Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1059.003 Windows Command Shell |
MalwareMafalda | Mafalda can execute shell commands using `cmd.exe`. |
| T1059.003 Windows Command Shell |
MalwareSquirrelwaffle | Squirrelwaffle has used `cmd.exe` for execution. |
| T1059.003 Windows Command Shell |
MalwareUmbreon | Umbreon provides access using both standard facilities like SSH and additional access using its backdoor Espeon, providing a reverse shell upon receipt of a special packet |
| T1059.003 Windows Command Shell |
MalwareAuTo Stealer | AuTo Stealer can use `cmd.exe` to execute a created batch file. |
| T1059.003 Windows Command Shell |
MalwareODAgent | ODAgent can execute a specified command line passed via API. |
| T1059.003 Windows Command Shell |
MalwareFlawedAmmyy | FlawedAmmyy has used `cmd` to execute commands on a compromised host. |
| T1059.003 Windows Command Shell |
MalwareSUGARUSH | SUGARUSH has used `cmd` for execution on an infected host. |
| T1059.003 Windows Command Shell |
MalwareHOPLIGHT | HOPLIGHT can launch cmd.exe to execute commands on the system. |
| T1059.003 Windows Command Shell |
MalwareWastedLocker | WastedLocker has used cmd to execute commands on the system. |
| T1059.003 Windows Command Shell |
MalwareInvisiMole | InvisiMole can launch a remote shell to execute commands. |
| T1059.003 Windows Command Shell |
MalwareVolgmer | Volgmer can execute commands on the victim's machine. |
| T1059.003 Windows Command Shell |
MalwareWhisperGate | WhisperGate can use `cmd.exe` to execute commands. |
| T1059.003 Windows Command Shell |
MalwareRDAT | RDAT has executed commands using |
| T1059.003 Windows Command Shell |
MalwareOkrum | Okrum's backdoor has used cmd.exe to execute arbitrary commands as well as batch scripts to update itself to a newer version. |
| T1059.003 Windows Command Shell |
MalwareSamSam | SamSam uses custom batch scripts to execute some of its components. |
| T1059.003 Windows Command Shell |
MalwareConti | Conti can utilize command line options to allow an attacker control over how it scans and encrypts files. |
| T1059.003 Windows Command Shell |
MalwareRaspberry Robin | Raspberry Robin uses cmd.exe to read and execute a file stored on an infected USB device as part of initial installation. |
| T1059.003 Windows Command Shell |
MalwareMegazord | Megazord can execute multiple commands post infection via `cmd.exe`. |
| T1059.003 Windows Command Shell |
MalwareTEXTMATE | TEXTMATE executes cmd.exe to provide a reverse shell to adversaries. |
| T1059.003 Windows Command Shell |
MalwareSiloscape | Siloscape can run cmd through an IRC channel. |
| T1059.003 Windows Command Shell |
MalwareBlackCat | BlackCat can execute commands on a compromised network with the use of `cmd.exe`. |
| T1059.003 Windows Command Shell |
MalwareUBoatRAT | UBoatRAT can start a command shell. |
| T1059.003 Windows Command Shell |
MalwareNightdoor | Nightdoor creates a cmd.exe shell to send and receive commands from the command and control server via open pipes. |
| T1059.003 Windows Command Shell |
MalwareHTTPTroy | HTTPTroy has the ability to generate a reverse shell using the command `conn <IP_ADDRESS> <PORT>`. |
| T1059.003 Windows Command Shell |
MalwareMarkiRAT | MarkiRAT can utilize cmd.exe to execute commands in a victim's environment. |
| T1059.003 Windows Command Shell |
MalwareKazuar | Kazuar uses cmd.exe to execute commands on the victim’s machine. |
| T1059.003 Windows Command Shell |
MalwareNavRAT | NavRAT leverages cmd.exe to perform discovery techniques. NavRAT loads malicious shellcode and executes it in memory. |
| T1059.003 Windows Command Shell |
MalwareDarkComet | DarkComet can launch a remote shell to execute commands on the victim’s machine. |
| T1059.003 Windows Command Shell |
MalwareNETEAGLE | NETEAGLE allows adversaries to execute shell commands on the infected host. |
| T1059.003 Windows Command Shell |
MalwareRagnar Locker | Ragnar Locker has used cmd.exe and batch scripts to execute commands. |
| T1059.003 Windows Command Shell |
MalwareLucifer | Lucifer can issue shell commands to download and execute additional payloads. |
| T1059.003 Windows Command Shell |
MalwarezwShell | zwShell can launch command-line shells. |
| T1059.003 Windows Command Shell |
MalwareRising Sun | Rising Sun has executed commands using `cmd.exe /c “<command> > <%temp%>\AM<random>. tmp” 2>&1`. |
| T1059.003 Windows Command Shell |
MalwareShimRat | ShimRat can be issued a command shell function from the C2. |
| T1059.003 Windows Command Shell |
MalwareFlagpro | Flagpro can use `cmd.exe` to execute commands received from C2. |
| T1059.003 Windows Command Shell |
MalwareHi-Zor | Hi-Zor has the ability to create a reverse shell. |
| T1059.003 Windows Command Shell |
MalwareChina Chopper | China Chopper's server component is capable of opening a command terminal. |
| T1059.003 Windows Command Shell |
MalwareCALENDAR | CALENDAR has a command to run cmd.exe to execute commands. |
| T1059.003 Windows Command Shell |
MalwareGoldMax | GoldMax can spawn a command shell, and execute native commands. |
| T1059.003 Windows Command Shell |
MalwareKeyBoy | KeyBoy can launch interactive shells for communicating with the victim machine. |
| T1059.003 Windows Command Shell |
MalwareAnchor | Anchor has used cmd.exe to run its self deletion routine. |
| T1059.003 Windows Command Shell |
MalwarePteranodon | Pteranodon can use `cmd.exe` for execution on victim systems. |
| T1059.003 Windows Command Shell |
MalwareDarkTortilla | DarkTortilla can use `cmd.exe` to add registry keys for persistence. |
| T1059.003 Windows Command Shell |
MalwareRunningRAT | RunningRAT uses a batch file to kill a security program task and then attempts to remove itself. |
| T1059.003 Windows Command Shell |
MalwareBabuk | Babuk has the ability to use the command line to control execution on compromised hosts. |
| T1059.003 Windows Command Shell |
MalwareDarkWatchman | DarkWatchman can use `cmd.exe` to execute commands. |
| T1059.003 Windows Command Shell |
MalwareBlackMould | BlackMould can run cmd.exe with parameters. |
| T1059.003 Windows Command Shell |
MalwarePlugX | PlugX allows actors to spawn a reverse shell on a victim. |
| T1059.003 Windows Command Shell |
MalwareBisonal | Bisonal has launched cmd.exe and used the ShellExecuteW() API function to execute commands on the system. |
| T1059.003 Windows Command Shell |
MalwareMultiLayer Wiper | MultiLayer Wiper uses a batch script launched via a scheduled task to delete Windows Event Logs. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.