ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1059.003
Windows Command Shell
MalwareHermeticWizard

HermeticWizard can use `cmd.exe` for execution on compromised hosts.

T1059.003
Windows Command Shell
ToolCovenant

Covenant provides access to a Command Shell in Windows environments for follow-on command execution and tasking.

T1059.003
Windows Command Shell
ToolDiskpart

Diskpart can execute a disk partition script file, which attempts to mount a virtual hard disk. Diskpart can also assign and mount virtual disks.

T1059.003
Windows Command Shell
ToolSILENTTRINITY

SILENTTRINITY can use `cmd.exe` to enable lateral movement using DCOM.

T1059.003
Windows Command Shell
ToolEmpire

Empire has modules for executing scripts.

T1059.003
Windows Command Shell
ToolPcShare

PcShare can execute `cmd` commands on a compromised host.

T1059.003
Windows Command Shell
ToolAsyncRAT

AsyncRAT can be deployed via batch script.

T1059.003
Windows Command Shell
ToolBrute Ratel C4

Brute Ratel C4 can use cmd.exe for execution.

T1059.003
Windows Command Shell
ToolRemcos

Remcos can launch a remote command line to execute commands on the victim’s machine.

T1059.003
Windows Command Shell
ToolOut1

Out1 can use native command line for execution.

T1059.003
Windows Command Shell
ToolMCMD

MCMD can launch a console process (cmd.exe) with redirected standard input and output.

T1059.003
Windows Command Shell
Toolcmd

cmd is used to execute programs and other actions at the command-line interface.

T1059.003
Windows Command Shell
ToolKoadic

Koadic can open an interactive command-shell to perform command line functions on victim machines. Koadic performs most of its operations using Windows Script Host (Jscript) and to run arbitrary shellcode.

T1059.003
Windows Command Shell
ToolQuasarRAT

QuasarRAT can launch a remote shell to execute commands on the victim’s machine.

T1059.004
Unix Shell
CampaignKV Botnet Activity

KV Botnet Activity utilizes multiple Bash scripts during botnet installation stages, and the final botnet payload allows for running commands in the Bash shell.

T1059.004
Unix Shell
CampaignRedPenguin

During RedPenguin, UNC3886 used malware capable of launching an interactive shell.

T1059.004
Unix Shell
CampaignOperation MidnightEclipse

During Operation MidnightEclipse, threat actors piped output from stdout to bash for execution.

T1059.004
Unix Shell
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries utilized the Linux `dd` command to overwrite portions of the disks with random data.

T1059.004
Unix Shell
CampaignQuad7 Activity

Quad7 Activity has enabled the creation of an access-controlled command shell /bin/sh on compromised routers.

T1059.004
Unix Shell
CampaignFLORAHOX Activity

FLORAHOX Activity has executed multiple Bash controller scripts to provide command line inputs for FLORAHOX traversal configurations.

T1059.004
Unix Shell
GroupVolt Typhoon

Volt Typhoon has used Brightmetricagent.exe which contains a command- line interface (CLI) library that can leverage command shells including Z Shell (zsh).

T1059.004
Unix Shell
GroupAPT41

APT41 used Linux shell commands for system survey and information gathering prior to exploitation of vulnerabilities such as CVE-2019-19871.

T1059.004
Unix Shell
GroupTeamTNT

TeamTNT has used shell scripts for execution.

T1059.004
Unix Shell
GroupRocke

Rocke used shell scripts to run commands which would obtain persistence and execute the cryptocurrency mining malware.

T1059.004
Unix Shell
GroupScattered Spider

Scattered Spider has used the command shell to upload and install the Teleport remote access tool to a compromised vCenter Server Appliance.

T1059.004
Unix Shell
GroupUNC3886

UNC3886 has used a bash script to install malicious vSphere Installation Bundles (VIBs).

T1059.004
Unix Shell
GroupContagious Interview

Contagious Interview has targeted macOS victim hosts using a bash downloader coremedia.sh and a bash script cloud.sh.

T1059.004
Unix Shell
GroupSea Turtle

Sea Turtle used shell scripts for post-exploitation execution in victim environments.

T1059.004
Unix Shell
GroupAquatic Panda

Aquatic Panda used malicious shell scripts in Linux environments following access via SSH to install Linux versions of Winnti malware.

T1059.004
Unix Shell
GroupVelvet Ant

Velvet Ant used a custom tool, VELVETSTING, to parse encoded inbound commands to compromised F5 BIG-IP devices and then execute them via the Unix shell.

T1059.004
Unix Shell
MalwareBRICKSTORM

BRICKSTORM has executed shell commands using `/bin/sh`.

T1059.004
Unix Shell
MalwareCOATHANGER

COATHANGER provides a BusyBox reverse shell for command and control.

T1059.004
Unix Shell
MalwareWindTail

WindTail can use the open command to execute an application.

T1059.004
Unix Shell
MalwareExaramel for Linux

Exaramel for Linux has a command to execute a shell command on the system.

T1059.004
Unix Shell
MalwareCASTLETAP

CASTLETAP has the ability to spawn BusyBox command shell in victim environments.

T1059.004
Unix Shell
MalwareNETWIRE

NETWIRE has the ability to use /bin/bash and /bin/sh to execute commands.

T1059.004
Unix Shell
MalwareJ-magic

The J-magic agent is executed through a command line argument which specifies an interface and listening port.

T1059.004
Unix Shell
MalwareGomir

Gomir reads command line arguments and parses them for functionality when executed from a Linux shell, and can execute arbitrary strings passed to it as shell commands.

T1059.004
Unix Shell
MalwareBOLDMOVE

BOLDMOVE is capable of spawning a remote command shell.

T1059.004
Unix Shell
MalwareTurian

Turian has the ability to use /bin/sh to execute commands.

T1059.004
Unix Shell
MalwareHildegard

Hildegard has used shell scripts for execution.

T1059.004
Unix Shell
MalwareCuckoo Stealer

Cuckoo Stealer can spawn a bash shell to enable execution on compromised hosts.

T1059.004
Unix Shell
MalwareSkidmap

Skidmap has used pm.sh to download and install its main payload.

T1059.004
Unix Shell
MalwareREPTILE

REPTILE can deploy components automatically with shell scripts.

T1059.004
Unix Shell
MalwareDoki

Doki has executed shell scripts with /bin/sh.

T1059.004
Unix Shell
MalwareFysbis

Fysbis has the ability to create and execute commands in a remote shell for CLI.

T1059.004
Unix Shell
MalwareKazuar

Kazuar uses /bin/bash to execute commands on the victim’s machine.

T1059.004
Unix Shell
MalwareGreen Lambert

Green Lambert can use shell scripts for execution, such as /bin/sh -c.

T1059.004
Unix Shell
MalwareSnappyTCP

SnappyTCP creates the reverse shell using a pthread spawning a bash shell.

T1059.004
Unix Shell
MalwareChaos

Chaos provides a reverse shell connection on 8338/TCP, encrypted via AES.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.