ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1059×

17 examples

TechniqueUsed byProcedure example
T1059
Command and Scripting Interpreter
GroupDragonfly

Dragonfly has used the command line for execution.

T1059
Command and Scripting Interpreter
GroupAPT32

APT32 has used COM scriptlets to download Cobalt Strike beacons.

T1059
Command and Scripting Interpreter
GroupFIN6

FIN6 has used scripting to iterate through a list of compromised PoS systems, copy data to a log file, and remove the original data files.

T1059
Command and Scripting Interpreter
GroupFIN7

FIN7 used SQL scripts to help perform tasks on the victim's machine.

T1059
Command and Scripting Interpreter
GroupMustang Panda

Mustang Panda has utilized meterpreter shellcode.

T1059
Command and Scripting Interpreter
GroupAPT39

APT39 has utilized custom scripts to perform internal reconnaissance.

T1059
Command and Scripting Interpreter
GroupAPT37

APT37 has used Ruby scripts to execute payloads.

T1059
Command and Scripting Interpreter
GroupOilRig

OilRig has used various types of scripting for execution.

T1059
Command and Scripting Interpreter
GroupWindigo

Windigo has used a Perl script for information gathering.

T1059
Command and Scripting Interpreter
GroupKe3chang

Malware used by Ke3chang can run commands on the command-line interface.

T1059
Command and Scripting Interpreter
GroupSaint Bear

Saint Bear has used the Windows Script Host (wscript) to execute intermediate files written to victim machines.

T1059
Command and Scripting Interpreter
GroupWinter Vivern

Winter Vivern used XLM 4.0 macros for initial code execution for malicious document files.

T1059
Command and Scripting Interpreter
GroupFIN5

FIN5 scans processes on all victim systems in the environment and uses automated scripts to pull back the results.

T1059
Command and Scripting Interpreter
GroupStealth Falcon

Stealth Falcon malware uses WMI to script data collection and command execution on the victim.

T1059
Command and Scripting Interpreter
GroupWhitefly

Whitefly has used a simple remote shell tool that will call back to the C2 server and wait for commands.

T1059
Command and Scripting Interpreter
GroupFox Kitten

Fox Kitten has used a Perl reverse shell to communicate with C2.

T1059
Command and Scripting Interpreter
GroupAPT19

APT19 downloaded and launched code within a SCT file.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.