ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

4628 examples

TechniqueUsed byProcedure example
T1059.001
PowerShell
GroupUNC3886

UNC3886 has used a PowerShell script to search memory dumps for credentials.

T1059.001
PowerShell
GroupTA2541

TA2541 has used PowerShell to download files and to inject into various Windows processes.

T1059.001
PowerShell
GroupAkira

Akira has used PowerShell scripts for credential harvesting and privilege escalation.

T1059.001
PowerShell
GroupOilRig

OilRig has used PowerShell scripts for execution, including use of a macro to run a PowerShell command to decode file contents.

T1059.001
PowerShell
GroupTA459

TA459 has used PowerShell for execution of a payload.

T1059.001
PowerShell
GroupAquatic Panda

Aquatic Panda has downloaded additional scripts and executed Base64 encoded commands in PowerShell.

T1059.001
PowerShell
GroupSaint Bear

Saint Bear relies extensively on PowerShell execution from malicious attachments and related content to retrieve and execute follow-on payloads.

T1059.001
PowerShell
GroupDarkHydrus

DarkHydrus leveraged PowerShell to download and execute additional scripts for execution.

T1059.001
PowerShell
GroupConfucius

Confucius has used PowerShell to execute malicious files and payloads.

T1059.001
PowerShell
GroupLeviathan

Leviathan has used PowerShell for execution.

T1059.001
PowerShell
GroupMoustachedBouncer

MoustachedBouncer has used plugins to execute PowerShell scripts.

T1059.001
PowerShell
GroupBlue Mockingbird

Blue Mockingbird has used PowerShell reverse TCP shells to issue interactive commands over a network connection.

T1059.001
PowerShell
GroupWinter Vivern

Winter Vivern passed execution from document macros to PowerShell scripts during initial access operations. Winter Vivern used batch scripts that called PowerShell commands as part of initial access and installation operations.

T1059.001
PowerShell
GroupTurla

Turla has used PowerShell to execute commands/scripts, in some cases via a custom executable or code from Empire's PSInject. Turla has also used PowerShell scripts to load and execute malware in memory.

T1059.001
PowerShell
GroupStorm-0501

Storm-0501 has leveraged PowerShell to execute commands and scripts.

T1059.001
PowerShell
GroupPoseidon Group

The Poseidon Group's Information Gathering Tool (IGT) includes PowerShell components.

T1059.001
PowerShell
GroupTA505

TA505 has used PowerShell to download and execute malware and reconnaissance scripts.

T1059.001
PowerShell
GroupDarkVishnya

DarkVishnya used PowerShell to create shellcode loaders.

T1059.001
PowerShell
GroupRedCurl

RedCurl has used PowerShell to execute commands and to download malware.

T1059.001
PowerShell
GroupStealth Falcon

Stealth Falcon malware uses PowerShell commands to perform various functions, including gathering system information via WMI and executing commands from its C2 server.

T1059.001
PowerShell
GroupAPT29

APT29 has used encoded PowerShell scripts uploaded to CozyCar installations to download and install SeaDuke.

T1059.001
PowerShell
GroupCinnamon Tempest

Cinnamon Tempest has used PowerShell to communicate with C2, download files, and execute reconnaissance commands.

T1059.001
PowerShell
GroupChimera

Chimera has used PowerShell scripts to execute malicious payloads and the DSInternals PowerShell module to make use of Active Directory features.

T1059.001
PowerShell
GroupMedusa Group

Medusa Group has leveraged PowerShell for execution and defense evasion. Medusa Group has also utilized PowerShell to execute a bitsadmin transfer from file hosting site.

T1059.001
PowerShell
GroupBRONZE BUTLER

BRONZE BUTLER has used PowerShell for execution.

T1059.001
PowerShell
GroupDeep Panda

Deep Panda has used PowerShell scripts to download and execute programs in memory, without writing to disk.

T1059.001
PowerShell
GroupEmber Bear

Ember Bear has used PowerShell commands to gather information from compromised systems, such as email servers.

T1059.001
PowerShell
GroupLazyScripter

LazyScripter has used PowerShell scripts to execute malicious code.

T1059.001
PowerShell
GroupToddyCat

ToddyCat has used Powershell scripts to perform post exploit collection.

T1059.001
PowerShell
GroupAPT28

APT28 downloads and executes PowerShell scripts and performs PowerShell commands.

T1059.001
PowerShell
GroupAPT42

APT42 has downloaded and executed PowerShell payloads.

T1059.001
PowerShell
GroupAPT5

APT5 has used PowerShell to accomplish tasks within targeted environments.

T1059.001
PowerShell
GroupFox Kitten

Fox Kitten has used PowerShell scripts to access credential data.

T1059.001
PowerShell
GroupAPT-C-36

APT-C-36 has used PowerShell in malware execution including as part of fileless attack chains to download additional payloads.

T1059.001
PowerShell
GroupTonto Team

Tonto Team has used PowerShell to download additional payloads.

T1059.001
PowerShell
GroupGOLD SOUTHFIELD

GOLD SOUTHFIELD has staged and executed PowerShell scripts on compromised hosts.

T1059.001
PowerShell
GroupLazarus Group

Lazarus Group has used PowerShell to execute commands and malicious code.

T1059.001
PowerShell
GroupEarth Lusca

Earth Lusca has used PowerShell to execute commands.

T1059.001
PowerShell
GroupSilence

Silence has used PowerShell to download and execute payloads.

T1059.001
PowerShell
GroupThrip

Thrip leveraged PowerShell to run commands to download payloads, traverse the compromised networks, and carry out reconnaissance.

T1059.001
PowerShell
GroupCobalt Group

Cobalt Group has used powershell.exe to download and execute scripts.

T1059.001
PowerShell
GroupCopyKittens

CopyKittens has used PowerShell Empire.

T1059.001
PowerShell
GroupWizard Spider

Wizard Spider has used macros to execute PowerShell scripts to download malware on victim's machines. It has also used PowerShell to execute commands and move laterally through a victim network.

T1059.001
PowerShell
GroupMolerats

Molerats used PowerShell implants on target machines.

T1059.001
PowerShell
GroupInception

Inception has used PowerShell to execute malicious commands and payloads.

T1059.001
PowerShell
GroupVOID MANTICORE

VOID MANTICORE has utilized PowerShell to execute malware in victim environments.

T1059.001
PowerShell
GroupPlay

Play has used Base64-encoded PowerShell scripts to disable Microsoft Defender.

T1059.001
PowerShell
GroupHEXANE

HEXANE has used PowerShell-based tools and scripts for discovery and collection on compromised hosts.

T1059.001
PowerShell
GroupDaggerfly

Daggerfly used PowerShell to download and execute remote-hosted files on victim systems.

T1059.001
PowerShell
GroupWIRTE

WIRTE has used PowerShell for script execution.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.