Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1059 Command and Scripting Interpreter |
GroupAPT32 | APT32 has used COM scriptlets to download Cobalt Strike beacons. |
| T1059 Command and Scripting Interpreter |
GroupFIN6 | FIN6 has used scripting to iterate through a list of compromised PoS systems, copy data to a log file, and remove the original data files. |
| T1059 Command and Scripting Interpreter |
GroupFIN7 | FIN7 used SQL scripts to help perform tasks on the victim's machine. |
| T1059 Command and Scripting Interpreter |
GroupMustang Panda | Mustang Panda has utilized meterpreter shellcode. |
| T1059 Command and Scripting Interpreter |
GroupAPT39 | APT39 has utilized custom scripts to perform internal reconnaissance. |
| T1059 Command and Scripting Interpreter |
GroupAPT37 | APT37 has used Ruby scripts to execute payloads. |
| T1059 Command and Scripting Interpreter |
GroupOilRig | OilRig has used various types of scripting for execution. |
| T1059 Command and Scripting Interpreter |
GroupWindigo | Windigo has used a Perl script for information gathering. |
| T1059 Command and Scripting Interpreter |
GroupKe3chang | Malware used by Ke3chang can run commands on the command-line interface. |
| T1059 Command and Scripting Interpreter |
GroupSaint Bear | Saint Bear has used the Windows Script Host (wscript) to execute intermediate files written to victim machines. |
| T1059 Command and Scripting Interpreter |
GroupWinter Vivern | Winter Vivern used XLM 4.0 macros for initial code execution for malicious document files. |
| T1059 Command and Scripting Interpreter |
GroupFIN5 | FIN5 scans processes on all victim systems in the environment and uses automated scripts to pull back the results. |
| T1059 Command and Scripting Interpreter |
GroupStealth Falcon | Stealth Falcon malware uses WMI to script data collection and command execution on the victim. |
| T1059 Command and Scripting Interpreter |
GroupWhitefly | Whitefly has used a simple remote shell tool that will call back to the C2 server and wait for commands. |
| T1059 Command and Scripting Interpreter |
GroupFox Kitten | Fox Kitten has used a Perl reverse shell to communicate with C2. |
| T1059 Command and Scripting Interpreter |
GroupAPT19 | APT19 downloaded and launched code within a SCT file. |
| T1059 Command and Scripting Interpreter |
MalwareNICECURL | NICECURL has provided an arbitrary command execution interface. |
| T1059 Command and Scripting Interpreter |
MalwareGet2 | Get2 has the ability to run executables with command-line arguments. |
| T1059 Command and Scripting Interpreter |
MalwareVersaMem | VersaMem was delivered as a Java Archive (JAR) that runs by attaching itself to the Apache Tomcat Java servlet and web server. |
| T1059 Command and Scripting Interpreter |
MalwareZeus Panda | Zeus Panda can launch remote scripts on the victim’s machine. |
| T1059 Command and Scripting Interpreter |
MalwareMatryoshka | Matryoshka is capable of providing Meterpreter shell access. |
| T1059 Command and Scripting Interpreter |
MalwareP.A.S. Webshell | P.A.S. Webshell has the ability to create reverse shells with Perl scripts. |
| T1059 Command and Scripting Interpreter |
MalwareWINERACK | WINERACK can create a reverse shell that utilizes statically-linked Wine cmd.exe code to emulate Windows command prompt commands. |
| T1059 Command and Scripting Interpreter |
MalwareBonadan | Bonadan can create bind and reverse shells on the infected system. |
| T1059 Command and Scripting Interpreter |
MalwareRaspberry Robin | Raspberry Robin variants can be delivered via highly obfuscated Windows Script Files (WSF) for initial execution. |
| T1059 Command and Scripting Interpreter |
MalwareDarkComet | DarkComet can execute various types of scripts on the victim’s machine. |
| T1059 Command and Scripting Interpreter |
MalwareMuddyViper | MuddyViper has launched a reverse shell using a provided command line. |
| T1059 Command and Scripting Interpreter |
MalwareBandook | Bandook can support commands to execute Java-based payloads. |
| T1059 Command and Scripting Interpreter |
Malwaregh0st RAT | gh0st RAT is able to open a remote shell to execute commands. |
| T1059 Command and Scripting Interpreter |
MalwareSpeakUp | SpeakUp uses Perl scripts. |
| T1059 Command and Scripting Interpreter |
MalwareKessel | Kessel can create a reverse shell between the infected host and a specified system. |
| T1059 Command and Scripting Interpreter |
MalwareCHOPSTICK | CHOPSTICK is capable of performing remote command execution. |
| T1059 Command and Scripting Interpreter |
MalwareSLIGHTPULSE | SLIGHTPULSE contains functionality to execute arbitrary commands passed to it. |
| T1059 Command and Scripting Interpreter |
MalwareStarProxy | StarProxy has used the command line for execution of commands. |
| T1059 Command and Scripting Interpreter |
MalwareFIVEHANDS | FIVEHANDS can receive a command line argument to limit file encryption to specified directories. |
| T1059 Command and Scripting Interpreter |
ToolEmpire | Empire uses a command-line interface to interact with systems. |
| T1059 Command and Scripting Interpreter |
ToolImminent Monitor | Imminent Monitor has a CommandPromptPacket and ScriptPacket module(s) for creating a remote shell and executing scripts. |
| T1059 Command and Scripting Interpreter |
ToolDonut | Donut can generate shellcode outputs that execute via Ruby. |
| T1059 Command and Scripting Interpreter |
MalwareZeroCleare | ZeroCleare can receive command line arguments from an operator to corrupt the file system using the RawDisk driver. |
| T1059.001 PowerShell |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group used PowerShell commands to explore the environment of compromised victims. |
| T1059.001 PowerShell |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors used PowerShell to execute attacker-controlled encoded commands. |
| T1059.001 PowerShell |
CampaignFrankenstein | During Frankenstein, the threat actors used PowerShell to run a series of Base64-encoded commands that acted as a stager and enumerated hosts. |
| T1059.001 PowerShell |
CampaignRedDelta Modified PlugX Infection Chain Operations | Mustang Panda used LNK files to execute PowerShell commands leading to eventual PlugX installation during RedDelta Modified PlugX Infection Chain Operations. |
| T1059.001 PowerShell |
CampaignTriton Safety Instrumented System Attack | In the Triton Safety Instrumented System Attack, TEMP.Veles used a publicly available PowerShell-based tool, WMImplant. |
| T1059.001 PowerShell |
CampaignC0018 | During C0018, the threat actors used encoded PowerShell scripts for execution. |
| T1059.001 PowerShell |
CampaignC0021 | During C0021, the threat actors used obfuscated PowerShell to extract an encoded payload from within an .LNK file. |
| T1059.001 PowerShell |
CampaignJuicy Mix | During Juicy Mix, OilRig used a PowerShell script to steal credentials. |
| T1059.001 PowerShell |
CampaignHomeLand Justice | During HomeLand Justice, threat actors used PowerShell cmdlets New-MailboxSearch and Get-Recipient for discovery. |
| T1059.001 PowerShell |
CampaignC0032 | During the C0032 campaign, TEMP.Veles used PowerShell to perform timestomping. |
| T1059.001 PowerShell |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used PowerShell to create new tasks on remote machines, identify configuration settings, exfiltrate data, and execute other commands. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.