ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1059.001
PowerShell
MalwareLunarWeb

LunarWeb has the ability to run shell commands via PowerShell.

T1059.001
PowerShell
MalwareQilin

Qilin has been deployed on VMware vCenter and ESXi servers via custom PowerShell script. Qilin has also used PowerShell for discovery in vCenter and Active Directory environments.

T1059.001
PowerShell
MalwareLazyWiper

LazyWiper has used PowerShell to enable data destruction on targeted systems.

T1059.001
PowerShell
MalwareDownPaper

DownPaper uses PowerShell for execution.

T1059.001
PowerShell
MalwareSocksbot

Socksbot can write and execute PowerShell scripts.

T1059.001
PowerShell
MalwarePOWERSTATS

POWERSTATS uses PowerShell for obfuscation and execution.

T1059.001
PowerShell
MalwarePOWERTON

POWERTON is written in PowerShell.

T1059.001
PowerShell
MalwareQakBot

QakBot can use PowerShell to download and execute payloads.

T1059.001
PowerShell
MalwareHancitor

Hancitor has used PowerShell to execute commands.

T1059.001
PowerShell
MalwareHelminth

One version of Helminth uses a PowerShell script.

T1059.001
PowerShell
MalwareDenis

Denis has a version written in PowerShell.

T1059.001
PowerShell
MalwareAutoIt backdoor

AutoIt backdoor downloads a PowerShell script that decodes to a typical shellcode loader.

T1059.001
PowerShell
MalwareJSS Loader

JSS Loader has the ability to download and execute PowerShell scripts.

T1059.001
PowerShell
MalwareLizar

Lizar has used PowerShell scripts.

T1059.001
PowerShell
MalwareWarzoneRAT

WarzoneRAT can use PowerShell to download files and execute commands.

T1059.001
PowerShell
ToolCovenant

Covenant can create PowerShell-based launchers for Grunt installation.

T1059.001
PowerShell
ToolBloodHound

BloodHound can use PowerShell to pull Active Directory information from the target environment.

T1059.001
PowerShell
ToolSliver

Sliver has built-in functionality to launch a Powershell command prompt.

T1059.001
PowerShell
ToolSILENTTRINITY

SILENTTRINITY can use PowerShell to execute commands.

T1059.001
PowerShell
ToolPowerSploit

PowerSploit modules are written in and executed via PowerShell.

T1059.001
PowerShell
ToolAADInternals

AADInternals is written and executed via PowerShell.

T1059.001
PowerShell
ToolEmpire

Empire leverages PowerShell for the majority of its client-side agent tasks. Empire also contains the ability to conduct PowerShell remoting with the Invoke-PSRemoting module.

T1059.001
PowerShell
ToolConnectWise

ConnectWise can be used to execute PowerShell commands on target machines.

T1059.001
PowerShell
ToolDonut

Donut can generate shellcode outputs that execute via PowerShell.

T1059.001
PowerShell
ToolCrackMapExec

CrackMapExec can execute PowerShell commands via WMI.

T1059.001
PowerShell
ToolKoadic

Koadic has used PowerShell to establish persistence.

T1059.001
PowerShell
ToolPupy

Pupy has a module for loading and executing PowerShell scripts.

T1059.001
PowerShell
MalwareZeroCleare

ZeroCleare can use a malicious PowerShell script to bypass Windows controls.

T1059.002
AppleScript
MalwaremacOS.OSAMiner

macOS.OSAMiner has used `osascript` to call itself via the `do shell script` command in the Launch Agent `.plist` file.

T1059.002
AppleScript
MalwareCuckoo Stealer

Cuckoo Stealer can use osascript to generate a password-stealing prompt, duplicate files and folders, and set environmental variables.

T1059.002
AppleScript
MalwareThiefQuest

ThiefQuest uses AppleScript's osascript -e command to launch ThiefQuest's persistence via Launch Agent and Launch Daemon.

T1059.002
AppleScript
MalwareBundlore

Bundlore can use AppleScript to inject malicious JavaScript into a browser.

T1059.002
AppleScript
MalwareGlassWorm

GlassWorm has utilized AppleScript to include `set keychainPassword to do shell script` to execute shell command that retrieves passwords from the macOS keychain.

T1059.002
AppleScript
MalwareDok

Dok uses AppleScript to create a login item for persistence.

T1059.003
Windows Command Shell
MalwareTrickBot

TrickBot has used macros in Excel documents to download and deploy the malware on the user’s machine.

T1059.003
Windows Command Shell
MalwarePowerDuke

PowerDuke runs cmd.exe /c and sends the output to its C2.

T1059.003
Windows Command Shell
MalwareBLINDINGCAN

BLINDINGCAN has executed commands via cmd.exe.

T1059.003
Windows Command Shell
MalwarePikabot

Pikabot can execute Windows shell commands via cmd.exe.

T1059.003
Windows Command Shell
MalwareWiarp

Wiarp creates a backdoor through which remote attackers can open a command line interface.

T1059.003
Windows Command Shell
MalwareRCSession

RCSession can use `cmd.exe` for execution on compromised hosts.

T1059.003
Windows Command Shell
MalwareSpark

Spark can use cmd.exe to run commands.

T1059.003
Windows Command Shell
MalwareBumblebee

Bumblebee can use `cmd.exe` to drop and run files.

T1059.003
Windows Command Shell
MalwareMURKYTOP

MURKYTOP uses the command-line interface.

T1059.003
Windows Command Shell
MalwareExaramel for Windows

Exaramel for Windows has a command to launch a remote shell and executes commands on the victim’s machine.

T1059.003
Windows Command Shell
MalwareProxysvc

Proxysvc executes a binary on the system and logs the results into a temp file by using: cmd.exe /c "<file_path> > %temp%\PM* .tmp 2>&1".

T1059.003
Windows Command Shell
MalwareOrz

Orz can execute shell commands. Orz can execute commands with JavaScript.

T1059.003
Windows Command Shell
MalwareIronWind

IronWind has used the Windows command shell to execute malicious files.

T1059.003
Windows Command Shell
MalwareSEASHARPEE

SEASHARPEE can execute commands on victims.

T1059.003
Windows Command Shell
MalwarePOWRUNER

POWRUNER can execute commands from its C2 server.

T1059.003
Windows Command Shell
MalwareRobbinHood

RobbinHood uses cmd.exe on the victim's computer.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.