Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1059.003 Windows Command Shell |
MalwareHikit | Hikit has the ability to create a remote shell and run given commands. |
| T1059.003 Windows Command Shell |
MalwareStrelaStealer | StrelaStealer has included BAT files in some instances for installation. |
| T1059.003 Windows Command Shell |
MalwareSakula | Sakula calls cmd.exe to run various DLL files via rundll32 and also to perform file cleanup. Sakula also has the capability to invoke a reverse shell. |
| T1059.003 Windows Command Shell |
MalwareTarrask | Tarrask may abuse the Windows schtasks command-line tool to create "hidden" scheduled tasks. |
| T1059.003 Windows Command Shell |
MalwareShark | Shark has the ability to use `CMD` to execute commands. |
| T1059.003 Windows Command Shell |
MalwareBazar | Bazar can launch cmd.exe to perform reconnaissance commands. |
| T1059.003 Windows Command Shell |
MalwareRATANKBA | RATANKBA uses cmd.exe to execute commands. |
| T1059.003 Windows Command Shell |
MalwarehcdLoader | hcdLoader provides command-line access to the compromised system. |
| T1059.003 Windows Command Shell |
MalwareMoonWind | MoonWind can execute commands via an interactive command shell. MoonWind uses batch scripts for various purposes, including to restart and uninstall itself. |
| T1059.003 Windows Command Shell |
MalwareRyuk | Ryuk has used |
| T1059.003 Windows Command Shell |
MalwareHermeticWiper | HermeticWiper can use `cmd.exe /Q/c move CSIDL_SYSTEM_DRIVE\temp\sys.tmp1 CSIDL_WINDOWS\policydefinitions\postgresql.exe 1> \\127.0.0.1\ADMIN$\_1636727589.6007507 2>&1` to deploy on an infected system. |
| T1059.003 Windows Command Shell |
MalwareABK | ABK has the ability to use cmd to run a Portable Executable (PE) on the compromised host. |
| T1059.003 Windows Command Shell |
Malwareccf32 | ccf32 has used `cmd.exe` for archiving data and deleting files. |
| T1059.003 Windows Command Shell |
MalwareKapeka | Kapeka allows for arbitrary Windows command execution. |
| T1059.003 Windows Command Shell |
MalwareLockBit 2.0 | LockBit 2.0 can use the Windows command shell for multiple post-compromise actions on objective. |
| T1059.003 Windows Command Shell |
MalwareZebrocy | Zebrocy uses cmd.exe to execute commands on the system. |
| T1059.003 Windows Command Shell |
MalwareCobalt Strike | Cobalt Strike uses a command-line interface to interact with systems. |
| T1059.003 Windows Command Shell |
MalwareSampleCheck5000 | SampleCheck5000 can call cmd.exe to execute C2 command line strings. |
| T1059.003 Windows Command Shell |
MalwareEvilBunny | EvilBunny has an integrated scripting engine to download and execute Lua scripts. |
| T1059.003 Windows Command Shell |
MalwareCobian RAT | Cobian RAT can launch a remote command shell interface for executing commands. |
| T1059.003 Windows Command Shell |
MalwareHotCroissant | HotCroissant can remotely open applications on the infected host with the |
| T1059.003 Windows Command Shell |
MalwareServHelper | ServHelper can execute shell commands against cmd. |
| T1059.003 Windows Command Shell |
MalwareJCry | JCry has used |
| T1059.003 Windows Command Shell |
MalwareREvil | REvil can use the Windows command line to delete volume shadow copies and disable recovery. |
| T1059.003 Windows Command Shell |
MalwareSamurai | Samurai can use a remote command module for execution via the Windows command line. |
| T1059.003 Windows Command Shell |
MalwareMilan | Milan can use `cmd.exe` for discovery actions on a targeted system. |
| T1059.003 Windows Command Shell |
MalwareOilBooster | OilBooster has the ability to execute shell commands and exfiltrate the results. |
| T1059.003 Windows Command Shell |
MalwareTaidoor | Taidoor can copy cmd.exe into the system temp folder. |
| T1059.003 Windows Command Shell |
MalwarePoisonIvy | PoisonIvy creates a backdoor through which remote attackers can open a command-line interface. |
| T1059.003 Windows Command Shell |
MalwareSeasalt | Seasalt uses cmd.exe to create a reverse shell on the infected endpoint. |
| T1059.003 Windows Command Shell |
MalwareNanoCore | NanoCore can open a remote command-line interface and execute commands. NanoCore uses JavaScript files. |
| T1059.003 Windows Command Shell |
MalwarePLEAD | PLEAD has the ability to execute shell commands on the compromised host. |
| T1059.003 Windows Command Shell |
MalwareIPsec Helper | IPsec Helper can run arbitrary commands passed to it through |
| T1059.003 Windows Command Shell |
MalwareDaserf | Daserf can execute shell commands. |
| T1059.003 Windows Command Shell |
MalwareCardinal RAT | Cardinal RAT can execute commands. |
| T1059.003 Windows Command Shell |
MalwareDanBot | DanBot has the ability to execute arbitrary commands via `cmd.exe`. |
| T1059.003 Windows Command Shell |
MalwareBISCUIT | BISCUIT has a command to launch a command shell on the system. |
| T1059.003 Windows Command Shell |
MalwarePisloader | Pisloader uses cmd.exe to set the Registry Run key value. It also has a command to spawn a command shell. |
| T1059.003 Windows Command Shell |
MalwareGoldenSpy | GoldenSpy can execute remote commands via the command-line interface. |
| T1059.003 Windows Command Shell |
MalwareGold Dragon | Gold Dragon uses cmd.exe to execute commands for discovery. |
| T1059.003 Windows Command Shell |
MalwareRGDoor | RGDoor uses cmd.exe to execute commands on the victim’s machine. |
| T1059.003 Windows Command Shell |
MalwareHARDRAIN | HARDRAIN uses cmd.exe to execute |
| T1059.003 Windows Command Shell |
MalwareRevenge RAT | Revenge RAT uses cmd.exe to execute commands and run scripts on the victim's machine. |
| T1059.003 Windows Command Shell |
MalwareFunnyDream | FunnyDream can use `cmd.exe` for execution on remote hosts. |
| T1059.003 Windows Command Shell |
MalwareROADSWEEP | ROADSWEEP can open cmd.exe to enable command execution. |
| T1059.003 Windows Command Shell |
MalwareMore_eggs | More_eggs has used cmd.exe for execution. |
| T1059.003 Windows Command Shell |
MalwareTinyZBot | TinyZBot supports execution from the command-line. |
| T1059.003 Windows Command Shell |
MalwareOutSteel | OutSteel has used `cmd.exe` to scan a compromised host for specific file extensions. |
| T1059.003 Windows Command Shell |
MalwareBackConfig | BackConfig can download and run batch files to execute commands on a compromised host. |
| T1059.003 Windows Command Shell |
MalwareDEADEYE | DEADEYE can run `cmd /c copy /y /b C:\Users\public\syslog_6-*.dat C:\Users\public\syslog.dll` to combine separated sections of code into a single DLL prior to execution. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.