Real-world descriptions of how a group, tool or campaign used a technique.
1146 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1059.003 Windows Command Shell |
Campaign2016 Ukraine Electric Power Attack | During the 2016 Ukraine Electric Power Attack, Sandworm Team used the `xp_cmdshell` command in MS-SQL. |
| T1059.003 Windows Command Shell |
CampaignNight Dragon | During Night Dragon, threat actors used zwShell to establish full remote control of the connected machine and run command-line shells. |
| T1059.003 Windows Command Shell |
CampaignOperation Wocao | During Operation Wocao, threat actors spawned a new `cmd.exe` process to execute commands. |
| T1059.003 Windows Command Shell |
CampaignC0017 | During C0017, APT41 used `cmd.exe` to execute reconnaissance commands. |
| T1059.004 Unix Shell |
CampaignKV Botnet Activity | KV Botnet Activity utilizes multiple Bash scripts during botnet installation stages, and the final botnet payload allows for running commands in the Bash shell. |
| T1059.004 Unix Shell |
CampaignRedPenguin | During RedPenguin, UNC3886 used malware capable of launching an interactive shell. |
| T1059.004 Unix Shell |
CampaignOperation MidnightEclipse | During Operation MidnightEclipse, threat actors piped output from stdout to bash for execution. |
| T1059.004 Unix Shell |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries utilized the Linux `dd` command to overwrite portions of the disks with random data. |
| T1059.004 Unix Shell |
CampaignQuad7 Activity | Quad7 Activity has enabled the creation of an access-controlled command shell |
| T1059.004 Unix Shell |
CampaignFLORAHOX Activity | FLORAHOX Activity has executed multiple Bash controller scripts to provide command line inputs for FLORAHOX traversal configurations. |
| T1059.005 Visual Basic |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group executed a VBA written malicious macro after victims download malicious DOTM files; Lazarus Group also used Visual Basic macro code to extract a double Base64 encoded DLL implant. |
| T1059.005 Visual Basic |
CampaignFrankenstein | During Frankenstein, the threat actors used Word documents that prompted the victim to enable macros and run a Visual Basic script. |
| T1059.005 Visual Basic |
CampaignOperation Sharpshooter | During Operation Sharpshooter, the threat actors used a VBA macro to execute a simple downloader that installed Rising Sun. |
| T1059.005 Visual Basic |
CampaignOperation Honeybee | For Operation Honeybee, the threat actors used a Visual Basic script embedded within a Word document to download an implant. |
| T1059.005 Visual Basic |
CampaignOperation Dust Storm | During Operation Dust Storm, the threat actors used Visual Basic scripts. |
| T1059.005 Visual Basic |
Campaign2015 Ukraine Electric Power Attack | During the 2015 Ukraine Electric Power Attack, Sandworm Team installed a VBA script called `vba_macro.exe`. This macro dropped `FONTCACHE.DAT`, the primary BlackEnergy implant; `rundll32.exe`, for executing the malware; `NTUSER.log`, an empty file; and desktop.ini, the default file used to determine folder displays on Windows machines. |
| T1059.005 Visual Basic |
CampaignC0015 | During C0015, the threat actors used a malicious HTA file that contained a mix of HTML and JavaScript/VBScript code. |
| T1059.005 Visual Basic |
CampaignJuicy Mix | During Juicy Mix, OilRig used VBS droppers to deliver and establish persistence for the Mango backdoor. |
| T1059.005 Visual Basic |
CampaignSolarWinds Compromise | For the SolarWinds Compromise, APT29 wrote malware such as Sibot in Visual Basic. |
| T1059.005 Visual Basic |
CampaignOperation AkaiRyū | During Operation AkaiRyū, MirrorFace used Word templates containing VBA code for malware execution. |
| T1059.005 Visual Basic |
CampaignFunnyDream | During FunnyDream, the threat actors used a Visual Basic script to run remote commands. |
| T1059.005 Visual Basic |
CampaignOperation CuckooBees | During Operation CuckooBees, the threat actors executed an encoded VBScript file using `wscript` and wrote the decoded output to a text file. |
| T1059.005 Visual Basic |
CampaignOuter Space | During Outer Space, OilRig used VBS droppers to deploy malware. |
| T1059.005 Visual Basic |
Campaign2016 Ukraine Electric Power Attack | During the 2016 Ukraine Electric Power Attack, Sandworm Team created VBScripts to run on an SSH server. |
| T1059.005 Visual Basic |
CampaignOperation Wocao | During Operation Wocao, threat actors used VBScript to conduct reconnaissance on targeted systems. |
| T1059.005 Visual Basic |
CampaignC0011 | For C0011, Transparent Tribe used malicious VBA macros within a lure document as part of the Crimson malware installation process onto a compromised host. |
| T1059.006 Python |
CampaignCutting Edge | During Cutting Edge, threat actors used a Python reverse shell and the PySoxy SOCKS5 proxy tool. |
| T1059.006 Python |
CampaignShadowRay | During ShadowRay, threat actors used the Python `pty` module to open reverse shells. |
| T1059.006 Python |
CampaignSalesforce Data Exfiltration | During Salesforce Data Exfiltration, threat actors used custom applications developed in python. |
| T1059.006 Python |
CampaignOperation Wocao | During Operation Wocao, threat actors' backdoors were written in Python and compiled with py2exe. |
| T1059.007 JavaScript |
CampaignOperation Dust Storm | During Operation Dust Storm, the threat actors used JavaScript code. |
| T1059.007 JavaScript |
CampaignWater Curupira Pikabot Distribution | Water Curupira Pikabot Distribution initial delivery included obfuscated JavaScript objects stored in password-protected ZIP archives. |
| T1059.007 JavaScript |
CampaignC0015 | During C0015, the threat actors used a malicious HTA file that contained a mix of encoded HTML and JavaScript/VBScript code. |
| T1059.007 JavaScript |
CampaignPikabot Distribution February 2024 | Pikabot Distribution February 2024 utilized obfuscated JavaScript files for initial Pikabot payload download. |
| T1059.007 JavaScript |
CampaignC0017 | During C0017, APT41 deployed JScript web shells on compromised systems. |
| T1059.008 Network Device CLI |
CampaignRedPenguin | During RedPenguin, UNC3886 accessed the Junos OS CLI on targeted devices. |
| T1059.008 Network Device CLI |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries leveraged the native CLI of the targeted FortiGate device. |
| T1068 Exploitation for Privilege Escalation |
CampaignShadowRay | During ShadowRay, threat actors downloaded a privilege escalation payload to gain root access. |
| T1068 Exploitation for Privilege Escalation |
CampaignLeviathan Australian Intrusions | Leviathan exploited software vulnerabilities in victim environments to escalate privileges during Leviathan Australian Intrusions. |
| T1069 Permission Groups Discovery |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used the `Get-ManagementRoleAssignment` PowerShell cmdlet to enumerate Exchange management role assignments through an Exchange Management Shell. |
| T1069.001 Local Groups |
CampaignOperation Digital Eye | During Operation Digital Eye, threat actors used the local.exe tool to view group memberships. |
| T1069.001 Local Groups |
CampaignC0015 | During C0015, the threat actors used the command `net localgroup "adminstrator" ` to identify accounts with local administrator rights. |
| T1069.001 Local Groups |
CampaignOperation CuckooBees | During Operation CuckooBees, the threat actors used the `net group` command as part of their advanced reconnaissance. |
| T1069.001 Local Groups |
CampaignOperation Wocao | During Operation Wocao, threat actors used the command `net localgroup administrators` to list all administrators part of a local group. |
| T1069.002 Domain Groups |
CampaignC0015 | During C0015, the threat actors use the command `net group "domain admins" /dom` to enumerate domain groups. |
| T1069.002 Domain Groups |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used AdFind to enumerate domain groups. |
| T1069.003 Cloud Groups |
CampaignC0027 | During C0027, Scattered Spider accessed Azure AD to download bulk lists of group members and their Active Directory attributes. |
| T1070 Indicator Removal |
CampaignCutting Edge | During Cutting Edge, threat actors cleared logs to remove traces of their activity and restored compromised systems to a clean state to bypass manufacturer mitigations for CVE-2023-46805 and CVE-2024-21887. |
| T1070 Indicator Removal |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 temporarily replaced legitimate utilities with their own, executed their payload, and then restored the original file. |
| T1070.004 File Deletion |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group removed all previously delivered files from a compromised computer. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.