 Windows Command Shell |
MalwarejRAT | jRAT has command line access. |
| T1059.003 Windows Command Shell |
MalwareHelminth | Helminth can provide a remote shell. One version of Helminth uses batch scripting. |
| T1059.003 Windows Command Shell |
MalwareBBK | BBK has the ability to use cmd to run a Portable Executable (PE) on the compromised host. |
| T1059.003 Windows Command Shell |
MalwareDenis | Denis can launch a remote shell to execute arbitrary commands on the victim’s machine. |
| T1059.003 Windows Command Shell |
MalwareComnie | Comnie executes BAT scripts. |
| T1059.003 Windows Command Shell |
MalwarePHOREAL | PHOREAL is capable of creating reverse shell. |
| T1059.003 Windows Command Shell |
MalwareLizar | Lizar has a command to open the command-line on the infected system. |
| T1059.003 Windows Command Shell |
MalwareDtrack | Dtrack has used |
| T1059.003 Windows Command Shell |
MalwareH1N1 | H1N1 kills and disables services by using cmd.exe. |
| T1059.003 Windows Command Shell |
MalwareSeth-Locker | Seth-Locker can execute commands via the command line shell. |
| T1059.003 Windows Command Shell |
MalwareLoudMiner | LoudMiner used a batch script to run the Linux virtual machine as a service. |
| T1059.003 Windows Command Shell |
MalwareBACKSPACE | Adversaries can direct BACKSPACE to execute from the command line on infected hosts, or have BACKSPACE create a reverse shell. |
| T1059.003 Windows Command Shell |
MalwareUPPERCUT | UPPERCUT uses cmd.exe to execute commands on the victim’s machine. |
| T1059.003 Windows Command Shell |
MalwareADVSTORESHELL | ADVSTORESHELL can create a remote shell and run a given command. |
| T1059.003 Windows Command Shell |
MalwareStrifeWater | StrifeWater can execute shell commands using `cmd.exe`. |
| T1059.003 Windows Command Shell |
MalwareMivast | Mivast has the capability to open a remote shell and run basic commands. |
| T1059.003 Windows Command Shell |
MalwareHiddenWasp | HiddenWasp uses a script to automate tasks on the victim's machine and to assist in execution. |
| T1059.003 Windows Command Shell |
MalwareWarzoneRAT | WarzoneRAT can use `cmd.exe` to execute malicious code. |
| T1059.003 Windows Command Shell |
MalwareSLOTHFULMEDIA | SLOTHFULMEDIA can open a command line to execute commands. |
| T1059.003 Windows Command Shell |
MalwareSmall Sieve | Small Sieve can use `cmd.exe` to execute commands on a victim's system. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.