ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1059.001×

131 examples

TechniqueUsed byProcedure example
T1059.001
PowerShell
MalwarePowerStallion

PowerStallion uses PowerShell loops to iteratively check for available commands in its OneDrive C2 server.

T1059.001
PowerShell
MalwareShai-Hulud

Shai-Hulud has utilized PowerShell `Invoke-WebRequest` to download and install the malicious payload.

T1059.001
PowerShell
MalwareKOCTOPUS

KOCTOPUS has used PowerShell commands to download additional files.

T1059.001
PowerShell
MalwareLunarWeb

LunarWeb has the ability to run shell commands via PowerShell.

T1059.001
PowerShell
MalwareQilin

Qilin has been deployed on VMware vCenter and ESXi servers via custom PowerShell script. Qilin has also used PowerShell for discovery in vCenter and Active Directory environments.

T1059.001
PowerShell
MalwareLazyWiper

LazyWiper has used PowerShell to enable data destruction on targeted systems.

T1059.001
PowerShell
MalwareDownPaper

DownPaper uses PowerShell for execution.

T1059.001
PowerShell
MalwareSocksbot

Socksbot can write and execute PowerShell scripts.

T1059.001
PowerShell
MalwarePOWERSTATS

POWERSTATS uses PowerShell for obfuscation and execution.

T1059.001
PowerShell
MalwarePOWERTON

POWERTON is written in PowerShell.

T1059.001
PowerShell
MalwareQakBot

QakBot can use PowerShell to download and execute payloads.

T1059.001
PowerShell
MalwareHancitor

Hancitor has used PowerShell to execute commands.

T1059.001
PowerShell
MalwareHelminth

One version of Helminth uses a PowerShell script.

T1059.001
PowerShell
MalwareDenis

Denis has a version written in PowerShell.

T1059.001
PowerShell
MalwareAutoIt backdoor

AutoIt backdoor downloads a PowerShell script that decodes to a typical shellcode loader.

T1059.001
PowerShell
MalwareJSS Loader

JSS Loader has the ability to download and execute PowerShell scripts.

T1059.001
PowerShell
MalwareLizar

Lizar has used PowerShell scripts.

T1059.001
PowerShell
MalwareWarzoneRAT

WarzoneRAT can use PowerShell to download files and execute commands.

T1059.001
PowerShell
ToolCovenant

Covenant can create PowerShell-based launchers for Grunt installation.

T1059.001
PowerShell
ToolBloodHound

BloodHound can use PowerShell to pull Active Directory information from the target environment.

T1059.001
PowerShell
ToolSliver

Sliver has built-in functionality to launch a Powershell command prompt.

T1059.001
PowerShell
ToolSILENTTRINITY

SILENTTRINITY can use PowerShell to execute commands.

T1059.001
PowerShell
ToolPowerSploit

PowerSploit modules are written in and executed via PowerShell.

T1059.001
PowerShell
ToolAADInternals

AADInternals is written and executed via PowerShell.

T1059.001
PowerShell
ToolEmpire

Empire leverages PowerShell for the majority of its client-side agent tasks. Empire also contains the ability to conduct PowerShell remoting with the Invoke-PSRemoting module.

T1059.001
PowerShell
ToolConnectWise

ConnectWise can be used to execute PowerShell commands on target machines.

T1059.001
PowerShell
ToolDonut

Donut can generate shellcode outputs that execute via PowerShell.

T1059.001
PowerShell
ToolCrackMapExec

CrackMapExec can execute PowerShell commands via WMI.

T1059.001
PowerShell
ToolKoadic

Koadic has used PowerShell to establish persistence.

T1059.001
PowerShell
ToolPupy

Pupy has a module for loading and executing PowerShell scripts.

T1059.001
PowerShell
MalwareZeroCleare

ZeroCleare can use a malicious PowerShell script to bypass Windows controls.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.