ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1059
Command and Scripting Interpreter
GroupAPT32

APT32 has used COM scriptlets to download Cobalt Strike beacons.

T1059
Command and Scripting Interpreter
GroupFIN6

FIN6 has used scripting to iterate through a list of compromised PoS systems, copy data to a log file, and remove the original data files.

T1059
Command and Scripting Interpreter
GroupFIN7

FIN7 used SQL scripts to help perform tasks on the victim's machine.

T1059
Command and Scripting Interpreter
GroupMustang Panda

Mustang Panda has utilized meterpreter shellcode.

T1059
Command and Scripting Interpreter
GroupAPT39

APT39 has utilized custom scripts to perform internal reconnaissance.

T1059
Command and Scripting Interpreter
GroupAPT37

APT37 has used Ruby scripts to execute payloads.

T1059
Command and Scripting Interpreter
GroupOilRig

OilRig has used various types of scripting for execution.

T1059
Command and Scripting Interpreter
GroupWindigo

Windigo has used a Perl script for information gathering.

T1059
Command and Scripting Interpreter
GroupKe3chang

Malware used by Ke3chang can run commands on the command-line interface.

T1059
Command and Scripting Interpreter
GroupSaint Bear

Saint Bear has used the Windows Script Host (wscript) to execute intermediate files written to victim machines.

T1059
Command and Scripting Interpreter
GroupWinter Vivern

Winter Vivern used XLM 4.0 macros for initial code execution for malicious document files.

T1059
Command and Scripting Interpreter
GroupFIN5

FIN5 scans processes on all victim systems in the environment and uses automated scripts to pull back the results.

T1059
Command and Scripting Interpreter
GroupStealth Falcon

Stealth Falcon malware uses WMI to script data collection and command execution on the victim.

T1059
Command and Scripting Interpreter
GroupWhitefly

Whitefly has used a simple remote shell tool that will call back to the C2 server and wait for commands.

T1059
Command and Scripting Interpreter
GroupFox Kitten

Fox Kitten has used a Perl reverse shell to communicate with C2.

T1059
Command and Scripting Interpreter
GroupAPT19

APT19 downloaded and launched code within a SCT file.

T1059
Command and Scripting Interpreter
MalwareNICECURL

NICECURL has provided an arbitrary command execution interface.

T1059
Command and Scripting Interpreter
MalwareGet2

Get2 has the ability to run executables with command-line arguments.

T1059
Command and Scripting Interpreter
MalwareVersaMem

VersaMem was delivered as a Java Archive (JAR) that runs by attaching itself to the Apache Tomcat Java servlet and web server.

T1059
Command and Scripting Interpreter
MalwareZeus Panda

Zeus Panda can launch remote scripts on the victim’s machine.

T1059
Command and Scripting Interpreter
MalwareMatryoshka

Matryoshka is capable of providing Meterpreter shell access.

T1059
Command and Scripting Interpreter
MalwareP.A.S. Webshell

P.A.S. Webshell has the ability to create reverse shells with Perl scripts.

T1059
Command and Scripting Interpreter
MalwareWINERACK

WINERACK can create a reverse shell that utilizes statically-linked Wine cmd.exe code to emulate Windows command prompt commands.

T1059
Command and Scripting Interpreter
MalwareBonadan

Bonadan can create bind and reverse shells on the infected system.

T1059
Command and Scripting Interpreter
MalwareRaspberry Robin

Raspberry Robin variants can be delivered via highly obfuscated Windows Script Files (WSF) for initial execution.

T1059
Command and Scripting Interpreter
MalwareDarkComet

DarkComet can execute various types of scripts on the victim’s machine.

T1059
Command and Scripting Interpreter
MalwareMuddyViper

MuddyViper has launched a reverse shell using a provided command line.

T1059
Command and Scripting Interpreter
MalwareBandook

Bandook can support commands to execute Java-based payloads.

T1059
Command and Scripting Interpreter
Malwaregh0st RAT

gh0st RAT is able to open a remote shell to execute commands.

T1059
Command and Scripting Interpreter
MalwareSpeakUp

SpeakUp uses Perl scripts.

T1059
Command and Scripting Interpreter
MalwareKessel

Kessel can create a reverse shell between the infected host and a specified system.

T1059
Command and Scripting Interpreter
MalwareCHOPSTICK

CHOPSTICK is capable of performing remote command execution.

T1059
Command and Scripting Interpreter
MalwareSLIGHTPULSE

SLIGHTPULSE contains functionality to execute arbitrary commands passed to it.

T1059
Command and Scripting Interpreter
MalwareStarProxy

StarProxy has used the command line for execution of commands.

T1059
Command and Scripting Interpreter
MalwareFIVEHANDS

FIVEHANDS can receive a command line argument to limit file encryption to specified directories.

T1059
Command and Scripting Interpreter
ToolEmpire

Empire uses a command-line interface to interact with systems.

T1059
Command and Scripting Interpreter
ToolImminent Monitor

Imminent Monitor has a CommandPromptPacket and ScriptPacket module(s) for creating a remote shell and executing scripts.

T1059
Command and Scripting Interpreter
ToolDonut

Donut can generate shellcode outputs that execute via Ruby.

T1059
Command and Scripting Interpreter
MalwareZeroCleare

ZeroCleare can receive command line arguments from an operator to corrupt the file system using the RawDisk driver.

T1059.001
PowerShell
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group used PowerShell commands to explore the environment of compromised victims.

T1059.001
PowerShell
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors used PowerShell to execute attacker-controlled encoded commands.

T1059.001
PowerShell
CampaignFrankenstein

During Frankenstein, the threat actors used PowerShell to run a series of Base64-encoded commands that acted as a stager and enumerated hosts.

T1059.001
PowerShell
CampaignRedDelta Modified PlugX Infection Chain Operations

Mustang Panda used LNK files to execute PowerShell commands leading to eventual PlugX installation during RedDelta Modified PlugX Infection Chain Operations.

T1059.001
PowerShell
CampaignTriton Safety Instrumented System Attack

In the Triton Safety Instrumented System Attack, TEMP.Veles used a publicly available PowerShell-based tool, WMImplant.

T1059.001
PowerShell
CampaignC0018

During C0018, the threat actors used encoded PowerShell scripts for execution.

T1059.001
PowerShell
CampaignC0021

During C0021, the threat actors used obfuscated PowerShell to extract an encoded payload from within an .LNK file.

T1059.001
PowerShell
CampaignJuicy Mix

During Juicy Mix, OilRig used a PowerShell script to steal credentials.

T1059.001
PowerShell
CampaignHomeLand Justice

During HomeLand Justice, threat actors used PowerShell cmdlets New-MailboxSearch and Get-Recipient for discovery.

T1059.001
PowerShell
CampaignC0032

During the C0032 campaign, TEMP.Veles used PowerShell to perform timestomping.

T1059.001
PowerShell
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used PowerShell to create new tasks on remote machines, identify configuration settings, exfiltrate data, and execute other commands.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.