ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1059.001×

85 examples

TechniqueUsed byProcedure example
T1059.001
PowerShell
GroupAPT38

APT38 has used PowerShell to execute commands and other operational tasks.

T1059.001
PowerShell
GroupIndrik Spider

Indrik Spider has used PowerShell Empire for execution of malware.

T1059.001
PowerShell
GroupBlackByte

BlackByte used encoded PowerShell commands during operations. BlackByte has used remote PowerShell commands in victim networks.

T1059.001
PowerShell
GroupGALLIUM

GALLIUM used PowerShell for execution to assist in lateral movement as well as for dumping credentials stored on compromised machines.

T1059.001
PowerShell
GroupAPT3

APT3 has used PowerShell on victim systems to download and run payloads after exploitation.

T1059.001
PowerShell
GroupKimsuky

Kimsuky has executed a variety of PowerShell scripts including Invoke-Mimikatz. Kimsuky has also utilized PowerShell scripts for execution, persistence, and defense evasion. Kimsuky has leveraged PowerShell’s cmdlet `Expand-Archive` to extract contents of zip files into the same directory. Kimsuky has employed ClickFix type tactics enticing victims to copy and paste malicious PowerShell commands and scripts, where the scripts ultimately led to QuasarRAT.

T1059.001
PowerShell
GroupVolt Typhoon

Volt Typhoon has used PowerShell including for remote system discovery.

T1059.001
PowerShell
GroupPatchwork

Patchwork used PowerSploit to download payloads, run a reverse shell, and execute malware on the victim's machine.

T1059.001
PowerShell
GroupAPT41

APT41 leveraged PowerShell to deploy malware families in victims’ environments.

T1059.001
PowerShell
GroupDragonfly

Dragonfly has used PowerShell scripts for execution.

T1059.001
PowerShell
GroupGorgon Group

Gorgon Group malware can use PowerShell commands to download and execute a payload and open a decoy document on the victim’s machine.

T1059.001
PowerShell
GroupmenuPass

menuPass uses PowerSploit to inject shellcode into PowerShell.

T1059.001
PowerShell
GroupAPT32

APT32 has used PowerShell-based tools, PowerShell one-liners, and shellcode loaders for execution.

T1059.001
PowerShell
GroupHAFNIUM

HAFNIUM has used the Exchange Power Shell module Set-OabVirtualDirectoryPowerShell to export mailbox data.

T1059.001
PowerShell
GroupMuddyWater

MuddyWater has used PowerShell for execution.

T1059.001
PowerShell
GroupFIN6

FIN6 has used PowerShell to gain access to merchant's networks, and a Metasploit PowerShell module to download and execute shellcode and to set up a local listener.

T1059.001
PowerShell
GroupGamaredon Group

Gamaredon Group has used obfuscated PowerShell scripts for staging. Additionally, (LinkById : G0047) has used PowerShell based tools later in its attack chain. Additionally, Gamaredon Group has used the PowerShell cmdlet `Get-Command` to download and execute the next stage payload.

T1059.001
PowerShell
GroupGallmaker

Gallmaker used PowerShell to download additional payloads and for execution.

T1059.001
PowerShell
GroupStorm-1811

Storm-1811 has used PowerShell for multiple purposes, such as using PowerShell scripts executing in an infinite loop to create an SSH connection to a command and control server.

T1059.001
PowerShell
GroupTeamTNT

TeamTNT has executed PowerShell commands in batch scripts.

T1059.001
PowerShell
GroupFIN7

FIN7 used a PowerShell script to launch shellcode that retrieved an additional payload. Additionally, FIN7 has executed a custom obfuscation of the shellcode invoker in PowerSploit called POWERTRASH.

T1059.001
PowerShell
GroupSandworm Team

Sandworm Team has used PowerShell scripts to run a credential harvesting tool in memory to evade defenses.

T1059.001
PowerShell
GroupCURIUM

CURIUM has leveraged PowerShell scripts for initial process execution and data gathering in victim environments.

T1059.001
PowerShell
GroupSidewinder

Sidewinder has used PowerShell to drop and execute malware loaders.

T1059.001
PowerShell
GroupMustang Panda

Mustang Panda has used malicious PowerShell scripts to enable execution.

T1059.001
PowerShell
GroupScattered Spider

Scattered Spider has used the PowerShell cmdlet Get-ADUser.

T1059.001
PowerShell
GroupAPT39

APT39 has used PowerShell to execute malicious code.

T1059.001
PowerShell
GroupUNC3886

UNC3886 has used a PowerShell script to search memory dumps for credentials.

T1059.001
PowerShell
GroupTA2541

TA2541 has used PowerShell to download files and to inject into various Windows processes.

T1059.001
PowerShell
GroupAkira

Akira has used PowerShell scripts for credential harvesting and privilege escalation.

T1059.001
PowerShell
GroupOilRig

OilRig has used PowerShell scripts for execution, including use of a macro to run a PowerShell command to decode file contents.

T1059.001
PowerShell
GroupTA459

TA459 has used PowerShell for execution of a payload.

T1059.001
PowerShell
GroupAquatic Panda

Aquatic Panda has downloaded additional scripts and executed Base64 encoded commands in PowerShell.

T1059.001
PowerShell
GroupSaint Bear

Saint Bear relies extensively on PowerShell execution from malicious attachments and related content to retrieve and execute follow-on payloads.

T1059.001
PowerShell
GroupDarkHydrus

DarkHydrus leveraged PowerShell to download and execute additional scripts for execution.

T1059.001
PowerShell
GroupConfucius

Confucius has used PowerShell to execute malicious files and payloads.

T1059.001
PowerShell
GroupLeviathan

Leviathan has used PowerShell for execution.

T1059.001
PowerShell
GroupMoustachedBouncer

MoustachedBouncer has used plugins to execute PowerShell scripts.

T1059.001
PowerShell
GroupBlue Mockingbird

Blue Mockingbird has used PowerShell reverse TCP shells to issue interactive commands over a network connection.

T1059.001
PowerShell
GroupWinter Vivern

Winter Vivern passed execution from document macros to PowerShell scripts during initial access operations. Winter Vivern used batch scripts that called PowerShell commands as part of initial access and installation operations.

T1059.001
PowerShell
GroupTurla

Turla has used PowerShell to execute commands/scripts, in some cases via a custom executable or code from Empire's PSInject. Turla has also used PowerShell scripts to load and execute malware in memory.

T1059.001
PowerShell
GroupStorm-0501

Storm-0501 has leveraged PowerShell to execute commands and scripts.

T1059.001
PowerShell
GroupPoseidon Group

The Poseidon Group's Information Gathering Tool (IGT) includes PowerShell components.

T1059.001
PowerShell
GroupTA505

TA505 has used PowerShell to download and execute malware and reconnaissance scripts.

T1059.001
PowerShell
GroupDarkVishnya

DarkVishnya used PowerShell to create shellcode loaders.

T1059.001
PowerShell
GroupRedCurl

RedCurl has used PowerShell to execute commands and to download malware.

T1059.001
PowerShell
GroupStealth Falcon

Stealth Falcon malware uses PowerShell commands to perform various functions, including gathering system information via WMI and executing commands from its C2 server.

T1059.001
PowerShell
GroupAPT29

APT29 has used encoded PowerShell scripts uploaded to CozyCar installations to download and install SeaDuke.

T1059.001
PowerShell
GroupCinnamon Tempest

Cinnamon Tempest has used PowerShell to communicate with C2, download files, and execute reconnaissance commands.

T1059.001
PowerShell
GroupChimera

Chimera has used PowerShell scripts to execute malicious payloads and the DSInternals PowerShell module to make use of Active Directory features.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.