Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1059.001 PowerShell |
MalwarePOWERTON | POWERTON is written in PowerShell. |
| T1059.001 PowerShell |
MalwareQakBot | QakBot can use PowerShell to download and execute payloads. |
| T1059.001 PowerShell |
MalwareHancitor | Hancitor has used PowerShell to execute commands. |
| T1059.001 PowerShell |
MalwareHelminth | One version of Helminth uses a PowerShell script. |
| T1059.001 PowerShell |
MalwareDenis | Denis has a version written in PowerShell. |
| T1059.001 PowerShell |
MalwareAutoIt backdoor | AutoIt backdoor downloads a PowerShell script that decodes to a typical shellcode loader. |
| T1059.001 PowerShell |
MalwareJSS Loader | JSS Loader has the ability to download and execute PowerShell scripts. |
| T1059.001 PowerShell |
MalwareLizar | Lizar has used PowerShell scripts. |
| T1059.001 PowerShell |
MalwareWarzoneRAT | WarzoneRAT can use PowerShell to download files and execute commands. |
| T1059.001 PowerShell |
ToolCovenant | Covenant can create PowerShell-based launchers for Grunt installation. |
| T1059.001 PowerShell |
ToolBloodHound | BloodHound can use PowerShell to pull Active Directory information from the target environment. |
| T1059.001 PowerShell |
ToolSliver | Sliver has built-in functionality to launch a Powershell command prompt. |
| T1059.001 PowerShell |
ToolSILENTTRINITY | SILENTTRINITY can use PowerShell to execute commands. |
| T1059.001 PowerShell |
ToolPowerSploit | PowerSploit modules are written in and executed via PowerShell. |
| T1059.001 PowerShell |
ToolAADInternals | AADInternals is written and executed via PowerShell. |
| T1059.001 PowerShell |
ToolEmpire | Empire leverages PowerShell for the majority of its client-side agent tasks. Empire also contains the ability to conduct PowerShell remoting with the |
| T1059.001 PowerShell |
ToolConnectWise | ConnectWise can be used to execute PowerShell commands on target machines. |
| T1059.001 PowerShell |
ToolDonut | Donut can generate shellcode outputs that execute via PowerShell. |
| T1059.001 PowerShell |
ToolCrackMapExec | CrackMapExec can execute PowerShell commands via WMI. |
| T1059.001 PowerShell |
ToolKoadic | Koadic has used PowerShell to establish persistence. |
| T1059.001 PowerShell |
ToolPupy | Pupy has a module for loading and executing PowerShell scripts. |
| T1059.001 PowerShell |
MalwareZeroCleare | ZeroCleare can use a malicious PowerShell script to bypass Windows controls. |
| T1059.002 AppleScript |
MalwaremacOS.OSAMiner | macOS.OSAMiner has used `osascript` to call itself via the `do shell script` command in the Launch Agent `.plist` file. |
| T1059.002 AppleScript |
MalwareCuckoo Stealer | Cuckoo Stealer can use osascript to generate a password-stealing prompt, duplicate files and folders, and set environmental variables. |
| T1059.002 AppleScript |
MalwareThiefQuest | ThiefQuest uses AppleScript's |
| T1059.002 AppleScript |
MalwareBundlore | Bundlore can use AppleScript to inject malicious JavaScript into a browser. |
| T1059.002 AppleScript |
MalwareGlassWorm | GlassWorm has utilized AppleScript to include `set keychainPassword to do shell script` to execute shell command that retrieves passwords from the macOS keychain. |
| T1059.002 AppleScript |
MalwareDok | Dok uses AppleScript to create a login item for persistence. |
| T1059.003 Windows Command Shell |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group launched malicious DLL files, created new folders, and renamed folders with the use of the Windows command shell. |
| T1059.003 Windows Command Shell |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors utilized `cmd.exe` and batch scripts within the victim environment. |
| T1059.003 Windows Command Shell |
CampaignFrankenstein | During Frankenstein, the threat actors ran a command script to set up persistence as a scheduled task named "WinUpdate", as well as other encoded commands from the command-line |
| T1059.003 Windows Command Shell |
CampaignOperation Honeybee | During Operation Honeybee, various implants used batch scripting and `cmd.exe` for execution. |
| T1059.003 Windows Command Shell |
CampaignWater Curupira Pikabot Distribution | Water Curupira Pikabot Distribution installation via JavaScript will launch follow-on commands via cmd.exe. |
| T1059.003 Windows Command Shell |
CampaignOperation Digital Eye | During Operation Digital Eye, threat actors used `cmd.exe` as a default method of execution for a custom version of Mimikatz named bK2o.exe. |
| T1059.003 Windows Command Shell |
CampaignC0015 | During C0015, the threat actors used `cmd.exe` to execute commands and run malicious binaries. |
| T1059.003 Windows Command Shell |
CampaignHomeLand Justice | During HomeLand Justice, threat actors used Windows batch files for persistence and execution. |
| T1059.003 Windows Command Shell |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used `cmd.exe` to execute commands on remote machines. |
| T1059.003 Windows Command Shell |
CampaignOperation AkaiRyū | During Operation AkaiRyū, MirrorFace used `cmd.exe` to run PowerShell commands to drop additional files on the compromised host. |
| T1059.003 Windows Command Shell |
CampaignFunnyDream | During FunnyDream, the threat actors used `cmd.exe` to execute the wmiexec.vbs script. |
| T1059.003 Windows Command Shell |
CampaignOperation CuckooBees | During Operation CuckooBees, the threat actors used batch scripts to perform reconnaissance. |
| T1059.003 Windows Command Shell |
CampaignAPT28 Nearest Neighbor Campaign | During APT28 Nearest Neighbor Campaign, APT28 used |
| T1059.003 Windows Command Shell |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries leveraged PsExec to run `cmd.exe` commands on multiple victim machines. |
| T1059.003 Windows Command Shell |
Campaign2016 Ukraine Electric Power Attack | During the 2016 Ukraine Electric Power Attack, Sandworm Team used the `xp_cmdshell` command in MS-SQL. |
| T1059.003 Windows Command Shell |
CampaignNight Dragon | During Night Dragon, threat actors used zwShell to establish full remote control of the connected machine and run command-line shells. |
| T1059.003 Windows Command Shell |
CampaignOperation Wocao | During Operation Wocao, threat actors spawned a new `cmd.exe` process to execute commands. |
| T1059.003 Windows Command Shell |
CampaignC0017 | During C0017, APT41 used `cmd.exe` to execute reconnaissance commands. |
| T1059.003 Windows Command Shell |
GroupAPT38 | APT38 has used a command-line tunneler, NACHOCHEESE, to give them shell access to a victim’s machine. Additionally, APT38 has used batch scripts. |
| T1059.003 Windows Command Shell |
GroupIndrik Spider | Indrik Spider has used batch scripts on victim's machines. |
| T1059.003 Windows Command Shell |
GroupBlackByte | BlackByte executed ransomware using the Windows command shell. |
| T1059.003 Windows Command Shell |
GroupGALLIUM | GALLIUM used the Windows command shell to execute commands. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.