Real-world descriptions of how a group, tool or campaign used a technique.
17 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1059.001 PowerShell |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group used PowerShell commands to explore the environment of compromised victims. |
| T1059.001 PowerShell |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors used PowerShell to execute attacker-controlled encoded commands. |
| T1059.001 PowerShell |
CampaignFrankenstein | During Frankenstein, the threat actors used PowerShell to run a series of Base64-encoded commands that acted as a stager and enumerated hosts. |
| T1059.001 PowerShell |
CampaignRedDelta Modified PlugX Infection Chain Operations | Mustang Panda used LNK files to execute PowerShell commands leading to eventual PlugX installation during RedDelta Modified PlugX Infection Chain Operations. |
| T1059.001 PowerShell |
CampaignTriton Safety Instrumented System Attack | In the Triton Safety Instrumented System Attack, TEMP.Veles used a publicly available PowerShell-based tool, WMImplant. |
| T1059.001 PowerShell |
CampaignC0018 | During C0018, the threat actors used encoded PowerShell scripts for execution. |
| T1059.001 PowerShell |
CampaignC0021 | During C0021, the threat actors used obfuscated PowerShell to extract an encoded payload from within an .LNK file. |
| T1059.001 PowerShell |
CampaignJuicy Mix | During Juicy Mix, OilRig used a PowerShell script to steal credentials. |
| T1059.001 PowerShell |
CampaignHomeLand Justice | During HomeLand Justice, threat actors used PowerShell cmdlets New-MailboxSearch and Get-Recipient for discovery. |
| T1059.001 PowerShell |
CampaignC0032 | During the C0032 campaign, TEMP.Veles used PowerShell to perform timestomping. |
| T1059.001 PowerShell |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used PowerShell to create new tasks on remote machines, identify configuration settings, exfiltrate data, and execute other commands. |
| T1059.001 PowerShell |
CampaignPikabot Distribution February 2024 | Pikabot Distribution February 2024 passed execution from obfuscated JavaScript files to PowerShell scripts to download and install Pikabot. |
| T1059.001 PowerShell |
CampaignOperation AkaiRyū | During Operation AkaiRyū, MirrorFace used PowerShell in execution chains to drop additional files such as embedded CAB files. |
| T1059.001 PowerShell |
CampaignAPT28 Nearest Neighbor Campaign | During APT28 Nearest Neighbor Campaign, APT28 used PowerShell cmdlet |
| T1059.001 PowerShell |
Campaign2016 Ukraine Electric Power Attack | During the 2016 Ukraine Electric Power Attack, Sandworm Team used PowerShell scripts to run a credential harvesting tool in memory to evade defenses. |
| T1059.001 PowerShell |
CampaignOperation Wocao | During Operation Wocao, threat actors used PowerShell on compromised systems. |
| T1059.001 PowerShell |
Campaign2022 Ukraine Electric Power Attack | During the 2022 Ukraine Electric Power Attack, Sandworm Team utilized a PowerShell utility called TANKTRAP to spread and launch a wiper using Windows Group Policy. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.