Real-world descriptions of how a group, tool or campaign used a technique.
131 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1059.001 PowerShell |
MalwarePowerStallion | PowerStallion uses PowerShell loops to iteratively check for available commands in its OneDrive C2 server. |
| T1059.001 PowerShell |
MalwareShai-Hulud | Shai-Hulud has utilized PowerShell `Invoke-WebRequest` to download and install the malicious payload. |
| T1059.001 PowerShell |
MalwareKOCTOPUS | KOCTOPUS has used PowerShell commands to download additional files. |
| T1059.001 PowerShell |
MalwareLunarWeb | LunarWeb has the ability to run shell commands via PowerShell. |
| T1059.001 PowerShell |
MalwareQilin | Qilin has been deployed on VMware vCenter and ESXi servers via custom PowerShell script. Qilin has also used PowerShell for discovery in vCenter and Active Directory environments. |
| T1059.001 PowerShell |
MalwareLazyWiper | LazyWiper has used PowerShell to enable data destruction on targeted systems. |
| T1059.001 PowerShell |
MalwareDownPaper | DownPaper uses PowerShell for execution. |
| T1059.001 PowerShell |
MalwareSocksbot | Socksbot can write and execute PowerShell scripts. |
| T1059.001 PowerShell |
MalwarePOWERSTATS | POWERSTATS uses PowerShell for obfuscation and execution. |
| T1059.001 PowerShell |
MalwarePOWERTON | POWERTON is written in PowerShell. |
| T1059.001 PowerShell |
MalwareQakBot | QakBot can use PowerShell to download and execute payloads. |
| T1059.001 PowerShell |
MalwareHancitor | Hancitor has used PowerShell to execute commands. |
| T1059.001 PowerShell |
MalwareHelminth | One version of Helminth uses a PowerShell script. |
| T1059.001 PowerShell |
MalwareDenis | Denis has a version written in PowerShell. |
| T1059.001 PowerShell |
MalwareAutoIt backdoor | AutoIt backdoor downloads a PowerShell script that decodes to a typical shellcode loader. |
| T1059.001 PowerShell |
MalwareJSS Loader | JSS Loader has the ability to download and execute PowerShell scripts. |
| T1059.001 PowerShell |
MalwareLizar | Lizar has used PowerShell scripts. |
| T1059.001 PowerShell |
MalwareWarzoneRAT | WarzoneRAT can use PowerShell to download files and execute commands. |
| T1059.001 PowerShell |
ToolCovenant | Covenant can create PowerShell-based launchers for Grunt installation. |
| T1059.001 PowerShell |
ToolBloodHound | BloodHound can use PowerShell to pull Active Directory information from the target environment. |
| T1059.001 PowerShell |
ToolSliver | Sliver has built-in functionality to launch a Powershell command prompt. |
| T1059.001 PowerShell |
ToolSILENTTRINITY | SILENTTRINITY can use PowerShell to execute commands. |
| T1059.001 PowerShell |
ToolPowerSploit | PowerSploit modules are written in and executed via PowerShell. |
| T1059.001 PowerShell |
ToolAADInternals | AADInternals is written and executed via PowerShell. |
| T1059.001 PowerShell |
ToolEmpire | Empire leverages PowerShell for the majority of its client-side agent tasks. Empire also contains the ability to conduct PowerShell remoting with the |
| T1059.001 PowerShell |
ToolConnectWise | ConnectWise can be used to execute PowerShell commands on target machines. |
| T1059.001 PowerShell |
ToolDonut | Donut can generate shellcode outputs that execute via PowerShell. |
| T1059.001 PowerShell |
ToolCrackMapExec | CrackMapExec can execute PowerShell commands via WMI. |
| T1059.001 PowerShell |
ToolKoadic | Koadic has used PowerShell to establish persistence. |
| T1059.001 PowerShell |
ToolPupy | Pupy has a module for loading and executing PowerShell scripts. |
| T1059.001 PowerShell |
MalwareZeroCleare | ZeroCleare can use a malicious PowerShell script to bypass Windows controls. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.