Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1059.008 Network Device CLI |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries leveraged the native CLI of the targeted FortiGate device. |
| T1059.008 Network Device CLI |
MalwareLine Dancer | Line Dancer can execute native commands in networking device command line interfaces. |
| T1059.008 Network Device CLI |
MalwarePHASEJAM | PHASEJAM has leveraged native commands associated with the compromised network appliance to execute code. |
| T1059.008 Network Device CLI |
MalwareDRYHOOK | DRYHOOK has the ability to interact with Ivanti Connect Secure environments and to modify system components. |
| T1059.009 Cloud API |
GroupTeamTNT | TeamTNT has leveraged AWS CLI to enumerate cloud environments with compromised credentials. |
| T1059.009 Cloud API |
GroupStorm-0501 | Storm-0501 has leveraged Cloud CLI to execute commands and exfiltrate data from compromised environments. |
| T1059.009 Cloud API |
GroupAPT29 | APT29 has leveraged the Microsoft Graph API to perform various actions across Azure and M365 environments. They have also utilized AADInternals PowerShell Modules to access the API |
| T1059.009 Cloud API |
ToolPacu | Pacu leverages the AWS CLI for its operations. |
| T1059.009 Cloud API |
ToolTruffleHog | TruffleHog has leveraged Cloud CLI in order to enumerate and gather credentials. |
| T1059.009 Cloud API |
GroupShinyHunters | ShinyHunters has used the AWS Command Line Interface (CLI) for operations to include a variety of API calls, such as `ListBuckets`, `CreateBucket` and `DeleteBucket`. |
| T1059.010 AutoHotKey & AutoIT |
GroupAPT39 | APT39 has utilized AutoIt malware scripts embedded in Microsoft Office documents or malicious links. |
| T1059.010 AutoHotKey & AutoIT |
MalwareLumma Stealer | Lumma Stealer has utilized AutoIt malware scripts and AutoIt executables. |
| T1059.010 AutoHotKey & AutoIT |
MalwareDarkGate | DarkGate uses AutoIt scripts dropped to a hidden directory during initial installation phases, such as `test.au3`. |
| T1059.010 AutoHotKey & AutoIT |
MalwareXLoader | XLoader can use an AutoIT script to decrypt a payload file, load it into victim memory, then execute it on the victim machine. |
| T1059.010 AutoHotKey & AutoIT |
MalwareOutSteel | OutSteel was developed using the AutoIT scripting language. |
| T1059.010 AutoHotKey & AutoIT |
MalwareMelcoz | Melcoz has been distributed through an AutoIt loader script. |
| T1059.011 Lua |
MalwareLine Runner | Line Runner utilizes Lua scripts for command execution. |
| T1059.011 Lua |
MalwareRemsec | Remsec can use modules written in Lua for execution. |
| T1059.011 Lua |
MalwareRedLine Stealer | RedLine Stealer malware has leveraged Lua bytecode to perform malicious behavior. |
| T1059.011 Lua |
MalwareEvilBunny | EvilBunny has used Lua scripts to execute payloads. |
| T1059.011 Lua |
MalwarePoetRAT | PoetRAT has executed a Lua script through a Lua interpreter for Windows. |
| T1059.012 Hypervisor CLI |
GroupUNC3886 | UNC3886 has used the esxcli command line utility to modify firewall rules, install malware, and for artifact removal. |
| T1059.012 Hypervisor CLI |
MalwareCheerscrypt | Cheerscrypt has leveraged `esxcli` in order to terminate running virtual machines. |
| T1059.012 Hypervisor CLI |
MalwareVIRTUALPIE | VIRTUALPIE is capable of command line execution on compromised ESXi servers. |
| T1059.012 Hypervisor CLI |
MalwareRoyal | Royal ransomware uses `esxcli` to gather a list of running VMs and terminate them. |
| T1059.013 Container CLI/API |
GroupTeamTNT | TeamTNT targeted misconfigured containers and used container CLI tools. |
| T1059.013 Container CLI/API |
MalwareMini Shai-Hulud | Mini Shai-Hulud has utilized the Docker command-line tool to gather details of the victim environment and collect credentials. |
| T1059.013 Container CLI/API |
GroupTeamPCP | TeamPCP has queried the Kubernetes API for local service account tokens and has used `kubectl` for lateral movement. |
| T1068 Exploitation for Privilege Escalation |
CampaignShadowRay | During ShadowRay, threat actors downloaded a privilege escalation payload to gain root access. |
| T1068 Exploitation for Privilege Escalation |
CampaignLeviathan Australian Intrusions | Leviathan exploited software vulnerabilities in victim environments to escalate privileges during Leviathan Australian Intrusions. |
| T1068 Exploitation for Privilege Escalation |
GroupBlackByte | BlackByte has exploited CVE-2024-37085 in VMWare ESXi software for authentication bypass and subsequent privilege escalation. |
| T1068 Exploitation for Privilege Escalation |
GroupVolt Typhoon | Volt Typhoon has gained initial access by exploiting privilege escalation vulnerabilities in the operating system or network services. |
| T1068 Exploitation for Privilege Escalation |
GroupAPT32 | APT32 has used CVE-2016-7255 to escalate privileges. |
| T1068 Exploitation for Privilege Escalation |
GroupHAFNIUM | HAFNIUM has targeted unpatched applications to elevate access in targeted organizations. |
| T1068 Exploitation for Privilege Escalation |
GroupFIN6 | FIN6 has used tools to exploit Windows vulnerabilities in order to escalate privileges. The tools targeted CVE-2013-3660, CVE-2011-2005, and CVE-2010-4398, all of which could allow local users to access kernel-level privileges. |
| T1068 Exploitation for Privilege Escalation |
GroupZIRCONIUM | ZIRCONIUM has exploited CVE-2017-0005 for local privilege escalation. |
| T1068 Exploitation for Privilege Escalation |
GroupScattered Spider | Scattered Spider has deployed a malicious kernel driver through exploitation of CVE-2015-2291 in the Intel Ethernet diagnostics driver for Windows (iqvw64.sys). |
| T1068 Exploitation for Privilege Escalation |
GroupUNC3886 | UNC3886 has exploited zero-day vulnerability CVE-2023-20867 to enable execution of privileged commands across Windows, Linux, and PhotonOS (vCenter) guest VMs. |
| T1068 Exploitation for Privilege Escalation |
GroupOilRig | OilRig has exploited the Windows Kernel Elevation of Privilege vulnerability, CVE-2024-30088. |
| T1068 Exploitation for Privilege Escalation |
GroupMoustachedBouncer | MoustachedBouncer has exploited CVE-2021-1732 to execute malware components with elevated rights. |
| T1068 Exploitation for Privilege Escalation |
GroupTurla | Turla has exploited vulnerabilities in the VBoxDrv.sys driver to obtain kernel mode privileges. |
| T1068 Exploitation for Privilege Escalation |
GroupBITTER | BITTER has exploited CVE-2021-1732 for privilege escalation. |
| T1068 Exploitation for Privilege Escalation |
GroupAPT29 | APT29 has exploited CVE-2021-36934 to escalate privileges on a compromised host. |
| T1068 Exploitation for Privilege Escalation |
GroupWhitefly | Whitefly has used an open-source tool to exploit a known Windows privilege escalation vulnerability (CVE-2016-0051) on unpatched computers. |
| T1068 Exploitation for Privilege Escalation |
GroupAPT28 | APT28 has exploited CVE-2014-4076, CVE-2015-2387, CVE-2015-1701, CVE-2017-0263, and CVE-2022-38028 to escalate privileges. |
| T1068 Exploitation for Privilege Escalation |
GroupTonto Team | Tonto Team has exploited CVE-2019-0803 and MS16-032 to escalate privileges. |
| T1068 Exploitation for Privilege Escalation |
GroupLAPSUS$ | LAPSUS$ has exploited unpatched vulnerabilities on internally accessible servers including JIRA, GitLab, and Confluence for privilege escalation. |
| T1068 Exploitation for Privilege Escalation |
GroupCobalt Group | Cobalt Group has used exploits to increase their levels of rights and privileges. |
| T1068 Exploitation for Privilege Escalation |
GroupPLATINUM | PLATINUM has leveraged a zero-day vulnerability to escalate privileges. |
| T1068 Exploitation for Privilege Escalation |
GroupThreat Group-3390 | Threat Group-3390 has used CVE-2014-6324 and CVE-2017-0213 to escalate privileges. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.