Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1059.001 PowerShell |
GroupDarkVishnya | DarkVishnya used PowerShell to create shellcode loaders. |
| T1059.001 PowerShell |
GroupRedCurl | RedCurl has used PowerShell to execute commands and to download malware. |
| T1059.001 PowerShell |
GroupStealth Falcon | Stealth Falcon malware uses PowerShell commands to perform various functions, including gathering system information via WMI and executing commands from its C2 server. |
| T1059.001 PowerShell |
GroupAPT29 | APT29 has used encoded PowerShell scripts uploaded to CozyCar installations to download and install SeaDuke. |
| T1059.001 PowerShell |
GroupCinnamon Tempest | Cinnamon Tempest has used PowerShell to communicate with C2, download files, and execute reconnaissance commands. |
| T1059.001 PowerShell |
GroupChimera | Chimera has used PowerShell scripts to execute malicious payloads and the DSInternals PowerShell module to make use of Active Directory features. |
| T1059.001 PowerShell |
GroupMedusa Group | Medusa Group has leveraged PowerShell for execution and defense evasion. Medusa Group has also utilized PowerShell to execute a bitsadmin transfer from file hosting site. |
| T1059.001 PowerShell |
GroupBRONZE BUTLER | BRONZE BUTLER has used PowerShell for execution. |
| T1059.001 PowerShell |
GroupDeep Panda | Deep Panda has used PowerShell scripts to download and execute programs in memory, without writing to disk. |
| T1059.001 PowerShell |
GroupEmber Bear | Ember Bear has used PowerShell commands to gather information from compromised systems, such as email servers. |
| T1059.001 PowerShell |
GroupLazyScripter | LazyScripter has used PowerShell scripts to execute malicious code. |
| T1059.001 PowerShell |
GroupToddyCat | ToddyCat has used Powershell scripts to perform post exploit collection. |
| T1059.001 PowerShell |
GroupAPT28 | APT28 downloads and executes PowerShell scripts and performs PowerShell commands. |
| T1059.001 PowerShell |
GroupAPT42 | APT42 has downloaded and executed PowerShell payloads. |
| T1059.001 PowerShell |
GroupAPT5 | APT5 has used PowerShell to accomplish tasks within targeted environments. |
| T1059.001 PowerShell |
GroupFox Kitten | Fox Kitten has used PowerShell scripts to access credential data. |
| T1059.001 PowerShell |
GroupAPT-C-36 | APT-C-36 has used PowerShell in malware execution including as part of fileless attack chains to download additional payloads. |
| T1059.001 PowerShell |
GroupTonto Team | Tonto Team has used PowerShell to download additional payloads. |
| T1059.001 PowerShell |
GroupGOLD SOUTHFIELD | GOLD SOUTHFIELD has staged and executed PowerShell scripts on compromised hosts. |
| T1059.001 PowerShell |
GroupLazarus Group | Lazarus Group has used PowerShell to execute commands and malicious code. |
| T1059.001 PowerShell |
GroupEarth Lusca | Earth Lusca has used PowerShell to execute commands. |
| T1059.001 PowerShell |
GroupSilence | Silence has used PowerShell to download and execute payloads. |
| T1059.001 PowerShell |
GroupThrip | Thrip leveraged PowerShell to run commands to download payloads, traverse the compromised networks, and carry out reconnaissance. |
| T1059.001 PowerShell |
GroupCobalt Group | Cobalt Group has used powershell.exe to download and execute scripts. |
| T1059.001 PowerShell |
GroupCopyKittens | CopyKittens has used PowerShell Empire. |
| T1059.001 PowerShell |
GroupWizard Spider | Wizard Spider has used macros to execute PowerShell scripts to download malware on victim's machines. It has also used PowerShell to execute commands and move laterally through a victim network. |
| T1059.001 PowerShell |
GroupMolerats | Molerats used PowerShell implants on target machines. |
| T1059.001 PowerShell |
GroupInception | Inception has used PowerShell to execute malicious commands and payloads. |
| T1059.001 PowerShell |
GroupVOID MANTICORE | VOID MANTICORE has utilized PowerShell to execute malware in victim environments. |
| T1059.001 PowerShell |
GroupPlay | Play has used Base64-encoded PowerShell scripts to disable Microsoft Defender. |
| T1059.001 PowerShell |
GroupHEXANE | HEXANE has used PowerShell-based tools and scripts for discovery and collection on compromised hosts. |
| T1059.001 PowerShell |
GroupDaggerfly | Daggerfly used PowerShell to download and execute remote-hosted files on victim systems. |
| T1059.001 PowerShell |
GroupWIRTE | WIRTE has used PowerShell for script execution. |
| T1059.001 PowerShell |
GroupMagic Hound | Magic Hound has used PowerShell for execution and privilege escalation. |
| T1059.001 PowerShell |
GroupThreat Group-3390 | Threat Group-3390 has used PowerShell for execution. |
| T1059.001 PowerShell |
GroupAPT33 | APT33 has utilized PowerShell to download files from the C2 server and run various scripts. |
| T1059.001 PowerShell |
GroupFIN10 | FIN10 uses PowerShell for execution as well as PowerShell Empire to establish persistence. |
| T1059.001 PowerShell |
GroupFIN8 | FIN8's malicious spearphishing payloads are executed as PowerShell. FIN8 has also used PowerShell for lateral movement and credential access. |
| T1059.001 PowerShell |
GroupFIN13 | FIN13 has used PowerShell commands to obtain DNS data from a compromised network. |
| T1059.001 PowerShell |
GroupAPT19 | APT19 used PowerShell commands to execute payloads. |
| T1059.001 PowerShell |
GroupNomadic Octopus | Nomadic Octopus has used PowerShell for execution. |
| T1059.001 PowerShell |
MalwareTrickBot | TrickBot has been known to use PowerShell to download new payloads, open documents, and upload data to command and control servers. |
| T1059.001 PowerShell |
MalwareBumblebee | Bumblebee can use PowerShell for execution. |
| T1059.001 PowerShell |
MalwareGRIFFON | GRIFFON has used PowerShell to execute the Meterpreter downloader TinyMet. |
| T1059.001 PowerShell |
MalwarePOWRUNER | POWRUNER is written in PowerShell. |
| T1059.001 PowerShell |
MalwareSharpStage | SharpStage can execute arbitrary commands with PowerShell. |
| T1059.001 PowerShell |
MalwareSardonic | Sardonic has the ability to execute PowerShell commands on a compromised machine. |
| T1059.001 PowerShell |
MalwareHALFBAKED | HALFBAKED can execute PowerShell scripts. |
| T1059.001 PowerShell |
MalwareTAMECAT | TAMECAT has used PowerShell to download and run additional content. |
| T1059.001 PowerShell |
MalwarePS1 | PS1 can utilize a PowerShell loader. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.