Real-world descriptions of how a group, tool or campaign used a technique.
295 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1059.003 Windows Command Shell |
MalwareKevin | Kevin can use a renamed image of `cmd.exe` for execution. |
| T1059.003 Windows Command Shell |
Malwarehttpclient | httpclient opens cmd.exe on the victim. |
| T1059.003 Windows Command Shell |
MalwareECCENTRICBANDWAGON | ECCENTRICBANDWAGON can use cmd to execute commands on a victim’s machine. |
| T1059.003 Windows Command Shell |
MalwareBADNEWS | BADNEWS is capable of executing commands via cmd.exe. |
| T1059.003 Windows Command Shell |
MalwareLinfo | Linfo creates a backdoor through which remote attackers can start a remote shell. |
| T1059.003 Windows Command Shell |
MalwareGoopy | Goopy has the ability to use cmd.exe to execute commands passed from an Outlook C2 channel. |
| T1059.003 Windows Command Shell |
MalwareRemexi | Remexi silently executes received commands with cmd.exe. |
| T1059.003 Windows Command Shell |
MalwareAstaroth | Astaroth spawns a CMD process to execute commands. |
| T1059.003 Windows Command Shell |
MalwareQakBot | QakBot can use cmd.exe to launch itself and to execute multiple C2 commands. |
| T1059.003 Windows Command Shell |
MalwareSYSCON | SYSCON has the ability to execute commands through cmd on a compromised host. |
| T1059.003 Windows Command Shell |
MalwareGelsemium | Gelsemium can use a batch script to delete itself. |
| T1059.003 Windows Command Shell |
MalwarejRAT | jRAT has command line access. |
| T1059.003 Windows Command Shell |
MalwareHelminth | Helminth can provide a remote shell. One version of Helminth uses batch scripting. |
| T1059.003 Windows Command Shell |
MalwareBBK | BBK has the ability to use cmd to run a Portable Executable (PE) on the compromised host. |
| T1059.003 Windows Command Shell |
MalwareDenis | Denis can launch a remote shell to execute arbitrary commands on the victim’s machine. |
| T1059.003 Windows Command Shell |
MalwareComnie | Comnie executes BAT scripts. |
| T1059.003 Windows Command Shell |
MalwarePHOREAL | PHOREAL is capable of creating reverse shell. |
| T1059.003 Windows Command Shell |
MalwareLizar | Lizar has a command to open the command-line on the infected system. |
| T1059.003 Windows Command Shell |
MalwareDtrack | Dtrack has used |
| T1059.003 Windows Command Shell |
MalwareH1N1 | H1N1 kills and disables services by using cmd.exe. |
| T1059.003 Windows Command Shell |
MalwareSeth-Locker | Seth-Locker can execute commands via the command line shell. |
| T1059.003 Windows Command Shell |
MalwareLoudMiner | LoudMiner used a batch script to run the Linux virtual machine as a service. |
| T1059.003 Windows Command Shell |
MalwareBACKSPACE | Adversaries can direct BACKSPACE to execute from the command line on infected hosts, or have BACKSPACE create a reverse shell. |
| T1059.003 Windows Command Shell |
MalwareUPPERCUT | UPPERCUT uses cmd.exe to execute commands on the victim’s machine. |
| T1059.003 Windows Command Shell |
MalwareADVSTORESHELL | ADVSTORESHELL can create a remote shell and run a given command. |
| T1059.003 Windows Command Shell |
MalwareStrifeWater | StrifeWater can execute shell commands using `cmd.exe`. |
| T1059.003 Windows Command Shell |
MalwareMivast | Mivast has the capability to open a remote shell and run basic commands. |
| T1059.003 Windows Command Shell |
MalwareHiddenWasp | HiddenWasp uses a script to automate tasks on the victim's machine and to assist in execution. |
| T1059.003 Windows Command Shell |
MalwareWarzoneRAT | WarzoneRAT can use `cmd.exe` to execute malicious code. |
| T1059.003 Windows Command Shell |
MalwareSLOTHFULMEDIA | SLOTHFULMEDIA can open a command line to execute commands. |
| T1059.003 Windows Command Shell |
MalwareSmall Sieve | Small Sieve can use `cmd.exe` to execute commands on a victim's system. |
| T1059.003 Windows Command Shell |
MalwareHermeticWizard | HermeticWizard can use `cmd.exe` for execution on compromised hosts. |
| T1059.003 Windows Command Shell |
ToolCovenant | Covenant provides access to a Command Shell in Windows environments for follow-on command execution and tasking. |
| T1059.003 Windows Command Shell |
ToolDiskpart | Diskpart can execute a disk partition script file, which attempts to mount a virtual hard disk. Diskpart can also assign and mount virtual disks. |
| T1059.003 Windows Command Shell |
ToolSILENTTRINITY | SILENTTRINITY can use `cmd.exe` to enable lateral movement using DCOM. |
| T1059.003 Windows Command Shell |
ToolEmpire | Empire has modules for executing scripts. |
| T1059.003 Windows Command Shell |
ToolPcShare | PcShare can execute `cmd` commands on a compromised host. |
| T1059.003 Windows Command Shell |
ToolAsyncRAT | AsyncRAT can be deployed via batch script. |
| T1059.003 Windows Command Shell |
ToolBrute Ratel C4 | Brute Ratel C4 can use cmd.exe for execution. |
| T1059.003 Windows Command Shell |
ToolRemcos | Remcos can launch a remote command line to execute commands on the victim’s machine. |
| T1059.003 Windows Command Shell |
ToolOut1 | Out1 can use native command line for execution. |
| T1059.003 Windows Command Shell |
ToolMCMD | MCMD can launch a console process (cmd.exe) with redirected standard input and output. |
| T1059.003 Windows Command Shell |
Toolcmd | cmd is used to execute programs and other actions at the command-line interface. |
| T1059.003 Windows Command Shell |
ToolKoadic | Koadic can open an interactive command-shell to perform command line functions on victim machines. Koadic performs most of its operations using Windows Script Host (Jscript) and to run arbitrary shellcode. |
| T1059.003 Windows Command Shell |
ToolQuasarRAT | QuasarRAT can launch a remote shell to execute commands on the victim’s machine. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.