Real-world descriptions of how a group, tool or campaign used a technique.
131 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1059.001 PowerShell |
MalwareCuba | Cuba has been dropped onto systems and used for lateral movement via obfuscated PowerShell scripts. |
| T1059.001 PowerShell |
MalwareClambling | The Clambling dropper can use PowerShell to download the malware. |
| T1059.001 PowerShell |
MalwarePureCrypter | PureCrypter can execute PowerShell commands to exclude files from EDR and to self-delete. |
| T1059.001 PowerShell |
MalwareAkira | Akira will execute PowerShell commands to delete system volume shadow copies. |
| T1059.001 PowerShell |
MalwareDarkGate | DarkGate has used PowerShell to create a remote shell. |
| T1059.001 PowerShell |
MalwareLockBit 3.0 | LockBit 3.0 can use PowerShell to apply Group Policy changes. |
| T1059.001 PowerShell |
MalwareSHARPSTATS | SHARPSTATS has the ability to employ a custom PowerShell script. |
| T1059.001 PowerShell |
MalwareFerocious | Ferocious can use PowerShell scripts for execution. |
| T1059.001 PowerShell |
MalwareCreepyDrive | CreepyDrive can use Powershell for execution, including the cmdlets `Invoke-WebRequest` and `Invoke-Expression`. |
| T1059.001 PowerShell |
MalwareNetwalker | Netwalker has been written in PowerShell and executed directly in memory, avoiding detection. |
| T1059.001 PowerShell |
MalwareSaint Bot | Saint Bot has used PowerShell for execution. |
| T1059.001 PowerShell |
MalwareCharmPower | CharmPower can use PowerShell for payload execution and C2 communication. |
| T1059.001 PowerShell |
MalwareMuddyViper | MuddyViper has used PowerShell.exe to launch a reverse shell. |
| T1059.001 PowerShell |
MalwareSMOKEDHAM | SMOKEDHAM can execute Powershell commands sent from its C2 server. |
| T1059.001 PowerShell |
MalwareQUADAGENT | QUADAGENT uses PowerShell scripts for execution. |
| T1059.001 PowerShell |
MalwareLP-Notes | LP-Notes has been downloaded and executed by PowerShell’s`Invoke-WebRequest` and `Invoke-Expression` cmdlets. |
| T1059.001 PowerShell |
MalwareSpica | Spica can use an obfuscated PowerShell command to create a scheduled task for persistence. |
| T1059.001 PowerShell |
MalwareBandook | Bandook has used PowerShell loaders as part of execution. |
| T1059.001 PowerShell |
MalwareKONNI | KONNI used PowerShell to download and execute a specific 64-bit version of the malware. |
| T1059.001 PowerShell |
MalwareMoleNet | MoleNet can use PowerShell to set persistence. |
| T1059.001 PowerShell |
MalwareKGH_SPY | KGH_SPY can execute PowerShell commands on the victim's machine. |
| T1059.001 PowerShell |
MalwareBlack Basta | Black Basta has used PowerShell scripts for discovery and to execute files over the network. |
| T1059.001 PowerShell |
MalwareRogueRobin | RogueRobin uses a command prompt to run a PowerShell script from Excel. To assist in establishing persistence, RogueRobin creates |
| T1059.001 PowerShell |
MalwareSQLRat | SQLRat has used PowerShell to create a Meterpreter session. |
| T1059.001 PowerShell |
MalwareLitePower | LitePower can use a PowerShell script to execute commands. |
| T1059.001 PowerShell |
MalwareMosquito | Mosquito can launch PowerShell Scripts. |
| T1059.001 PowerShell |
MalwareStrelaStealer | StrelaStealer variants have used PowerShell scripts to download or drop payloads, including obfuscated variants to connect to a WebDAV server to download and executed an encrypted DLL for installation. |
| T1059.001 PowerShell |
MalwareBazar | Bazar can execute a PowerShell script received from C2. |
| T1059.001 PowerShell |
MalwareRATANKBA | There is a variant of RATANKBA that uses a PowerShell script instead of the traditional PE form. |
| T1059.001 PowerShell |
MalwarePysa | Pysa has used Powershell scripts to deploy its ransomware. |
| T1059.001 PowerShell |
MalwareLockBit 2.0 | LockBit 2.0 can use the PowerShell module `InvokeGPUpdate` to modify Group Policy. |
| T1059.001 PowerShell |
MalwareCobalt Strike | Cobalt Strike can execute a payload on a remote host with PowerShell. This technique does not write any data to disk. Cobalt Strike can also use PowerSploit and other scripting frameworks to perform execution. |
| T1059.001 PowerShell |
MalwareServHelper | ServHelper has the ability to execute a PowerShell script to get information from the infected host. |
| T1059.001 PowerShell |
MalwareJCry | JCry has used PowerShell to execute payloads. |
| T1059.001 PowerShell |
MalwareREvil | REvil has used PowerShell to delete volume shadow copies and download files. |
| T1059.001 PowerShell |
MalwareValak | Valak has used PowerShell to download additional modules. |
| T1059.001 PowerShell |
MalwareOSX_OCEANLOTUS.D | OSX_OCEANLOTUS.D uses PowerShell scripts. |
| T1059.001 PowerShell |
MalwareIPsec Helper | IPsec Helper can run arbitrary PowerShell commands passed to it. |
| T1059.001 PowerShell |
MalwarePillowmint | Pillowmint has used a PowerShell script to install a shim database. |
| T1059.001 PowerShell |
MalwareRevenge RAT | Revenge RAT uses the PowerShell command |
| T1059.001 PowerShell |
MalwarePowGoop | PowGoop has the ability to use PowerShell scripts to execute commands. |
| T1059.001 PowerShell |
MalwareLokibot | Lokibot has used PowerShell commands embedded inside batch scripts. |
| T1059.001 PowerShell |
MalwareEgregor | Egregor has used an encoded PowerShell command by a service created by Cobalt Strike for lateral movement. |
| T1059.001 PowerShell |
MalwareCreepySnail | CreepySnail can use PowerShell for execution, including the cmdlets `Invoke-WebRequst` and `Invoke-Expression`. |
| T1059.001 PowerShell |
MalwarePowerPunch | PowerPunch has the ability to execute through PowerShell. |
| T1059.001 PowerShell |
MalwareBONDUPDATER | BONDUPDATER is written in PowerShell. |
| T1059.001 PowerShell |
MalwareTroll Stealer | Troll Stealer creates and executes a PowerShell script to delete itself. |
| T1059.001 PowerShell |
MalwareMeteor | Meteor can use PowerShell commands to disable the network adapters on a victim machines. |
| T1059.001 PowerShell |
MalwarenjRAT | njRAT has executed PowerShell commands via auto-run registry key persistence. |
| T1059.001 PowerShell |
MalwareComRAT | ComRAT has used PowerShell to load itself every time a user logs in to the system. ComRAT can execute PowerShell scripts loaded into memory or from the file system. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.