ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1059.001×

17 examples

TechniqueUsed byProcedure example
T1059.001
PowerShell
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group used PowerShell commands to explore the environment of compromised victims.

T1059.001
PowerShell
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors used PowerShell to execute attacker-controlled encoded commands.

T1059.001
PowerShell
CampaignFrankenstein

During Frankenstein, the threat actors used PowerShell to run a series of Base64-encoded commands that acted as a stager and enumerated hosts.

T1059.001
PowerShell
CampaignRedDelta Modified PlugX Infection Chain Operations

Mustang Panda used LNK files to execute PowerShell commands leading to eventual PlugX installation during RedDelta Modified PlugX Infection Chain Operations.

T1059.001
PowerShell
CampaignTriton Safety Instrumented System Attack

In the Triton Safety Instrumented System Attack, TEMP.Veles used a publicly available PowerShell-based tool, WMImplant.

T1059.001
PowerShell
CampaignC0018

During C0018, the threat actors used encoded PowerShell scripts for execution.

T1059.001
PowerShell
CampaignC0021

During C0021, the threat actors used obfuscated PowerShell to extract an encoded payload from within an .LNK file.

T1059.001
PowerShell
CampaignJuicy Mix

During Juicy Mix, OilRig used a PowerShell script to steal credentials.

T1059.001
PowerShell
CampaignHomeLand Justice

During HomeLand Justice, threat actors used PowerShell cmdlets New-MailboxSearch and Get-Recipient for discovery.

T1059.001
PowerShell
CampaignC0032

During the C0032 campaign, TEMP.Veles used PowerShell to perform timestomping.

T1059.001
PowerShell
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used PowerShell to create new tasks on remote machines, identify configuration settings, exfiltrate data, and execute other commands.

T1059.001
PowerShell
CampaignPikabot Distribution February 2024

Pikabot Distribution February 2024 passed execution from obfuscated JavaScript files to PowerShell scripts to download and install Pikabot.

T1059.001
PowerShell
CampaignOperation AkaiRyū

During Operation AkaiRyū, MirrorFace used PowerShell in execution chains to drop additional files such as embedded CAB files.

T1059.001
PowerShell
CampaignAPT28 Nearest Neighbor Campaign

During APT28 Nearest Neighbor Campaign, APT28 used PowerShell cmdlet Get-ChildItem to access credentials, among other PowerShell functions deployed.

T1059.001
PowerShell
Campaign2016 Ukraine Electric Power Attack

During the 2016 Ukraine Electric Power Attack, Sandworm Team used PowerShell scripts to run a credential harvesting tool in memory to evade defenses.

T1059.001
PowerShell
CampaignOperation Wocao

During Operation Wocao, threat actors used PowerShell on compromised systems.

T1059.001
PowerShell
Campaign2022 Ukraine Electric Power Attack

During the 2022 Ukraine Electric Power Attack, Sandworm Team utilized a PowerShell utility called TANKTRAP to spread and launch a wiper using Windows Group Policy.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.