Real-world descriptions of how a group, tool or campaign used a technique.
4628 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1059.001 PowerShell |
GroupUNC3886 | UNC3886 has used a PowerShell script to search memory dumps for credentials. |
| T1059.001 PowerShell |
GroupTA2541 | TA2541 has used PowerShell to download files and to inject into various Windows processes. |
| T1059.001 PowerShell |
GroupAkira | Akira has used PowerShell scripts for credential harvesting and privilege escalation. |
| T1059.001 PowerShell |
GroupOilRig | OilRig has used PowerShell scripts for execution, including use of a macro to run a PowerShell command to decode file contents. |
| T1059.001 PowerShell |
GroupTA459 | TA459 has used PowerShell for execution of a payload. |
| T1059.001 PowerShell |
GroupAquatic Panda | Aquatic Panda has downloaded additional scripts and executed Base64 encoded commands in PowerShell. |
| T1059.001 PowerShell |
GroupSaint Bear | Saint Bear relies extensively on PowerShell execution from malicious attachments and related content to retrieve and execute follow-on payloads. |
| T1059.001 PowerShell |
GroupDarkHydrus | DarkHydrus leveraged PowerShell to download and execute additional scripts for execution. |
| T1059.001 PowerShell |
GroupConfucius | Confucius has used PowerShell to execute malicious files and payloads. |
| T1059.001 PowerShell |
GroupLeviathan | Leviathan has used PowerShell for execution. |
| T1059.001 PowerShell |
GroupMoustachedBouncer | MoustachedBouncer has used plugins to execute PowerShell scripts. |
| T1059.001 PowerShell |
GroupBlue Mockingbird | Blue Mockingbird has used PowerShell reverse TCP shells to issue interactive commands over a network connection. |
| T1059.001 PowerShell |
GroupWinter Vivern | Winter Vivern passed execution from document macros to PowerShell scripts during initial access operations. Winter Vivern used batch scripts that called PowerShell commands as part of initial access and installation operations. |
| T1059.001 PowerShell |
GroupTurla | Turla has used PowerShell to execute commands/scripts, in some cases via a custom executable or code from Empire's PSInject. Turla has also used PowerShell scripts to load and execute malware in memory. |
| T1059.001 PowerShell |
GroupStorm-0501 | Storm-0501 has leveraged PowerShell to execute commands and scripts. |
| T1059.001 PowerShell |
GroupPoseidon Group | The Poseidon Group's Information Gathering Tool (IGT) includes PowerShell components. |
| T1059.001 PowerShell |
GroupTA505 | TA505 has used PowerShell to download and execute malware and reconnaissance scripts. |
| T1059.001 PowerShell |
GroupDarkVishnya | DarkVishnya used PowerShell to create shellcode loaders. |
| T1059.001 PowerShell |
GroupRedCurl | RedCurl has used PowerShell to execute commands and to download malware. |
| T1059.001 PowerShell |
GroupStealth Falcon | Stealth Falcon malware uses PowerShell commands to perform various functions, including gathering system information via WMI and executing commands from its C2 server. |
| T1059.001 PowerShell |
GroupAPT29 | APT29 has used encoded PowerShell scripts uploaded to CozyCar installations to download and install SeaDuke. |
| T1059.001 PowerShell |
GroupCinnamon Tempest | Cinnamon Tempest has used PowerShell to communicate with C2, download files, and execute reconnaissance commands. |
| T1059.001 PowerShell |
GroupChimera | Chimera has used PowerShell scripts to execute malicious payloads and the DSInternals PowerShell module to make use of Active Directory features. |
| T1059.001 PowerShell |
GroupMedusa Group | Medusa Group has leveraged PowerShell for execution and defense evasion. Medusa Group has also utilized PowerShell to execute a bitsadmin transfer from file hosting site. |
| T1059.001 PowerShell |
GroupBRONZE BUTLER | BRONZE BUTLER has used PowerShell for execution. |
| T1059.001 PowerShell |
GroupDeep Panda | Deep Panda has used PowerShell scripts to download and execute programs in memory, without writing to disk. |
| T1059.001 PowerShell |
GroupEmber Bear | Ember Bear has used PowerShell commands to gather information from compromised systems, such as email servers. |
| T1059.001 PowerShell |
GroupLazyScripter | LazyScripter has used PowerShell scripts to execute malicious code. |
| T1059.001 PowerShell |
GroupToddyCat | ToddyCat has used Powershell scripts to perform post exploit collection. |
| T1059.001 PowerShell |
GroupAPT28 | APT28 downloads and executes PowerShell scripts and performs PowerShell commands. |
| T1059.001 PowerShell |
GroupAPT42 | APT42 has downloaded and executed PowerShell payloads. |
| T1059.001 PowerShell |
GroupAPT5 | APT5 has used PowerShell to accomplish tasks within targeted environments. |
| T1059.001 PowerShell |
GroupFox Kitten | Fox Kitten has used PowerShell scripts to access credential data. |
| T1059.001 PowerShell |
GroupAPT-C-36 | APT-C-36 has used PowerShell in malware execution including as part of fileless attack chains to download additional payloads. |
| T1059.001 PowerShell |
GroupTonto Team | Tonto Team has used PowerShell to download additional payloads. |
| T1059.001 PowerShell |
GroupGOLD SOUTHFIELD | GOLD SOUTHFIELD has staged and executed PowerShell scripts on compromised hosts. |
| T1059.001 PowerShell |
GroupLazarus Group | Lazarus Group has used PowerShell to execute commands and malicious code. |
| T1059.001 PowerShell |
GroupEarth Lusca | Earth Lusca has used PowerShell to execute commands. |
| T1059.001 PowerShell |
GroupSilence | Silence has used PowerShell to download and execute payloads. |
| T1059.001 PowerShell |
GroupThrip | Thrip leveraged PowerShell to run commands to download payloads, traverse the compromised networks, and carry out reconnaissance. |
| T1059.001 PowerShell |
GroupCobalt Group | Cobalt Group has used powershell.exe to download and execute scripts. |
| T1059.001 PowerShell |
GroupCopyKittens | CopyKittens has used PowerShell Empire. |
| T1059.001 PowerShell |
GroupWizard Spider | Wizard Spider has used macros to execute PowerShell scripts to download malware on victim's machines. It has also used PowerShell to execute commands and move laterally through a victim network. |
| T1059.001 PowerShell |
GroupMolerats | Molerats used PowerShell implants on target machines. |
| T1059.001 PowerShell |
GroupInception | Inception has used PowerShell to execute malicious commands and payloads. |
| T1059.001 PowerShell |
GroupVOID MANTICORE | VOID MANTICORE has utilized PowerShell to execute malware in victim environments. |
| T1059.001 PowerShell |
GroupPlay | Play has used Base64-encoded PowerShell scripts to disable Microsoft Defender. |
| T1059.001 PowerShell |
GroupHEXANE | HEXANE has used PowerShell-based tools and scripts for discovery and collection on compromised hosts. |
| T1059.001 PowerShell |
GroupDaggerfly | Daggerfly used PowerShell to download and execute remote-hosted files on victim systems. |
| T1059.001 PowerShell |
GroupWIRTE | WIRTE has used PowerShell for script execution. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.