Real-world descriptions of how a group, tool or campaign used a technique.
17 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1059 Command and Scripting Interpreter |
GroupDragonfly | Dragonfly has used the command line for execution. |
| T1059 Command and Scripting Interpreter |
GroupAPT32 | APT32 has used COM scriptlets to download Cobalt Strike beacons. |
| T1059 Command and Scripting Interpreter |
GroupFIN6 | FIN6 has used scripting to iterate through a list of compromised PoS systems, copy data to a log file, and remove the original data files. |
| T1059 Command and Scripting Interpreter |
GroupFIN7 | FIN7 used SQL scripts to help perform tasks on the victim's machine. |
| T1059 Command and Scripting Interpreter |
GroupMustang Panda | Mustang Panda has utilized meterpreter shellcode. |
| T1059 Command and Scripting Interpreter |
GroupAPT39 | APT39 has utilized custom scripts to perform internal reconnaissance. |
| T1059 Command and Scripting Interpreter |
GroupAPT37 | APT37 has used Ruby scripts to execute payloads. |
| T1059 Command and Scripting Interpreter |
GroupOilRig | OilRig has used various types of scripting for execution. |
| T1059 Command and Scripting Interpreter |
GroupWindigo | Windigo has used a Perl script for information gathering. |
| T1059 Command and Scripting Interpreter |
GroupKe3chang | Malware used by Ke3chang can run commands on the command-line interface. |
| T1059 Command and Scripting Interpreter |
GroupSaint Bear | Saint Bear has used the Windows Script Host (wscript) to execute intermediate files written to victim machines. |
| T1059 Command and Scripting Interpreter |
GroupWinter Vivern | Winter Vivern used XLM 4.0 macros for initial code execution for malicious document files. |
| T1059 Command and Scripting Interpreter |
GroupFIN5 | FIN5 scans processes on all victim systems in the environment and uses automated scripts to pull back the results. |
| T1059 Command and Scripting Interpreter |
GroupStealth Falcon | Stealth Falcon malware uses WMI to script data collection and command execution on the victim. |
| T1059 Command and Scripting Interpreter |
GroupWhitefly | Whitefly has used a simple remote shell tool that will call back to the C2 server and wait for commands. |
| T1059 Command and Scripting Interpreter |
GroupFox Kitten | Fox Kitten has used a Perl reverse shell to communicate with C2. |
| T1059 Command and Scripting Interpreter |
GroupAPT19 | APT19 downloaded and launched code within a SCT file. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.