ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1059.001×

85 examples

TechniqueUsed byProcedure example
T1059.001
PowerShell
GroupMedusa Group

Medusa Group has leveraged PowerShell for execution and defense evasion. Medusa Group has also utilized PowerShell to execute a bitsadmin transfer from file hosting site.

T1059.001
PowerShell
GroupBRONZE BUTLER

BRONZE BUTLER has used PowerShell for execution.

T1059.001
PowerShell
GroupDeep Panda

Deep Panda has used PowerShell scripts to download and execute programs in memory, without writing to disk.

T1059.001
PowerShell
GroupEmber Bear

Ember Bear has used PowerShell commands to gather information from compromised systems, such as email servers.

T1059.001
PowerShell
GroupLazyScripter

LazyScripter has used PowerShell scripts to execute malicious code.

T1059.001
PowerShell
GroupToddyCat

ToddyCat has used Powershell scripts to perform post exploit collection.

T1059.001
PowerShell
GroupAPT28

APT28 downloads and executes PowerShell scripts and performs PowerShell commands.

T1059.001
PowerShell
GroupAPT42

APT42 has downloaded and executed PowerShell payloads.

T1059.001
PowerShell
GroupAPT5

APT5 has used PowerShell to accomplish tasks within targeted environments.

T1059.001
PowerShell
GroupFox Kitten

Fox Kitten has used PowerShell scripts to access credential data.

T1059.001
PowerShell
GroupAPT-C-36

APT-C-36 has used PowerShell in malware execution including as part of fileless attack chains to download additional payloads.

T1059.001
PowerShell
GroupTonto Team

Tonto Team has used PowerShell to download additional payloads.

T1059.001
PowerShell
GroupGOLD SOUTHFIELD

GOLD SOUTHFIELD has staged and executed PowerShell scripts on compromised hosts.

T1059.001
PowerShell
GroupLazarus Group

Lazarus Group has used PowerShell to execute commands and malicious code.

T1059.001
PowerShell
GroupEarth Lusca

Earth Lusca has used PowerShell to execute commands.

T1059.001
PowerShell
GroupSilence

Silence has used PowerShell to download and execute payloads.

T1059.001
PowerShell
GroupThrip

Thrip leveraged PowerShell to run commands to download payloads, traverse the compromised networks, and carry out reconnaissance.

T1059.001
PowerShell
GroupCobalt Group

Cobalt Group has used powershell.exe to download and execute scripts.

T1059.001
PowerShell
GroupCopyKittens

CopyKittens has used PowerShell Empire.

T1059.001
PowerShell
GroupWizard Spider

Wizard Spider has used macros to execute PowerShell scripts to download malware on victim's machines. It has also used PowerShell to execute commands and move laterally through a victim network.

T1059.001
PowerShell
GroupMolerats

Molerats used PowerShell implants on target machines.

T1059.001
PowerShell
GroupInception

Inception has used PowerShell to execute malicious commands and payloads.

T1059.001
PowerShell
GroupVOID MANTICORE

VOID MANTICORE has utilized PowerShell to execute malware in victim environments.

T1059.001
PowerShell
GroupPlay

Play has used Base64-encoded PowerShell scripts to disable Microsoft Defender.

T1059.001
PowerShell
GroupHEXANE

HEXANE has used PowerShell-based tools and scripts for discovery and collection on compromised hosts.

T1059.001
PowerShell
GroupDaggerfly

Daggerfly used PowerShell to download and execute remote-hosted files on victim systems.

T1059.001
PowerShell
GroupWIRTE

WIRTE has used PowerShell for script execution.

T1059.001
PowerShell
GroupMagic Hound

Magic Hound has used PowerShell for execution and privilege escalation.

T1059.001
PowerShell
GroupThreat Group-3390

Threat Group-3390 has used PowerShell for execution.

T1059.001
PowerShell
GroupAPT33

APT33 has utilized PowerShell to download files from the C2 server and run various scripts.

T1059.001
PowerShell
GroupFIN10

FIN10 uses PowerShell for execution as well as PowerShell Empire to establish persistence.

T1059.001
PowerShell
GroupFIN8

FIN8's malicious spearphishing payloads are executed as PowerShell. FIN8 has also used PowerShell for lateral movement and credential access.

T1059.001
PowerShell
GroupFIN13

FIN13 has used PowerShell commands to obtain DNS data from a compromised network.

T1059.001
PowerShell
GroupAPT19

APT19 used PowerShell commands to execute payloads.

T1059.001
PowerShell
GroupNomadic Octopus

Nomadic Octopus has used PowerShell for execution.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.