Real-world descriptions of how a group, tool or campaign used a technique.
1146 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1056.001 Keylogging |
Campaign2015 Ukraine Electric Power Attack | During the 2015 Ukraine Electric Power Attack, Sandworm Team gathered account credentials via a BlackEnergy keylogger plugin. |
| T1056.001 Keylogging |
CampaignCutting Edge | During Cutting Edge, threat actors modified a JavaScript file on the Web SSL VPN component of Ivanti Connect Secure devices to keylog credentials. |
| T1056.001 Keylogging |
CampaignOperation Wocao | During Operation Wocao, threat actors obtained the password for the victim's password manager via a custom keylogger. |
| T1056.003 Web Portal Capture |
CampaignTriton Safety Instrumented System Attack | In the Triton Safety Instrumented System Attack, TEMP.Veles captured credentials as they were being changed by redirecting text-based login codes to websites they controlled. |
| T1056.003 Web Portal Capture |
CampaignCutting Edge | During Cutting Edge, threat actors modified the JavaScript loaded by the Ivanti Connect Secure login page to capture credentials entered. |
| T1057 Process Discovery |
CampaignKV Botnet Activity | Scripts associated with KV Botnet Activity initial deployment can identify processes related to security tools and other botnet families for follow-on disabling during installation. |
| T1057 Process Discovery |
CampaignFrankenstein | During Frankenstein, the threat actors used Empire to obtain a list of all running processes. |
| T1057 Process Discovery |
CampaignRedPenguin | During RedPenguin, UNC3886 used malware capable of reading the PID for the Junos OS snmpd daemon. |
| T1057 Process Discovery |
CampaignOperation Honeybee | During Operation Honeybee, the threat actors obtained a list of running processes on a victim machine using `cmd /c tasklist > %temp%\temp.ini`. |
| T1057 Process Discovery |
CampaignC0015 | During C0015, the threat actors used the `tasklist /s` command as well as `taskmanager` to obtain a list of running processes. |
| T1057 Process Discovery |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used multiple command-line utilities to enumerate running processes. |
| T1057 Process Discovery |
CampaignFunnyDream | During FunnyDream, the threat actors used Tasklist on targeted systems. |
| T1057 Process Discovery |
CampaignOperation CuckooBees | During Operation CuckooBees, the threat actors used the `tasklist` command as part of their advanced reconnaissance. |
| T1057 Process Discovery |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries enumerated current running processes using `tasklist`. |
| T1057 Process Discovery |
CampaignOperation Wocao | During Operation Wocao, the threat actors used `tasklist` to collect a list of running processes on an infected system. |
| T1059 Command and Scripting Interpreter |
CampaignOperation Spalax | For Operation Spalax, the threat actors used Nullsoft Scriptable Install System (NSIS) scripts to install malware. |
| T1059 Command and Scripting Interpreter |
CampaignCutting Edge | During Cutting Edge, threat actors used Perl scripts to enable the deployment of the THINSPOOL shell script dropper and for enumerating host data. |
| T1059 Command and Scripting Interpreter |
CampaignArcaneDoor | ArcaneDoor included the adversary executing command line interface (CLI) commands. |
| T1059 Command and Scripting Interpreter |
CampaignFLORAHOX Activity | FLORAHOX Activity has executed PHP and Shell scripts to identify and infect subsequent routers for the ORB network. |
| T1059.001 PowerShell |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group used PowerShell commands to explore the environment of compromised victims. |
| T1059.001 PowerShell |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors used PowerShell to execute attacker-controlled encoded commands. |
| T1059.001 PowerShell |
CampaignFrankenstein | During Frankenstein, the threat actors used PowerShell to run a series of Base64-encoded commands that acted as a stager and enumerated hosts. |
| T1059.001 PowerShell |
CampaignRedDelta Modified PlugX Infection Chain Operations | Mustang Panda used LNK files to execute PowerShell commands leading to eventual PlugX installation during RedDelta Modified PlugX Infection Chain Operations. |
| T1059.001 PowerShell |
CampaignTriton Safety Instrumented System Attack | In the Triton Safety Instrumented System Attack, TEMP.Veles used a publicly available PowerShell-based tool, WMImplant. |
| T1059.001 PowerShell |
CampaignC0018 | During C0018, the threat actors used encoded PowerShell scripts for execution. |
| T1059.001 PowerShell |
CampaignC0021 | During C0021, the threat actors used obfuscated PowerShell to extract an encoded payload from within an .LNK file. |
| T1059.001 PowerShell |
CampaignJuicy Mix | During Juicy Mix, OilRig used a PowerShell script to steal credentials. |
| T1059.001 PowerShell |
CampaignHomeLand Justice | During HomeLand Justice, threat actors used PowerShell cmdlets New-MailboxSearch and Get-Recipient for discovery. |
| T1059.001 PowerShell |
CampaignC0032 | During the C0032 campaign, TEMP.Veles used PowerShell to perform timestomping. |
| T1059.001 PowerShell |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used PowerShell to create new tasks on remote machines, identify configuration settings, exfiltrate data, and execute other commands. |
| T1059.001 PowerShell |
CampaignPikabot Distribution February 2024 | Pikabot Distribution February 2024 passed execution from obfuscated JavaScript files to PowerShell scripts to download and install Pikabot. |
| T1059.001 PowerShell |
CampaignOperation AkaiRyū | During Operation AkaiRyū, MirrorFace used PowerShell in execution chains to drop additional files such as embedded CAB files. |
| T1059.001 PowerShell |
CampaignAPT28 Nearest Neighbor Campaign | During APT28 Nearest Neighbor Campaign, APT28 used PowerShell cmdlet |
| T1059.001 PowerShell |
Campaign2016 Ukraine Electric Power Attack | During the 2016 Ukraine Electric Power Attack, Sandworm Team used PowerShell scripts to run a credential harvesting tool in memory to evade defenses. |
| T1059.001 PowerShell |
CampaignOperation Wocao | During Operation Wocao, threat actors used PowerShell on compromised systems. |
| T1059.001 PowerShell |
Campaign2022 Ukraine Electric Power Attack | During the 2022 Ukraine Electric Power Attack, Sandworm Team utilized a PowerShell utility called TANKTRAP to spread and launch a wiper using Windows Group Policy. |
| T1059.003 Windows Command Shell |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group launched malicious DLL files, created new folders, and renamed folders with the use of the Windows command shell. |
| T1059.003 Windows Command Shell |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors utilized `cmd.exe` and batch scripts within the victim environment. |
| T1059.003 Windows Command Shell |
CampaignFrankenstein | During Frankenstein, the threat actors ran a command script to set up persistence as a scheduled task named "WinUpdate", as well as other encoded commands from the command-line |
| T1059.003 Windows Command Shell |
CampaignOperation Honeybee | During Operation Honeybee, various implants used batch scripting and `cmd.exe` for execution. |
| T1059.003 Windows Command Shell |
CampaignWater Curupira Pikabot Distribution | Water Curupira Pikabot Distribution installation via JavaScript will launch follow-on commands via cmd.exe. |
| T1059.003 Windows Command Shell |
CampaignOperation Digital Eye | During Operation Digital Eye, threat actors used `cmd.exe` as a default method of execution for a custom version of Mimikatz named bK2o.exe. |
| T1059.003 Windows Command Shell |
CampaignC0015 | During C0015, the threat actors used `cmd.exe` to execute commands and run malicious binaries. |
| T1059.003 Windows Command Shell |
CampaignHomeLand Justice | During HomeLand Justice, threat actors used Windows batch files for persistence and execution. |
| T1059.003 Windows Command Shell |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used `cmd.exe` to execute commands on remote machines. |
| T1059.003 Windows Command Shell |
CampaignOperation AkaiRyū | During Operation AkaiRyū, MirrorFace used `cmd.exe` to run PowerShell commands to drop additional files on the compromised host. |
| T1059.003 Windows Command Shell |
CampaignFunnyDream | During FunnyDream, the threat actors used `cmd.exe` to execute the wmiexec.vbs script. |
| T1059.003 Windows Command Shell |
CampaignOperation CuckooBees | During Operation CuckooBees, the threat actors used batch scripts to perform reconnaissance. |
| T1059.003 Windows Command Shell |
CampaignAPT28 Nearest Neighbor Campaign | During APT28 Nearest Neighbor Campaign, APT28 used |
| T1059.003 Windows Command Shell |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries leveraged PsExec to run `cmd.exe` commands on multiple victim machines. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.