ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

1146 examples

TechniqueUsed byProcedure example
T1059.003
Windows Command Shell
Campaign2016 Ukraine Electric Power Attack

During the 2016 Ukraine Electric Power Attack, Sandworm Team used the `xp_cmdshell` command in MS-SQL.

T1059.003
Windows Command Shell
CampaignNight Dragon

During Night Dragon, threat actors used zwShell to establish full remote control of the connected machine and run command-line shells.

T1059.003
Windows Command Shell
CampaignOperation Wocao

During Operation Wocao, threat actors spawned a new `cmd.exe` process to execute commands.

T1059.003
Windows Command Shell
CampaignC0017

During C0017, APT41 used `cmd.exe` to execute reconnaissance commands.

T1059.004
Unix Shell
CampaignKV Botnet Activity

KV Botnet Activity utilizes multiple Bash scripts during botnet installation stages, and the final botnet payload allows for running commands in the Bash shell.

T1059.004
Unix Shell
CampaignRedPenguin

During RedPenguin, UNC3886 used malware capable of launching an interactive shell.

T1059.004
Unix Shell
CampaignOperation MidnightEclipse

During Operation MidnightEclipse, threat actors piped output from stdout to bash for execution.

T1059.004
Unix Shell
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries utilized the Linux `dd` command to overwrite portions of the disks with random data.

T1059.004
Unix Shell
CampaignQuad7 Activity

Quad7 Activity has enabled the creation of an access-controlled command shell /bin/sh on compromised routers.

T1059.004
Unix Shell
CampaignFLORAHOX Activity

FLORAHOX Activity has executed multiple Bash controller scripts to provide command line inputs for FLORAHOX traversal configurations.

T1059.005
Visual Basic
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group executed a VBA written malicious macro after victims download malicious DOTM files; Lazarus Group also used Visual Basic macro code to extract a double Base64 encoded DLL implant.

T1059.005
Visual Basic
CampaignFrankenstein

During Frankenstein, the threat actors used Word documents that prompted the victim to enable macros and run a Visual Basic script.

T1059.005
Visual Basic
CampaignOperation Sharpshooter

During Operation Sharpshooter, the threat actors used a VBA macro to execute a simple downloader that installed Rising Sun.

T1059.005
Visual Basic
CampaignOperation Honeybee

For Operation Honeybee, the threat actors used a Visual Basic script embedded within a Word document to download an implant.

T1059.005
Visual Basic
CampaignOperation Dust Storm

During Operation Dust Storm, the threat actors used Visual Basic scripts.

T1059.005
Visual Basic
Campaign2015 Ukraine Electric Power Attack

During the 2015 Ukraine Electric Power Attack, Sandworm Team installed a VBA script called `vba_macro.exe`. This macro dropped `FONTCACHE.DAT`, the primary BlackEnergy implant; `rundll32.exe`, for executing the malware; `NTUSER.log`, an empty file; and desktop.ini, the default file used to determine folder displays on Windows machines.

T1059.005
Visual Basic
CampaignC0015

During C0015, the threat actors used a malicious HTA file that contained a mix of HTML and JavaScript/VBScript code.

T1059.005
Visual Basic
CampaignJuicy Mix

During Juicy Mix, OilRig used VBS droppers to deliver and establish persistence for the Mango backdoor.

T1059.005
Visual Basic
CampaignSolarWinds Compromise

For the SolarWinds Compromise, APT29 wrote malware such as Sibot in Visual Basic.

T1059.005
Visual Basic
CampaignOperation AkaiRyū

During Operation AkaiRyū, MirrorFace used Word templates containing VBA code for malware execution.

T1059.005
Visual Basic
CampaignFunnyDream

During FunnyDream, the threat actors used a Visual Basic script to run remote commands.

T1059.005
Visual Basic
CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors executed an encoded VBScript file using `wscript` and wrote the decoded output to a text file.

T1059.005
Visual Basic
CampaignOuter Space

During Outer Space, OilRig used VBS droppers to deploy malware.

T1059.005
Visual Basic
Campaign2016 Ukraine Electric Power Attack

During the 2016 Ukraine Electric Power Attack, Sandworm Team created VBScripts to run on an SSH server.

T1059.005
Visual Basic
CampaignOperation Wocao

During Operation Wocao, threat actors used VBScript to conduct reconnaissance on targeted systems.

T1059.005
Visual Basic
CampaignC0011

For C0011, Transparent Tribe used malicious VBA macros within a lure document as part of the Crimson malware installation process onto a compromised host.

T1059.006
Python
CampaignCutting Edge

During Cutting Edge, threat actors used a Python reverse shell and the PySoxy SOCKS5 proxy tool.

T1059.006
Python
CampaignShadowRay

During ShadowRay, threat actors used the Python `pty` module to open reverse shells.

T1059.006
Python
CampaignSalesforce Data Exfiltration

During Salesforce Data Exfiltration, threat actors used custom applications developed in python.

T1059.006
Python
CampaignOperation Wocao

During Operation Wocao, threat actors' backdoors were written in Python and compiled with py2exe.

T1059.007
JavaScript
CampaignOperation Dust Storm

During Operation Dust Storm, the threat actors used JavaScript code.

T1059.007
JavaScript
CampaignWater Curupira Pikabot Distribution

Water Curupira Pikabot Distribution initial delivery included obfuscated JavaScript objects stored in password-protected ZIP archives.

T1059.007
JavaScript
CampaignC0015

During C0015, the threat actors used a malicious HTA file that contained a mix of encoded HTML and JavaScript/VBScript code.

T1059.007
JavaScript
CampaignPikabot Distribution February 2024

Pikabot Distribution February 2024 utilized obfuscated JavaScript files for initial Pikabot payload download.

T1059.007
JavaScript
CampaignC0017

During C0017, APT41 deployed JScript web shells on compromised systems.

T1059.008
Network Device CLI
CampaignRedPenguin

During RedPenguin, UNC3886 accessed the Junos OS CLI on targeted devices.

T1059.008
Network Device CLI
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries leveraged the native CLI of the targeted FortiGate device.

T1068
Exploitation for Privilege Escalation
CampaignShadowRay

During ShadowRay, threat actors downloaded a privilege escalation payload to gain root access.

T1068
Exploitation for Privilege Escalation
CampaignLeviathan Australian Intrusions

Leviathan exploited software vulnerabilities in victim environments to escalate privileges during Leviathan Australian Intrusions.

T1069
Permission Groups Discovery
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used the `Get-ManagementRoleAssignment` PowerShell cmdlet to enumerate Exchange management role assignments through an Exchange Management Shell.

T1069.001
Local Groups
CampaignOperation Digital Eye

During Operation Digital Eye, threat actors used the local.exe tool to view group memberships.

T1069.001
Local Groups
CampaignC0015

During C0015, the threat actors used the command `net localgroup "adminstrator" ` to identify accounts with local administrator rights.

T1069.001
Local Groups
CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors used the `net group` command as part of their advanced reconnaissance.

T1069.001
Local Groups
CampaignOperation Wocao

During Operation Wocao, threat actors used the command `net localgroup administrators` to list all administrators part of a local group.

T1069.002
Domain Groups
CampaignC0015

During C0015, the threat actors use the command `net group "domain admins" /dom` to enumerate domain groups.

T1069.002
Domain Groups
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used AdFind to enumerate domain groups.

T1069.003
Cloud Groups
CampaignC0027

During C0027, Scattered Spider accessed Azure AD to download bulk lists of group members and their Active Directory attributes.

T1070
Indicator Removal
CampaignCutting Edge

During Cutting Edge, threat actors cleared logs to remove traces of their activity and restored compromised systems to a clean state to bypass manufacturer mitigations for CVE-2023-46805 and CVE-2024-21887.

T1070
Indicator Removal
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 temporarily replaced legitimate utilities with their own, executed their payload, and then restored the original file.

T1070.004
File Deletion
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group removed all previously delivered files from a compromised computer.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.