Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1059.001 PowerShell |
MalwareLunarWeb | LunarWeb has the ability to run shell commands via PowerShell. |
| T1059.001 PowerShell |
MalwareQilin | Qilin has been deployed on VMware vCenter and ESXi servers via custom PowerShell script. Qilin has also used PowerShell for discovery in vCenter and Active Directory environments. |
| T1059.001 PowerShell |
MalwareLazyWiper | LazyWiper has used PowerShell to enable data destruction on targeted systems. |
| T1059.001 PowerShell |
MalwareDownPaper | DownPaper uses PowerShell for execution. |
| T1059.001 PowerShell |
MalwareSocksbot | Socksbot can write and execute PowerShell scripts. |
| T1059.001 PowerShell |
MalwarePOWERSTATS | POWERSTATS uses PowerShell for obfuscation and execution. |
| T1059.001 PowerShell |
MalwarePOWERTON | POWERTON is written in PowerShell. |
| T1059.001 PowerShell |
MalwareQakBot | QakBot can use PowerShell to download and execute payloads. |
| T1059.001 PowerShell |
MalwareHancitor | Hancitor has used PowerShell to execute commands. |
| T1059.001 PowerShell |
MalwareHelminth | One version of Helminth uses a PowerShell script. |
| T1059.001 PowerShell |
MalwareDenis | Denis has a version written in PowerShell. |
| T1059.001 PowerShell |
MalwareAutoIt backdoor | AutoIt backdoor downloads a PowerShell script that decodes to a typical shellcode loader. |
| T1059.001 PowerShell |
MalwareJSS Loader | JSS Loader has the ability to download and execute PowerShell scripts. |
| T1059.001 PowerShell |
MalwareLizar | Lizar has used PowerShell scripts. |
| T1059.001 PowerShell |
MalwareWarzoneRAT | WarzoneRAT can use PowerShell to download files and execute commands. |
| T1059.001 PowerShell |
ToolCovenant | Covenant can create PowerShell-based launchers for Grunt installation. |
| T1059.001 PowerShell |
ToolBloodHound | BloodHound can use PowerShell to pull Active Directory information from the target environment. |
| T1059.001 PowerShell |
ToolSliver | Sliver has built-in functionality to launch a Powershell command prompt. |
| T1059.001 PowerShell |
ToolSILENTTRINITY | SILENTTRINITY can use PowerShell to execute commands. |
| T1059.001 PowerShell |
ToolPowerSploit | PowerSploit modules are written in and executed via PowerShell. |
| T1059.001 PowerShell |
ToolAADInternals | AADInternals is written and executed via PowerShell. |
| T1059.001 PowerShell |
ToolEmpire | Empire leverages PowerShell for the majority of its client-side agent tasks. Empire also contains the ability to conduct PowerShell remoting with the |
| T1059.001 PowerShell |
ToolConnectWise | ConnectWise can be used to execute PowerShell commands on target machines. |
| T1059.001 PowerShell |
ToolDonut | Donut can generate shellcode outputs that execute via PowerShell. |
| T1059.001 PowerShell |
ToolCrackMapExec | CrackMapExec can execute PowerShell commands via WMI. |
| T1059.001 PowerShell |
ToolKoadic | Koadic has used PowerShell to establish persistence. |
| T1059.001 PowerShell |
ToolPupy | Pupy has a module for loading and executing PowerShell scripts. |
| T1059.001 PowerShell |
MalwareZeroCleare | ZeroCleare can use a malicious PowerShell script to bypass Windows controls. |
| T1059.002 AppleScript |
MalwaremacOS.OSAMiner | macOS.OSAMiner has used `osascript` to call itself via the `do shell script` command in the Launch Agent `.plist` file. |
| T1059.002 AppleScript |
MalwareCuckoo Stealer | Cuckoo Stealer can use osascript to generate a password-stealing prompt, duplicate files and folders, and set environmental variables. |
| T1059.002 AppleScript |
MalwareThiefQuest | ThiefQuest uses AppleScript's |
| T1059.002 AppleScript |
MalwareBundlore | Bundlore can use AppleScript to inject malicious JavaScript into a browser. |
| T1059.002 AppleScript |
MalwareGlassWorm | GlassWorm has utilized AppleScript to include `set keychainPassword to do shell script` to execute shell command that retrieves passwords from the macOS keychain. |
| T1059.002 AppleScript |
MalwareDok | Dok uses AppleScript to create a login item for persistence. |
| T1059.003 Windows Command Shell |
MalwareTrickBot | TrickBot has used macros in Excel documents to download and deploy the malware on the user’s machine. |
| T1059.003 Windows Command Shell |
MalwarePowerDuke | PowerDuke runs |
| T1059.003 Windows Command Shell |
MalwareBLINDINGCAN | BLINDINGCAN has executed commands via cmd.exe. |
| T1059.003 Windows Command Shell |
MalwarePikabot | Pikabot can execute Windows shell commands via |
| T1059.003 Windows Command Shell |
MalwareWiarp | Wiarp creates a backdoor through which remote attackers can open a command line interface. |
| T1059.003 Windows Command Shell |
MalwareRCSession | RCSession can use `cmd.exe` for execution on compromised hosts. |
| T1059.003 Windows Command Shell |
MalwareSpark | Spark can use cmd.exe to run commands. |
| T1059.003 Windows Command Shell |
MalwareBumblebee | Bumblebee can use `cmd.exe` to drop and run files. |
| T1059.003 Windows Command Shell |
MalwareMURKYTOP | MURKYTOP uses the command-line interface. |
| T1059.003 Windows Command Shell |
MalwareExaramel for Windows | Exaramel for Windows has a command to launch a remote shell and executes commands on the victim’s machine. |
| T1059.003 Windows Command Shell |
MalwareProxysvc | Proxysvc executes a binary on the system and logs the results into a temp file by using: |
| T1059.003 Windows Command Shell |
MalwareOrz | Orz can execute shell commands. Orz can execute commands with JavaScript. |
| T1059.003 Windows Command Shell |
MalwareIronWind | IronWind has used the Windows command shell to execute malicious files. |
| T1059.003 Windows Command Shell |
MalwareSEASHARPEE | SEASHARPEE can execute commands on victims. |
| T1059.003 Windows Command Shell |
MalwarePOWRUNER | POWRUNER can execute commands from its C2 server. |
| T1059.003 Windows Command Shell |
MalwareRobbinHood | RobbinHood uses cmd.exe on the victim's computer. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.