ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1059.003×

295 examples

TechniqueUsed byProcedure example
T1059.003
Windows Command Shell
MalwareKevin

Kevin can use a renamed image of `cmd.exe` for execution.

T1059.003
Windows Command Shell
Malwarehttpclient

httpclient opens cmd.exe on the victim.

T1059.003
Windows Command Shell
MalwareECCENTRICBANDWAGON

ECCENTRICBANDWAGON can use cmd to execute commands on a victim’s machine.

T1059.003
Windows Command Shell
MalwareBADNEWS

BADNEWS is capable of executing commands via cmd.exe.

T1059.003
Windows Command Shell
MalwareLinfo

Linfo creates a backdoor through which remote attackers can start a remote shell.

T1059.003
Windows Command Shell
MalwareGoopy

Goopy has the ability to use cmd.exe to execute commands passed from an Outlook C2 channel.

T1059.003
Windows Command Shell
MalwareRemexi

Remexi silently executes received commands with cmd.exe.

T1059.003
Windows Command Shell
MalwareAstaroth

Astaroth spawns a CMD process to execute commands.

T1059.003
Windows Command Shell
MalwareQakBot

QakBot can use cmd.exe to launch itself and to execute multiple C2 commands.

T1059.003
Windows Command Shell
MalwareSYSCON

SYSCON has the ability to execute commands through cmd on a compromised host.

T1059.003
Windows Command Shell
MalwareGelsemium

Gelsemium can use a batch script to delete itself.

T1059.003
Windows Command Shell
MalwarejRAT

jRAT has command line access.

T1059.003
Windows Command Shell
MalwareHelminth

Helminth can provide a remote shell. One version of Helminth uses batch scripting.

T1059.003
Windows Command Shell
MalwareBBK

BBK has the ability to use cmd to run a Portable Executable (PE) on the compromised host.

T1059.003
Windows Command Shell
MalwareDenis

Denis can launch a remote shell to execute arbitrary commands on the victim’s machine.

T1059.003
Windows Command Shell
MalwareComnie

Comnie executes BAT scripts.

T1059.003
Windows Command Shell
MalwarePHOREAL

PHOREAL is capable of creating reverse shell.

T1059.003
Windows Command Shell
MalwareLizar

Lizar has a command to open the command-line on the infected system.

T1059.003
Windows Command Shell
MalwareDtrack

Dtrack has used cmd.exe to add a persistent service.

T1059.003
Windows Command Shell
MalwareH1N1

H1N1 kills and disables services by using cmd.exe.

T1059.003
Windows Command Shell
MalwareSeth-Locker

Seth-Locker can execute commands via the command line shell.

T1059.003
Windows Command Shell
MalwareLoudMiner

LoudMiner used a batch script to run the Linux virtual machine as a service.

T1059.003
Windows Command Shell
MalwareBACKSPACE

Adversaries can direct BACKSPACE to execute from the command line on infected hosts, or have BACKSPACE create a reverse shell.

T1059.003
Windows Command Shell
MalwareUPPERCUT

UPPERCUT uses cmd.exe to execute commands on the victim’s machine.

T1059.003
Windows Command Shell
MalwareADVSTORESHELL

ADVSTORESHELL can create a remote shell and run a given command.

T1059.003
Windows Command Shell
MalwareStrifeWater

StrifeWater can execute shell commands using `cmd.exe`.

T1059.003
Windows Command Shell
MalwareMivast

Mivast has the capability to open a remote shell and run basic commands.

T1059.003
Windows Command Shell
MalwareHiddenWasp

HiddenWasp uses a script to automate tasks on the victim's machine and to assist in execution.

T1059.003
Windows Command Shell
MalwareWarzoneRAT

WarzoneRAT can use `cmd.exe` to execute malicious code.

T1059.003
Windows Command Shell
MalwareSLOTHFULMEDIA

SLOTHFULMEDIA can open a command line to execute commands.

T1059.003
Windows Command Shell
MalwareSmall Sieve

Small Sieve can use `cmd.exe` to execute commands on a victim's system.

T1059.003
Windows Command Shell
MalwareHermeticWizard

HermeticWizard can use `cmd.exe` for execution on compromised hosts.

T1059.003
Windows Command Shell
ToolCovenant

Covenant provides access to a Command Shell in Windows environments for follow-on command execution and tasking.

T1059.003
Windows Command Shell
ToolDiskpart

Diskpart can execute a disk partition script file, which attempts to mount a virtual hard disk. Diskpart can also assign and mount virtual disks.

T1059.003
Windows Command Shell
ToolSILENTTRINITY

SILENTTRINITY can use `cmd.exe` to enable lateral movement using DCOM.

T1059.003
Windows Command Shell
ToolEmpire

Empire has modules for executing scripts.

T1059.003
Windows Command Shell
ToolPcShare

PcShare can execute `cmd` commands on a compromised host.

T1059.003
Windows Command Shell
ToolAsyncRAT

AsyncRAT can be deployed via batch script.

T1059.003
Windows Command Shell
ToolBrute Ratel C4

Brute Ratel C4 can use cmd.exe for execution.

T1059.003
Windows Command Shell
ToolRemcos

Remcos can launch a remote command line to execute commands on the victim’s machine.

T1059.003
Windows Command Shell
ToolOut1

Out1 can use native command line for execution.

T1059.003
Windows Command Shell
ToolMCMD

MCMD can launch a console process (cmd.exe) with redirected standard input and output.

T1059.003
Windows Command Shell
Toolcmd

cmd is used to execute programs and other actions at the command-line interface.

T1059.003
Windows Command Shell
ToolKoadic

Koadic can open an interactive command-shell to perform command line functions on victim machines. Koadic performs most of its operations using Windows Script Host (Jscript) and to run arbitrary shellcode.

T1059.003
Windows Command Shell
ToolQuasarRAT

QuasarRAT can launch a remote shell to execute commands on the victim’s machine.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.