Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1059.003 Windows Command Shell |
MalwarePHOREAL | PHOREAL is capable of creating reverse shell. |
| T1059.003 Windows Command Shell |
MalwareLizar | Lizar has a command to open the command-line on the infected system. |
| T1059.003 Windows Command Shell |
MalwareDtrack | Dtrack has used |
| T1059.003 Windows Command Shell |
MalwareH1N1 | H1N1 kills and disables services by using cmd.exe. |
| T1059.003 Windows Command Shell |
MalwareSeth-Locker | Seth-Locker can execute commands via the command line shell. |
| T1059.003 Windows Command Shell |
MalwareLoudMiner | LoudMiner used a batch script to run the Linux virtual machine as a service. |
| T1059.003 Windows Command Shell |
MalwareBACKSPACE | Adversaries can direct BACKSPACE to execute from the command line on infected hosts, or have BACKSPACE create a reverse shell. |
| T1059.003 Windows Command Shell |
MalwareUPPERCUT | UPPERCUT uses cmd.exe to execute commands on the victim’s machine. |
| T1059.003 Windows Command Shell |
MalwareADVSTORESHELL | ADVSTORESHELL can create a remote shell and run a given command. |
| T1059.003 Windows Command Shell |
MalwareStrifeWater | StrifeWater can execute shell commands using `cmd.exe`. |
| T1059.003 Windows Command Shell |
MalwareMivast | Mivast has the capability to open a remote shell and run basic commands. |
| T1059.003 Windows Command Shell |
MalwareHiddenWasp | HiddenWasp uses a script to automate tasks on the victim's machine and to assist in execution. |
| T1059.003 Windows Command Shell |
MalwareWarzoneRAT | WarzoneRAT can use `cmd.exe` to execute malicious code. |
| T1059.003 Windows Command Shell |
MalwareSLOTHFULMEDIA | SLOTHFULMEDIA can open a command line to execute commands. |
| T1059.003 Windows Command Shell |
MalwareSmall Sieve | Small Sieve can use `cmd.exe` to execute commands on a victim's system. |
| T1059.003 Windows Command Shell |
MalwareHermeticWizard | HermeticWizard can use `cmd.exe` for execution on compromised hosts. |
| T1059.003 Windows Command Shell |
ToolCovenant | Covenant provides access to a Command Shell in Windows environments for follow-on command execution and tasking. |
| T1059.003 Windows Command Shell |
ToolDiskpart | Diskpart can execute a disk partition script file, which attempts to mount a virtual hard disk. Diskpart can also assign and mount virtual disks. |
| T1059.003 Windows Command Shell |
ToolSILENTTRINITY | SILENTTRINITY can use `cmd.exe` to enable lateral movement using DCOM. |
| T1059.003 Windows Command Shell |
ToolEmpire | Empire has modules for executing scripts. |
| T1059.003 Windows Command Shell |
ToolPcShare | PcShare can execute `cmd` commands on a compromised host. |
| T1059.003 Windows Command Shell |
ToolAsyncRAT | AsyncRAT can be deployed via batch script. |
| T1059.003 Windows Command Shell |
ToolBrute Ratel C4 | Brute Ratel C4 can use cmd.exe for execution. |
| T1059.003 Windows Command Shell |
ToolRemcos | Remcos can launch a remote command line to execute commands on the victim’s machine. |
| T1059.003 Windows Command Shell |
ToolOut1 | Out1 can use native command line for execution. |
| T1059.003 Windows Command Shell |
ToolMCMD | MCMD can launch a console process (cmd.exe) with redirected standard input and output. |
| T1059.003 Windows Command Shell |
Toolcmd | cmd is used to execute programs and other actions at the command-line interface. |
| T1059.003 Windows Command Shell |
ToolKoadic | Koadic can open an interactive command-shell to perform command line functions on victim machines. Koadic performs most of its operations using Windows Script Host (Jscript) and to run arbitrary shellcode. |
| T1059.003 Windows Command Shell |
ToolQuasarRAT | QuasarRAT can launch a remote shell to execute commands on the victim’s machine. |
| T1059.004 Unix Shell |
MalwareBRICKSTORM | BRICKSTORM has executed shell commands using `/bin/sh`. |
| T1059.004 Unix Shell |
MalwareCOATHANGER | COATHANGER provides a BusyBox reverse shell for command and control. |
| T1059.004 Unix Shell |
MalwareWindTail | WindTail can use the |
| T1059.004 Unix Shell |
MalwareExaramel for Linux | Exaramel for Linux has a command to execute a shell command on the system. |
| T1059.004 Unix Shell |
MalwareCASTLETAP | CASTLETAP has the ability to spawn BusyBox command shell in victim environments. |
| T1059.004 Unix Shell |
MalwareNETWIRE | NETWIRE has the ability to use |
| T1059.004 Unix Shell |
MalwareJ-magic | The J-magic agent is executed through a command line argument which specifies an interface and listening port. |
| T1059.004 Unix Shell |
MalwareGomir | Gomir reads command line arguments and parses them for functionality when executed from a Linux shell, and can execute arbitrary strings passed to it as shell commands. |
| T1059.004 Unix Shell |
MalwareBOLDMOVE | BOLDMOVE is capable of spawning a remote command shell. |
| T1059.004 Unix Shell |
MalwareTurian | Turian has the ability to use |
| T1059.004 Unix Shell |
MalwareHildegard | Hildegard has used shell scripts for execution. |
| T1059.004 Unix Shell |
MalwareCuckoo Stealer | Cuckoo Stealer can spawn a bash shell to enable execution on compromised hosts. |
| T1059.004 Unix Shell |
MalwareSkidmap | Skidmap has used |
| T1059.004 Unix Shell |
MalwareREPTILE | REPTILE can deploy components automatically with shell scripts. |
| T1059.004 Unix Shell |
MalwareDoki | Doki has executed shell scripts with /bin/sh. |
| T1059.004 Unix Shell |
MalwareFysbis | Fysbis has the ability to create and execute commands in a remote shell for CLI. |
| T1059.004 Unix Shell |
MalwareKazuar | Kazuar uses /bin/bash to execute commands on the victim’s machine. |
| T1059.004 Unix Shell |
MalwareGreen Lambert | Green Lambert can use shell scripts for execution, such as |
| T1059.004 Unix Shell |
MalwareSnappyTCP | SnappyTCP creates the reverse shell using a pthread spawning a bash shell. |
| T1059.004 Unix Shell |
MalwareChaos | Chaos provides a reverse shell connection on 8338/TCP, encrypted via AES. |
| T1059.004 Unix Shell |
MalwareAnchor | Anchor can execute payloads via shell scripting. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.