Real-world descriptions of how a group, tool or campaign used a technique.
85 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1059.001 PowerShell |
GroupMedusa Group | Medusa Group has leveraged PowerShell for execution and defense evasion. Medusa Group has also utilized PowerShell to execute a bitsadmin transfer from file hosting site. |
| T1059.001 PowerShell |
GroupBRONZE BUTLER | BRONZE BUTLER has used PowerShell for execution. |
| T1059.001 PowerShell |
GroupDeep Panda | Deep Panda has used PowerShell scripts to download and execute programs in memory, without writing to disk. |
| T1059.001 PowerShell |
GroupEmber Bear | Ember Bear has used PowerShell commands to gather information from compromised systems, such as email servers. |
| T1059.001 PowerShell |
GroupLazyScripter | LazyScripter has used PowerShell scripts to execute malicious code. |
| T1059.001 PowerShell |
GroupToddyCat | ToddyCat has used Powershell scripts to perform post exploit collection. |
| T1059.001 PowerShell |
GroupAPT28 | APT28 downloads and executes PowerShell scripts and performs PowerShell commands. |
| T1059.001 PowerShell |
GroupAPT42 | APT42 has downloaded and executed PowerShell payloads. |
| T1059.001 PowerShell |
GroupAPT5 | APT5 has used PowerShell to accomplish tasks within targeted environments. |
| T1059.001 PowerShell |
GroupFox Kitten | Fox Kitten has used PowerShell scripts to access credential data. |
| T1059.001 PowerShell |
GroupAPT-C-36 | APT-C-36 has used PowerShell in malware execution including as part of fileless attack chains to download additional payloads. |
| T1059.001 PowerShell |
GroupTonto Team | Tonto Team has used PowerShell to download additional payloads. |
| T1059.001 PowerShell |
GroupGOLD SOUTHFIELD | GOLD SOUTHFIELD has staged and executed PowerShell scripts on compromised hosts. |
| T1059.001 PowerShell |
GroupLazarus Group | Lazarus Group has used PowerShell to execute commands and malicious code. |
| T1059.001 PowerShell |
GroupEarth Lusca | Earth Lusca has used PowerShell to execute commands. |
| T1059.001 PowerShell |
GroupSilence | Silence has used PowerShell to download and execute payloads. |
| T1059.001 PowerShell |
GroupThrip | Thrip leveraged PowerShell to run commands to download payloads, traverse the compromised networks, and carry out reconnaissance. |
| T1059.001 PowerShell |
GroupCobalt Group | Cobalt Group has used powershell.exe to download and execute scripts. |
| T1059.001 PowerShell |
GroupCopyKittens | CopyKittens has used PowerShell Empire. |
| T1059.001 PowerShell |
GroupWizard Spider | Wizard Spider has used macros to execute PowerShell scripts to download malware on victim's machines. It has also used PowerShell to execute commands and move laterally through a victim network. |
| T1059.001 PowerShell |
GroupMolerats | Molerats used PowerShell implants on target machines. |
| T1059.001 PowerShell |
GroupInception | Inception has used PowerShell to execute malicious commands and payloads. |
| T1059.001 PowerShell |
GroupVOID MANTICORE | VOID MANTICORE has utilized PowerShell to execute malware in victim environments. |
| T1059.001 PowerShell |
GroupPlay | Play has used Base64-encoded PowerShell scripts to disable Microsoft Defender. |
| T1059.001 PowerShell |
GroupHEXANE | HEXANE has used PowerShell-based tools and scripts for discovery and collection on compromised hosts. |
| T1059.001 PowerShell |
GroupDaggerfly | Daggerfly used PowerShell to download and execute remote-hosted files on victim systems. |
| T1059.001 PowerShell |
GroupWIRTE | WIRTE has used PowerShell for script execution. |
| T1059.001 PowerShell |
GroupMagic Hound | Magic Hound has used PowerShell for execution and privilege escalation. |
| T1059.001 PowerShell |
GroupThreat Group-3390 | Threat Group-3390 has used PowerShell for execution. |
| T1059.001 PowerShell |
GroupAPT33 | APT33 has utilized PowerShell to download files from the C2 server and run various scripts. |
| T1059.001 PowerShell |
GroupFIN10 | FIN10 uses PowerShell for execution as well as PowerShell Empire to establish persistence. |
| T1059.001 PowerShell |
GroupFIN8 | FIN8's malicious spearphishing payloads are executed as PowerShell. FIN8 has also used PowerShell for lateral movement and credential access. |
| T1059.001 PowerShell |
GroupFIN13 | FIN13 has used PowerShell commands to obtain DNS data from a compromised network. |
| T1059.001 PowerShell |
GroupAPT19 | APT19 used PowerShell commands to execute payloads. |
| T1059.001 PowerShell |
GroupNomadic Octopus | Nomadic Octopus has used PowerShell for execution. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.