ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1059.003
Windows Command Shell
MalwareHikit

Hikit has the ability to create a remote shell and run given commands.

T1059.003
Windows Command Shell
MalwareStrelaStealer

StrelaStealer has included BAT files in some instances for installation.

T1059.003
Windows Command Shell
MalwareSakula

Sakula calls cmd.exe to run various DLL files via rundll32 and also to perform file cleanup. Sakula also has the capability to invoke a reverse shell.

T1059.003
Windows Command Shell
MalwareTarrask

Tarrask may abuse the Windows schtasks command-line tool to create "hidden" scheduled tasks.

T1059.003
Windows Command Shell
MalwareShark

Shark has the ability to use `CMD` to execute commands.

T1059.003
Windows Command Shell
MalwareBazar

Bazar can launch cmd.exe to perform reconnaissance commands.

T1059.003
Windows Command Shell
MalwareRATANKBA

RATANKBA uses cmd.exe to execute commands.

T1059.003
Windows Command Shell
MalwarehcdLoader

hcdLoader provides command-line access to the compromised system.

T1059.003
Windows Command Shell
MalwareMoonWind

MoonWind can execute commands via an interactive command shell. MoonWind uses batch scripts for various purposes, including to restart and uninstall itself.

T1059.003
Windows Command Shell
MalwareRyuk

Ryuk has used cmd.exe to create a Registry entry to establish persistence.

T1059.003
Windows Command Shell
MalwareHermeticWiper

HermeticWiper can use `cmd.exe /Q/c move CSIDL_SYSTEM_DRIVE\temp\sys.tmp1 CSIDL_WINDOWS\policydefinitions\postgresql.exe 1> \\127.0.0.1\ADMIN$\_1636727589.6007507 2>&1` to deploy on an infected system.

T1059.003
Windows Command Shell
MalwareABK

ABK has the ability to use cmd to run a Portable Executable (PE) on the compromised host.

T1059.003
Windows Command Shell
Malwareccf32

ccf32 has used `cmd.exe` for archiving data and deleting files.

T1059.003
Windows Command Shell
MalwareKapeka

Kapeka allows for arbitrary Windows command execution.

T1059.003
Windows Command Shell
MalwareLockBit 2.0

LockBit 2.0 can use the Windows command shell for multiple post-compromise actions on objective.

T1059.003
Windows Command Shell
MalwareZebrocy

Zebrocy uses cmd.exe to execute commands on the system.

T1059.003
Windows Command Shell
MalwareCobalt Strike

Cobalt Strike uses a command-line interface to interact with systems.

T1059.003
Windows Command Shell
MalwareSampleCheck5000

SampleCheck5000 can call cmd.exe to execute C2 command line strings.

T1059.003
Windows Command Shell
MalwareEvilBunny

EvilBunny has an integrated scripting engine to download and execute Lua scripts.

T1059.003
Windows Command Shell
MalwareCobian RAT

Cobian RAT can launch a remote command shell interface for executing commands.

T1059.003
Windows Command Shell
MalwareHotCroissant

HotCroissant can remotely open applications on the infected host with the ShellExecuteA command.

T1059.003
Windows Command Shell
MalwareServHelper

ServHelper can execute shell commands against cmd.

T1059.003
Windows Command Shell
MalwareJCry

JCry has used cmd.exe to launch PowerShell.

T1059.003
Windows Command Shell
MalwareREvil

REvil can use the Windows command line to delete volume shadow copies and disable recovery.

T1059.003
Windows Command Shell
MalwareSamurai

Samurai can use a remote command module for execution via the Windows command line.

T1059.003
Windows Command Shell
MalwareMilan

Milan can use `cmd.exe` for discovery actions on a targeted system.

T1059.003
Windows Command Shell
MalwareOilBooster

OilBooster has the ability to execute shell commands and exfiltrate the results.

T1059.003
Windows Command Shell
MalwareTaidoor

Taidoor can copy cmd.exe into the system temp folder.

T1059.003
Windows Command Shell
MalwarePoisonIvy

PoisonIvy creates a backdoor through which remote attackers can open a command-line interface.

T1059.003
Windows Command Shell
MalwareSeasalt

Seasalt uses cmd.exe to create a reverse shell on the infected endpoint.

T1059.003
Windows Command Shell
MalwareNanoCore

NanoCore can open a remote command-line interface and execute commands. NanoCore uses JavaScript files.

T1059.003
Windows Command Shell
MalwarePLEAD

PLEAD has the ability to execute shell commands on the compromised host.

T1059.003
Windows Command Shell
MalwareIPsec Helper

IPsec Helper can run arbitrary commands passed to it through cmd.exe.

T1059.003
Windows Command Shell
MalwareDaserf

Daserf can execute shell commands.

T1059.003
Windows Command Shell
MalwareCardinal RAT

Cardinal RAT can execute commands.

T1059.003
Windows Command Shell
MalwareDanBot

DanBot has the ability to execute arbitrary commands via `cmd.exe`.

T1059.003
Windows Command Shell
MalwareBISCUIT

BISCUIT has a command to launch a command shell on the system.

T1059.003
Windows Command Shell
MalwarePisloader

Pisloader uses cmd.exe to set the Registry Run key value. It also has a command to spawn a command shell.

T1059.003
Windows Command Shell
MalwareGoldenSpy

GoldenSpy can execute remote commands via the command-line interface.

T1059.003
Windows Command Shell
MalwareGold Dragon

Gold Dragon uses cmd.exe to execute commands for discovery.

T1059.003
Windows Command Shell
MalwareRGDoor

RGDoor uses cmd.exe to execute commands on the victim’s machine.

T1059.003
Windows Command Shell
MalwareHARDRAIN

HARDRAIN uses cmd.exe to execute netshcommands.

T1059.003
Windows Command Shell
MalwareRevenge RAT

Revenge RAT uses cmd.exe to execute commands and run scripts on the victim's machine.

T1059.003
Windows Command Shell
MalwareFunnyDream

FunnyDream can use `cmd.exe` for execution on remote hosts.

T1059.003
Windows Command Shell
MalwareROADSWEEP

ROADSWEEP can open cmd.exe to enable command execution.

T1059.003
Windows Command Shell
MalwareMore_eggs

More_eggs has used cmd.exe for execution.

T1059.003
Windows Command Shell
MalwareTinyZBot

TinyZBot supports execution from the command-line.

T1059.003
Windows Command Shell
MalwareOutSteel

OutSteel has used `cmd.exe` to scan a compromised host for specific file extensions.

T1059.003
Windows Command Shell
MalwareBackConfig

BackConfig can download and run batch files to execute commands on a compromised host.

T1059.003
Windows Command Shell
MalwareDEADEYE

DEADEYE can run `cmd /c copy /y /b C:\Users\public\syslog_6-*.dat C:\Users\public\syslog.dll` to combine separated sections of code into a single DLL prior to execution.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.