ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

1146 examples

TechniqueUsed byProcedure example
T1056.001
Keylogging
Campaign2015 Ukraine Electric Power Attack

During the 2015 Ukraine Electric Power Attack, Sandworm Team gathered account credentials via a BlackEnergy keylogger plugin.

T1056.001
Keylogging
CampaignCutting Edge

During Cutting Edge, threat actors modified a JavaScript file on the Web SSL VPN component of Ivanti Connect Secure devices to keylog credentials.

T1056.001
Keylogging
CampaignOperation Wocao

During Operation Wocao, threat actors obtained the password for the victim's password manager via a custom keylogger.

T1056.003
Web Portal Capture
CampaignTriton Safety Instrumented System Attack

In the Triton Safety Instrumented System Attack, TEMP.Veles captured credentials as they were being changed by redirecting text-based login codes to websites they controlled.

T1056.003
Web Portal Capture
CampaignCutting Edge

During Cutting Edge, threat actors modified the JavaScript loaded by the Ivanti Connect Secure login page to capture credentials entered.

T1057
Process Discovery
CampaignKV Botnet Activity

Scripts associated with KV Botnet Activity initial deployment can identify processes related to security tools and other botnet families for follow-on disabling during installation.

T1057
Process Discovery
CampaignFrankenstein

During Frankenstein, the threat actors used Empire to obtain a list of all running processes.

T1057
Process Discovery
CampaignRedPenguin

During RedPenguin, UNC3886 used malware capable of reading the PID for the Junos OS snmpd daemon.

T1057
Process Discovery
CampaignOperation Honeybee

During Operation Honeybee, the threat actors obtained a list of running processes on a victim machine using `cmd /c tasklist > %temp%\temp.ini`.

T1057
Process Discovery
CampaignC0015

During C0015, the threat actors used the `tasklist /s` command as well as `taskmanager` to obtain a list of running processes.

T1057
Process Discovery
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used multiple command-line utilities to enumerate running processes.

T1057
Process Discovery
CampaignFunnyDream

During FunnyDream, the threat actors used Tasklist on targeted systems.

T1057
Process Discovery
CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors used the `tasklist` command as part of their advanced reconnaissance.

T1057
Process Discovery
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries enumerated current running processes using `tasklist`.

T1057
Process Discovery
CampaignOperation Wocao

During Operation Wocao, the threat actors used `tasklist` to collect a list of running processes on an infected system.

T1059
Command and Scripting Interpreter
CampaignOperation Spalax

For Operation Spalax, the threat actors used Nullsoft Scriptable Install System (NSIS) scripts to install malware.

T1059
Command and Scripting Interpreter
CampaignCutting Edge

During Cutting Edge, threat actors used Perl scripts to enable the deployment of the THINSPOOL shell script dropper and for enumerating host data.

T1059
Command and Scripting Interpreter
CampaignArcaneDoor

ArcaneDoor included the adversary executing command line interface (CLI) commands.

T1059
Command and Scripting Interpreter
CampaignFLORAHOX Activity

FLORAHOX Activity has executed PHP and Shell scripts to identify and infect subsequent routers for the ORB network.

T1059.001
PowerShell
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group used PowerShell commands to explore the environment of compromised victims.

T1059.001
PowerShell
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors used PowerShell to execute attacker-controlled encoded commands.

T1059.001
PowerShell
CampaignFrankenstein

During Frankenstein, the threat actors used PowerShell to run a series of Base64-encoded commands that acted as a stager and enumerated hosts.

T1059.001
PowerShell
CampaignRedDelta Modified PlugX Infection Chain Operations

Mustang Panda used LNK files to execute PowerShell commands leading to eventual PlugX installation during RedDelta Modified PlugX Infection Chain Operations.

T1059.001
PowerShell
CampaignTriton Safety Instrumented System Attack

In the Triton Safety Instrumented System Attack, TEMP.Veles used a publicly available PowerShell-based tool, WMImplant.

T1059.001
PowerShell
CampaignC0018

During C0018, the threat actors used encoded PowerShell scripts for execution.

T1059.001
PowerShell
CampaignC0021

During C0021, the threat actors used obfuscated PowerShell to extract an encoded payload from within an .LNK file.

T1059.001
PowerShell
CampaignJuicy Mix

During Juicy Mix, OilRig used a PowerShell script to steal credentials.

T1059.001
PowerShell
CampaignHomeLand Justice

During HomeLand Justice, threat actors used PowerShell cmdlets New-MailboxSearch and Get-Recipient for discovery.

T1059.001
PowerShell
CampaignC0032

During the C0032 campaign, TEMP.Veles used PowerShell to perform timestomping.

T1059.001
PowerShell
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used PowerShell to create new tasks on remote machines, identify configuration settings, exfiltrate data, and execute other commands.

T1059.001
PowerShell
CampaignPikabot Distribution February 2024

Pikabot Distribution February 2024 passed execution from obfuscated JavaScript files to PowerShell scripts to download and install Pikabot.

T1059.001
PowerShell
CampaignOperation AkaiRyū

During Operation AkaiRyū, MirrorFace used PowerShell in execution chains to drop additional files such as embedded CAB files.

T1059.001
PowerShell
CampaignAPT28 Nearest Neighbor Campaign

During APT28 Nearest Neighbor Campaign, APT28 used PowerShell cmdlet Get-ChildItem to access credentials, among other PowerShell functions deployed.

T1059.001
PowerShell
Campaign2016 Ukraine Electric Power Attack

During the 2016 Ukraine Electric Power Attack, Sandworm Team used PowerShell scripts to run a credential harvesting tool in memory to evade defenses.

T1059.001
PowerShell
CampaignOperation Wocao

During Operation Wocao, threat actors used PowerShell on compromised systems.

T1059.001
PowerShell
Campaign2022 Ukraine Electric Power Attack

During the 2022 Ukraine Electric Power Attack, Sandworm Team utilized a PowerShell utility called TANKTRAP to spread and launch a wiper using Windows Group Policy.

T1059.003
Windows Command Shell
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group launched malicious DLL files, created new folders, and renamed folders with the use of the Windows command shell.

T1059.003
Windows Command Shell
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors utilized `cmd.exe` and batch scripts within the victim environment.

T1059.003
Windows Command Shell
CampaignFrankenstein

During Frankenstein, the threat actors ran a command script to set up persistence as a scheduled task named "WinUpdate", as well as other encoded commands from the command-line

T1059.003
Windows Command Shell
CampaignOperation Honeybee

During Operation Honeybee, various implants used batch scripting and `cmd.exe` for execution.

T1059.003
Windows Command Shell
CampaignWater Curupira Pikabot Distribution

Water Curupira Pikabot Distribution installation via JavaScript will launch follow-on commands via cmd.exe.

T1059.003
Windows Command Shell
CampaignOperation Digital Eye

During Operation Digital Eye, threat actors used `cmd.exe` as a default method of execution for a custom version of Mimikatz named bK2o.exe.

T1059.003
Windows Command Shell
CampaignC0015

During C0015, the threat actors used `cmd.exe` to execute commands and run malicious binaries.

T1059.003
Windows Command Shell
CampaignHomeLand Justice

During HomeLand Justice, threat actors used Windows batch files for persistence and execution.

T1059.003
Windows Command Shell
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used `cmd.exe` to execute commands on remote machines.

T1059.003
Windows Command Shell
CampaignOperation AkaiRyū

During Operation AkaiRyū, MirrorFace used `cmd.exe` to run PowerShell commands to drop additional files on the compromised host.

T1059.003
Windows Command Shell
CampaignFunnyDream

During FunnyDream, the threat actors used `cmd.exe` to execute the wmiexec.vbs script.

T1059.003
Windows Command Shell
CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors used batch scripts to perform reconnaissance.

T1059.003
Windows Command Shell
CampaignAPT28 Nearest Neighbor Campaign

During APT28 Nearest Neighbor Campaign, APT28 used cmd.exe for execution.

T1059.003
Windows Command Shell
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries leveraged PsExec to run `cmd.exe` commands on multiple victim machines.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.