ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1059.001
PowerShell
MalwarePOWERTON

POWERTON is written in PowerShell.

T1059.001
PowerShell
MalwareQakBot

QakBot can use PowerShell to download and execute payloads.

T1059.001
PowerShell
MalwareHancitor

Hancitor has used PowerShell to execute commands.

T1059.001
PowerShell
MalwareHelminth

One version of Helminth uses a PowerShell script.

T1059.001
PowerShell
MalwareDenis

Denis has a version written in PowerShell.

T1059.001
PowerShell
MalwareAutoIt backdoor

AutoIt backdoor downloads a PowerShell script that decodes to a typical shellcode loader.

T1059.001
PowerShell
MalwareJSS Loader

JSS Loader has the ability to download and execute PowerShell scripts.

T1059.001
PowerShell
MalwareLizar

Lizar has used PowerShell scripts.

T1059.001
PowerShell
MalwareWarzoneRAT

WarzoneRAT can use PowerShell to download files and execute commands.

T1059.001
PowerShell
ToolCovenant

Covenant can create PowerShell-based launchers for Grunt installation.

T1059.001
PowerShell
ToolBloodHound

BloodHound can use PowerShell to pull Active Directory information from the target environment.

T1059.001
PowerShell
ToolSliver

Sliver has built-in functionality to launch a Powershell command prompt.

T1059.001
PowerShell
ToolSILENTTRINITY

SILENTTRINITY can use PowerShell to execute commands.

T1059.001
PowerShell
ToolPowerSploit

PowerSploit modules are written in and executed via PowerShell.

T1059.001
PowerShell
ToolAADInternals

AADInternals is written and executed via PowerShell.

T1059.001
PowerShell
ToolEmpire

Empire leverages PowerShell for the majority of its client-side agent tasks. Empire also contains the ability to conduct PowerShell remoting with the Invoke-PSRemoting module.

T1059.001
PowerShell
ToolConnectWise

ConnectWise can be used to execute PowerShell commands on target machines.

T1059.001
PowerShell
ToolDonut

Donut can generate shellcode outputs that execute via PowerShell.

T1059.001
PowerShell
ToolCrackMapExec

CrackMapExec can execute PowerShell commands via WMI.

T1059.001
PowerShell
ToolKoadic

Koadic has used PowerShell to establish persistence.

T1059.001
PowerShell
ToolPupy

Pupy has a module for loading and executing PowerShell scripts.

T1059.001
PowerShell
MalwareZeroCleare

ZeroCleare can use a malicious PowerShell script to bypass Windows controls.

T1059.002
AppleScript
MalwaremacOS.OSAMiner

macOS.OSAMiner has used `osascript` to call itself via the `do shell script` command in the Launch Agent `.plist` file.

T1059.002
AppleScript
MalwareCuckoo Stealer

Cuckoo Stealer can use osascript to generate a password-stealing prompt, duplicate files and folders, and set environmental variables.

T1059.002
AppleScript
MalwareThiefQuest

ThiefQuest uses AppleScript's osascript -e command to launch ThiefQuest's persistence via Launch Agent and Launch Daemon.

T1059.002
AppleScript
MalwareBundlore

Bundlore can use AppleScript to inject malicious JavaScript into a browser.

T1059.002
AppleScript
MalwareGlassWorm

GlassWorm has utilized AppleScript to include `set keychainPassword to do shell script` to execute shell command that retrieves passwords from the macOS keychain.

T1059.002
AppleScript
MalwareDok

Dok uses AppleScript to create a login item for persistence.

T1059.003
Windows Command Shell
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group launched malicious DLL files, created new folders, and renamed folders with the use of the Windows command shell.

T1059.003
Windows Command Shell
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors utilized `cmd.exe` and batch scripts within the victim environment.

T1059.003
Windows Command Shell
CampaignFrankenstein

During Frankenstein, the threat actors ran a command script to set up persistence as a scheduled task named "WinUpdate", as well as other encoded commands from the command-line

T1059.003
Windows Command Shell
CampaignOperation Honeybee

During Operation Honeybee, various implants used batch scripting and `cmd.exe` for execution.

T1059.003
Windows Command Shell
CampaignWater Curupira Pikabot Distribution

Water Curupira Pikabot Distribution installation via JavaScript will launch follow-on commands via cmd.exe.

T1059.003
Windows Command Shell
CampaignOperation Digital Eye

During Operation Digital Eye, threat actors used `cmd.exe` as a default method of execution for a custom version of Mimikatz named bK2o.exe.

T1059.003
Windows Command Shell
CampaignC0015

During C0015, the threat actors used `cmd.exe` to execute commands and run malicious binaries.

T1059.003
Windows Command Shell
CampaignHomeLand Justice

During HomeLand Justice, threat actors used Windows batch files for persistence and execution.

T1059.003
Windows Command Shell
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used `cmd.exe` to execute commands on remote machines.

T1059.003
Windows Command Shell
CampaignOperation AkaiRyū

During Operation AkaiRyū, MirrorFace used `cmd.exe` to run PowerShell commands to drop additional files on the compromised host.

T1059.003
Windows Command Shell
CampaignFunnyDream

During FunnyDream, the threat actors used `cmd.exe` to execute the wmiexec.vbs script.

T1059.003
Windows Command Shell
CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors used batch scripts to perform reconnaissance.

T1059.003
Windows Command Shell
CampaignAPT28 Nearest Neighbor Campaign

During APT28 Nearest Neighbor Campaign, APT28 used cmd.exe for execution.

T1059.003
Windows Command Shell
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries leveraged PsExec to run `cmd.exe` commands on multiple victim machines.

T1059.003
Windows Command Shell
Campaign2016 Ukraine Electric Power Attack

During the 2016 Ukraine Electric Power Attack, Sandworm Team used the `xp_cmdshell` command in MS-SQL.

T1059.003
Windows Command Shell
CampaignNight Dragon

During Night Dragon, threat actors used zwShell to establish full remote control of the connected machine and run command-line shells.

T1059.003
Windows Command Shell
CampaignOperation Wocao

During Operation Wocao, threat actors spawned a new `cmd.exe` process to execute commands.

T1059.003
Windows Command Shell
CampaignC0017

During C0017, APT41 used `cmd.exe` to execute reconnaissance commands.

T1059.003
Windows Command Shell
GroupAPT38

APT38 has used a command-line tunneler, NACHOCHEESE, to give them shell access to a victim’s machine. Additionally, APT38 has used batch scripts.

T1059.003
Windows Command Shell
GroupIndrik Spider

Indrik Spider has used batch scripts on victim's machines.

T1059.003
Windows Command Shell
GroupBlackByte

BlackByte executed ransomware using the Windows command shell.

T1059.003
Windows Command Shell
GroupGALLIUM

GALLIUM used the Windows command shell to execute commands.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.