Real-world descriptions of how a group, tool or campaign used a technique.
295 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1059.003 Windows Command Shell |
MalwareFlagpro | Flagpro can use `cmd.exe` to execute commands received from C2. |
| T1059.003 Windows Command Shell |
MalwareHi-Zor | Hi-Zor has the ability to create a reverse shell. |
| T1059.003 Windows Command Shell |
MalwareChina Chopper | China Chopper's server component is capable of opening a command terminal. |
| T1059.003 Windows Command Shell |
MalwareCALENDAR | CALENDAR has a command to run cmd.exe to execute commands. |
| T1059.003 Windows Command Shell |
MalwareGoldMax | GoldMax can spawn a command shell, and execute native commands. |
| T1059.003 Windows Command Shell |
MalwareKeyBoy | KeyBoy can launch interactive shells for communicating with the victim machine. |
| T1059.003 Windows Command Shell |
MalwareAnchor | Anchor has used cmd.exe to run its self deletion routine. |
| T1059.003 Windows Command Shell |
MalwarePteranodon | Pteranodon can use `cmd.exe` for execution on victim systems. |
| T1059.003 Windows Command Shell |
MalwareDarkTortilla | DarkTortilla can use `cmd.exe` to add registry keys for persistence. |
| T1059.003 Windows Command Shell |
MalwareRunningRAT | RunningRAT uses a batch file to kill a security program task and then attempts to remove itself. |
| T1059.003 Windows Command Shell |
MalwareBabuk | Babuk has the ability to use the command line to control execution on compromised hosts. |
| T1059.003 Windows Command Shell |
MalwareDarkWatchman | DarkWatchman can use `cmd.exe` to execute commands. |
| T1059.003 Windows Command Shell |
MalwareBlackMould | BlackMould can run cmd.exe with parameters. |
| T1059.003 Windows Command Shell |
MalwarePlugX | PlugX allows actors to spawn a reverse shell on a victim. |
| T1059.003 Windows Command Shell |
MalwareBisonal | Bisonal has launched cmd.exe and used the ShellExecuteW() API function to execute commands on the system. |
| T1059.003 Windows Command Shell |
MalwareMultiLayer Wiper | MultiLayer Wiper uses a batch script launched via a scheduled task to delete Windows Event Logs. |
| T1059.003 Windows Command Shell |
MalwareS-Type | S-Type has provided the ability to execute shell commands on a compromised host. |
| T1059.003 Windows Command Shell |
MalwareSeaDuke | SeaDuke is capable of executing commands. |
| T1059.003 Windows Command Shell |
MalwareLightNeuron | LightNeuron is capable of executing commands via cmd.exe. |
| T1059.003 Windows Command Shell |
MalwarePeppy | Peppy has the ability to execute shell commands. |
| T1059.003 Windows Command Shell |
MalwareCuba | Cuba has used |
| T1059.003 Windows Command Shell |
MalwareClambling | Clambling can use cmd.exe for command execution. |
| T1059.003 Windows Command Shell |
MalwareAkira | Akira executes from the Windows command line and can take various arguments for execution. |
| T1059.003 Windows Command Shell |
MalwareDarkGate | DarkGate uses a malicious Windows Batch script to run the Windows |
| T1059.003 Windows Command Shell |
MalwareCarbanak | Carbanak has a command to create a reverse shell. |
| T1059.003 Windows Command Shell |
MalwareXTunnel | XTunnel has been used to execute remote commands. |
| T1059.003 Windows Command Shell |
MalwareHOMEFRY | HOMEFRY uses a command-line interface. |
| T1059.003 Windows Command Shell |
MalwareCaterpillar WebShell | Caterpillar WebShell can run commands on the compromised asset with CMD functions. |
| T1059.003 Windows Command Shell |
MalwareNetwalker | Operators deploying Netwalker have used batch scripts to retrieve the Netwalker payload. |
| T1059.003 Windows Command Shell |
MalwareUSBferry | USBferry can execute various Windows commands. |
| T1059.003 Windows Command Shell |
MalwareTSCookie | TSCookie has the ability to execute shell commands on the infected host. |
| T1059.003 Windows Command Shell |
MalwareLatrodectus | The Latrodectus command handler can use `cmdexe` to run multiple discovery commands. |
| T1059.003 Windows Command Shell |
MalwareSaint Bot | Saint Bot has used `cmd.exe` and `.bat` scripts for execution. |
| T1059.003 Windows Command Shell |
MalwareChaes | |
| T1059.003 Windows Command Shell |
MalwareCharmPower | The C# implementation of the CharmPower command execution module can use |
| T1059.003 Windows Command Shell |
MalwareMuddyViper | MuddyViper has used cmd.exe to launch a reverse shell. |
| T1059.003 Windows Command Shell |
MalwareTYPEFRAME | TYPEFRAME can uninstall malware components using a batch script. TYPEFRAME can execute commands using a shell. |
| T1059.003 Windows Command Shell |
MalwareKOMPROGO | KOMPROGO is capable of creating a reverse shell. |
| T1059.003 Windows Command Shell |
MalwareQUADAGENT | QUADAGENT uses cmd.exe to execute scripts and commands on the victim’s machine. |
| T1059.003 Windows Command Shell |
MalwareTAINTEDSCRIBE | TAINTEDSCRIBE can enable Windows CLI access and execute files. |
| T1059.003 Windows Command Shell |
MalwareUroburos | Uroburos has the ability to use the command line for execution on the targeted system. |
| T1059.003 Windows Command Shell |
MalwareMetamorfo | Metamorfo has used |
| T1059.003 Windows Command Shell |
MalwareEmbargo | Embargo has utilized a BAT script to disable security solutions. |
| T1059.003 Windows Command Shell |
MalwareTrojan.Karagany | Trojan.Karagany can perform reconnaissance commands on a victim machine via a cmd.exe process. |
| T1059.003 Windows Command Shell |
MalwareBandook | Bandook is capable of spawning a Windows command shell. |
| T1059.003 Windows Command Shell |
MalwareMagicRAT | MagicRAT allows for the execution of arbitrary commands on the victim system. |
| T1059.003 Windows Command Shell |
MalwareKONNI | KONNI has used cmd.exe to execute arbitrary commands on the infected host across different stages of the infection chain. |
| T1059.003 Windows Command Shell |
MalwareDnsSystem | DnsSystem can use `cmd.exe` for execution. |
| T1059.003 Windows Command Shell |
MalwareMoleNet | MoleNet can execute commands via the command line utility. |
| T1059.003 Windows Command Shell |
MalwareJHUHUGIT | JHUHUGIT uses a .bat file to execute a .dll. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.