Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1059.003 Windows Command Shell |
MalwareHermeticWizard | HermeticWizard can use `cmd.exe` for execution on compromised hosts. |
| T1059.003 Windows Command Shell |
ToolCovenant | Covenant provides access to a Command Shell in Windows environments for follow-on command execution and tasking. |
| T1059.003 Windows Command Shell |
ToolDiskpart | Diskpart can execute a disk partition script file, which attempts to mount a virtual hard disk. Diskpart can also assign and mount virtual disks. |
| T1059.003 Windows Command Shell |
ToolSILENTTRINITY | SILENTTRINITY can use `cmd.exe` to enable lateral movement using DCOM. |
| T1059.003 Windows Command Shell |
ToolEmpire | Empire has modules for executing scripts. |
| T1059.003 Windows Command Shell |
ToolPcShare | PcShare can execute `cmd` commands on a compromised host. |
| T1059.003 Windows Command Shell |
ToolAsyncRAT | AsyncRAT can be deployed via batch script. |
| T1059.003 Windows Command Shell |
ToolBrute Ratel C4 | Brute Ratel C4 can use cmd.exe for execution. |
| T1059.003 Windows Command Shell |
ToolRemcos | Remcos can launch a remote command line to execute commands on the victim’s machine. |
| T1059.003 Windows Command Shell |
ToolOut1 | Out1 can use native command line for execution. |
| T1059.003 Windows Command Shell |
ToolMCMD | MCMD can launch a console process (cmd.exe) with redirected standard input and output. |
| T1059.003 Windows Command Shell |
Toolcmd | cmd is used to execute programs and other actions at the command-line interface. |
| T1059.003 Windows Command Shell |
ToolKoadic | Koadic can open an interactive command-shell to perform command line functions on victim machines. Koadic performs most of its operations using Windows Script Host (Jscript) and to run arbitrary shellcode. |
| T1059.003 Windows Command Shell |
ToolQuasarRAT | QuasarRAT can launch a remote shell to execute commands on the victim’s machine. |
| T1059.004 Unix Shell |
CampaignKV Botnet Activity | KV Botnet Activity utilizes multiple Bash scripts during botnet installation stages, and the final botnet payload allows for running commands in the Bash shell. |
| T1059.004 Unix Shell |
CampaignRedPenguin | During RedPenguin, UNC3886 used malware capable of launching an interactive shell. |
| T1059.004 Unix Shell |
CampaignOperation MidnightEclipse | During Operation MidnightEclipse, threat actors piped output from stdout to bash for execution. |
| T1059.004 Unix Shell |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries utilized the Linux `dd` command to overwrite portions of the disks with random data. |
| T1059.004 Unix Shell |
CampaignQuad7 Activity | Quad7 Activity has enabled the creation of an access-controlled command shell |
| T1059.004 Unix Shell |
CampaignFLORAHOX Activity | FLORAHOX Activity has executed multiple Bash controller scripts to provide command line inputs for FLORAHOX traversal configurations. |
| T1059.004 Unix Shell |
GroupVolt Typhoon | Volt Typhoon has used Brightmetricagent.exe which contains a command- line interface (CLI) library that can leverage command shells including Z Shell (zsh). |
| T1059.004 Unix Shell |
GroupAPT41 | APT41 used Linux shell commands for system survey and information gathering prior to exploitation of vulnerabilities such as CVE-2019-19871. |
| T1059.004 Unix Shell |
GroupTeamTNT | TeamTNT has used shell scripts for execution. |
| T1059.004 Unix Shell |
GroupRocke | Rocke used shell scripts to run commands which would obtain persistence and execute the cryptocurrency mining malware. |
| T1059.004 Unix Shell |
GroupScattered Spider | Scattered Spider has used the command shell to upload and install the Teleport remote access tool to a compromised vCenter Server Appliance. |
| T1059.004 Unix Shell |
GroupUNC3886 | UNC3886 has used a bash script to install malicious vSphere Installation Bundles (VIBs). |
| T1059.004 Unix Shell |
GroupContagious Interview | Contagious Interview has targeted macOS victim hosts using a bash downloader coremedia.sh and a bash script cloud.sh. |
| T1059.004 Unix Shell |
GroupSea Turtle | Sea Turtle used shell scripts for post-exploitation execution in victim environments. |
| T1059.004 Unix Shell |
GroupAquatic Panda | Aquatic Panda used malicious shell scripts in Linux environments following access via SSH to install Linux versions of Winnti malware. |
| T1059.004 Unix Shell |
GroupVelvet Ant | Velvet Ant used a custom tool, VELVETSTING, to parse encoded inbound commands to compromised F5 BIG-IP devices and then execute them via the Unix shell. |
| T1059.004 Unix Shell |
MalwareBRICKSTORM | BRICKSTORM has executed shell commands using `/bin/sh`. |
| T1059.004 Unix Shell |
MalwareCOATHANGER | COATHANGER provides a BusyBox reverse shell for command and control. |
| T1059.004 Unix Shell |
MalwareWindTail | WindTail can use the |
| T1059.004 Unix Shell |
MalwareExaramel for Linux | Exaramel for Linux has a command to execute a shell command on the system. |
| T1059.004 Unix Shell |
MalwareCASTLETAP | CASTLETAP has the ability to spawn BusyBox command shell in victim environments. |
| T1059.004 Unix Shell |
MalwareNETWIRE | NETWIRE has the ability to use |
| T1059.004 Unix Shell |
MalwareJ-magic | The J-magic agent is executed through a command line argument which specifies an interface and listening port. |
| T1059.004 Unix Shell |
MalwareGomir | Gomir reads command line arguments and parses them for functionality when executed from a Linux shell, and can execute arbitrary strings passed to it as shell commands. |
| T1059.004 Unix Shell |
MalwareBOLDMOVE | BOLDMOVE is capable of spawning a remote command shell. |
| T1059.004 Unix Shell |
MalwareTurian | Turian has the ability to use |
| T1059.004 Unix Shell |
MalwareHildegard | Hildegard has used shell scripts for execution. |
| T1059.004 Unix Shell |
MalwareCuckoo Stealer | Cuckoo Stealer can spawn a bash shell to enable execution on compromised hosts. |
| T1059.004 Unix Shell |
MalwareSkidmap | Skidmap has used |
| T1059.004 Unix Shell |
MalwareREPTILE | REPTILE can deploy components automatically with shell scripts. |
| T1059.004 Unix Shell |
MalwareDoki | Doki has executed shell scripts with /bin/sh. |
| T1059.004 Unix Shell |
MalwareFysbis | Fysbis has the ability to create and execute commands in a remote shell for CLI. |
| T1059.004 Unix Shell |
MalwareKazuar | Kazuar uses /bin/bash to execute commands on the victim’s machine. |
| T1059.004 Unix Shell |
MalwareGreen Lambert | Green Lambert can use shell scripts for execution, such as |
| T1059.004 Unix Shell |
MalwareSnappyTCP | SnappyTCP creates the reverse shell using a pthread spawning a bash shell. |
| T1059.004 Unix Shell |
MalwareChaos | Chaos provides a reverse shell connection on 8338/TCP, encrypted via AES. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.