ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1059.003
Windows Command Shell
MalwarePHOREAL

PHOREAL is capable of creating reverse shell.

T1059.003
Windows Command Shell
MalwareLizar

Lizar has a command to open the command-line on the infected system.

T1059.003
Windows Command Shell
MalwareDtrack

Dtrack has used cmd.exe to add a persistent service.

T1059.003
Windows Command Shell
MalwareH1N1

H1N1 kills and disables services by using cmd.exe.

T1059.003
Windows Command Shell
MalwareSeth-Locker

Seth-Locker can execute commands via the command line shell.

T1059.003
Windows Command Shell
MalwareLoudMiner

LoudMiner used a batch script to run the Linux virtual machine as a service.

T1059.003
Windows Command Shell
MalwareBACKSPACE

Adversaries can direct BACKSPACE to execute from the command line on infected hosts, or have BACKSPACE create a reverse shell.

T1059.003
Windows Command Shell
MalwareUPPERCUT

UPPERCUT uses cmd.exe to execute commands on the victim’s machine.

T1059.003
Windows Command Shell
MalwareADVSTORESHELL

ADVSTORESHELL can create a remote shell and run a given command.

T1059.003
Windows Command Shell
MalwareStrifeWater

StrifeWater can execute shell commands using `cmd.exe`.

T1059.003
Windows Command Shell
MalwareMivast

Mivast has the capability to open a remote shell and run basic commands.

T1059.003
Windows Command Shell
MalwareHiddenWasp

HiddenWasp uses a script to automate tasks on the victim's machine and to assist in execution.

T1059.003
Windows Command Shell
MalwareWarzoneRAT

WarzoneRAT can use `cmd.exe` to execute malicious code.

T1059.003
Windows Command Shell
MalwareSLOTHFULMEDIA

SLOTHFULMEDIA can open a command line to execute commands.

T1059.003
Windows Command Shell
MalwareSmall Sieve

Small Sieve can use `cmd.exe` to execute commands on a victim's system.

T1059.003
Windows Command Shell
MalwareHermeticWizard

HermeticWizard can use `cmd.exe` for execution on compromised hosts.

T1059.003
Windows Command Shell
ToolCovenant

Covenant provides access to a Command Shell in Windows environments for follow-on command execution and tasking.

T1059.003
Windows Command Shell
ToolDiskpart

Diskpart can execute a disk partition script file, which attempts to mount a virtual hard disk. Diskpart can also assign and mount virtual disks.

T1059.003
Windows Command Shell
ToolSILENTTRINITY

SILENTTRINITY can use `cmd.exe` to enable lateral movement using DCOM.

T1059.003
Windows Command Shell
ToolEmpire

Empire has modules for executing scripts.

T1059.003
Windows Command Shell
ToolPcShare

PcShare can execute `cmd` commands on a compromised host.

T1059.003
Windows Command Shell
ToolAsyncRAT

AsyncRAT can be deployed via batch script.

T1059.003
Windows Command Shell
ToolBrute Ratel C4

Brute Ratel C4 can use cmd.exe for execution.

T1059.003
Windows Command Shell
ToolRemcos

Remcos can launch a remote command line to execute commands on the victim’s machine.

T1059.003
Windows Command Shell
ToolOut1

Out1 can use native command line for execution.

T1059.003
Windows Command Shell
ToolMCMD

MCMD can launch a console process (cmd.exe) with redirected standard input and output.

T1059.003
Windows Command Shell
Toolcmd

cmd is used to execute programs and other actions at the command-line interface.

T1059.003
Windows Command Shell
ToolKoadic

Koadic can open an interactive command-shell to perform command line functions on victim machines. Koadic performs most of its operations using Windows Script Host (Jscript) and to run arbitrary shellcode.

T1059.003
Windows Command Shell
ToolQuasarRAT

QuasarRAT can launch a remote shell to execute commands on the victim’s machine.

T1059.004
Unix Shell
MalwareBRICKSTORM

BRICKSTORM has executed shell commands using `/bin/sh`.

T1059.004
Unix Shell
MalwareCOATHANGER

COATHANGER provides a BusyBox reverse shell for command and control.

T1059.004
Unix Shell
MalwareWindTail

WindTail can use the open command to execute an application.

T1059.004
Unix Shell
MalwareExaramel for Linux

Exaramel for Linux has a command to execute a shell command on the system.

T1059.004
Unix Shell
MalwareCASTLETAP

CASTLETAP has the ability to spawn BusyBox command shell in victim environments.

T1059.004
Unix Shell
MalwareNETWIRE

NETWIRE has the ability to use /bin/bash and /bin/sh to execute commands.

T1059.004
Unix Shell
MalwareJ-magic

The J-magic agent is executed through a command line argument which specifies an interface and listening port.

T1059.004
Unix Shell
MalwareGomir

Gomir reads command line arguments and parses them for functionality when executed from a Linux shell, and can execute arbitrary strings passed to it as shell commands.

T1059.004
Unix Shell
MalwareBOLDMOVE

BOLDMOVE is capable of spawning a remote command shell.

T1059.004
Unix Shell
MalwareTurian

Turian has the ability to use /bin/sh to execute commands.

T1059.004
Unix Shell
MalwareHildegard

Hildegard has used shell scripts for execution.

T1059.004
Unix Shell
MalwareCuckoo Stealer

Cuckoo Stealer can spawn a bash shell to enable execution on compromised hosts.

T1059.004
Unix Shell
MalwareSkidmap

Skidmap has used pm.sh to download and install its main payload.

T1059.004
Unix Shell
MalwareREPTILE

REPTILE can deploy components automatically with shell scripts.

T1059.004
Unix Shell
MalwareDoki

Doki has executed shell scripts with /bin/sh.

T1059.004
Unix Shell
MalwareFysbis

Fysbis has the ability to create and execute commands in a remote shell for CLI.

T1059.004
Unix Shell
MalwareKazuar

Kazuar uses /bin/bash to execute commands on the victim’s machine.

T1059.004
Unix Shell
MalwareGreen Lambert

Green Lambert can use shell scripts for execution, such as /bin/sh -c.

T1059.004
Unix Shell
MalwareSnappyTCP

SnappyTCP creates the reverse shell using a pthread spawning a bash shell.

T1059.004
Unix Shell
MalwareChaos

Chaos provides a reverse shell connection on 8338/TCP, encrypted via AES.

T1059.004
Unix Shell
MalwareAnchor

Anchor can execute payloads via shell scripting.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.