ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1059.001×

131 examples

TechniqueUsed byProcedure example
T1059.001
PowerShell
MalwareTrickBot

TrickBot has been known to use PowerShell to download new payloads, open documents, and upload data to command and control servers.

T1059.001
PowerShell
MalwareBumblebee

Bumblebee can use PowerShell for execution.

T1059.001
PowerShell
MalwareGRIFFON

GRIFFON has used PowerShell to execute the Meterpreter downloader TinyMet.

T1059.001
PowerShell
MalwarePOWRUNER

POWRUNER is written in PowerShell.

T1059.001
PowerShell
MalwareSharpStage

SharpStage can execute arbitrary commands with PowerShell.

T1059.001
PowerShell
MalwareSardonic

Sardonic has the ability to execute PowerShell commands on a compromised machine.

T1059.001
PowerShell
MalwareHALFBAKED

HALFBAKED can execute PowerShell scripts.

T1059.001
PowerShell
MalwareTAMECAT

TAMECAT has used PowerShell to download and run additional content.

T1059.001
PowerShell
MalwarePS1

PS1 can utilize a PowerShell loader.

T1059.001
PowerShell
MalwareUrsnif

Ursnif droppers have used PowerShell in download cradles to download and execute the malware's full executable payload.

T1059.001
PowerShell
MalwareRansomHub

RansomHub can use PowerShell to delete volume shadow copies.

T1059.001
PowerShell
MalwarePOWERSOURCE

POWERSOURCE is a PowerShell backdoor.

T1059.001
PowerShell
MalwareTsundere Botnet

Tsundere Botnet has been distributed via a PowerShell script.

T1059.001
PowerShell
MalwareZeus Panda

Zeus Panda uses PowerShell to download and execute the payload.

T1059.001
PowerShell
MalwareHavoc

Havoc can facilitate the execution of PowerShell commands.

T1059.001
PowerShell
MalwarePrestige

Prestige can use PowerShell for payload execution on targeted systems.

T1059.001
PowerShell
MalwareInvisibleFerret

InvisibleFerret has utilized a PowerShell script created in the victim’s home directory named “conf.ps1” that is used to modify configuration files for AnyDesk remote services.

T1059.001
PowerShell
MalwareStrongPity

StrongPity can use PowerShell to add files to the Windows Defender exclusions list.

T1059.001
PowerShell
MalwareMedusa Ransomware

Medusa Ransomware has launched PowerShell scripts for execution and defense evasion.

T1059.001
PowerShell
MalwareAppleSeed

AppleSeed has the ability to execute its payload via PowerShell.

T1059.001
PowerShell
MalwareNETWIRE

The NETWIRE binary has been executed via PowerShell script.

T1059.001
PowerShell
MalwarePyDCrypt

PyDCrypt has attempted to execute with PowerShell.

T1059.001
PowerShell
MalwarePowerExchange

PowerExchange can use PowerShell to execute commands received from C2.

T1059.001
PowerShell
MalwareHAMMERTOSS

HAMMERTOSS is known to use PowerShell.

T1059.001
PowerShell
MalwareEmotet

Emotet has used Powershell to retrieve the malicious payload and download additional resources like Mimikatz.

T1059.001
PowerShell
MalwareBADHATCH

BADHATCH can utilize `powershell.exe` to execute commands on a compromised host.

T1059.001
PowerShell
MalwarePowerLess

PowerLess is written in and executed via PowerShell without using powershell.exe.

T1059.001
PowerShell
MalwareSystemBC

SystemBC has used hidden scheduled tasks to execute PowerShell commands by adding the following: `-WindowStyle Hidden -ep bypass -file `.

T1059.001
PowerShell
MalwareGootloader

Gootloader can use an encoded PowerShell stager to write to the Registry for persistence.

T1059.001
PowerShell
MalwareWellMess

WellMess can execute PowerShell scripts received from C2.

T1059.001
PowerShell
MalwareWoody RAT

Woody RAT can execute PowerShell commands and scripts with the use of .NET DLL, `WoodyPowerSession`.

T1059.001
PowerShell
MalwareMafalda

Mafalda can execute PowerShell commands on a compromised machine.

T1059.001
PowerShell
MalwareSquirrelwaffle

Squirrelwaffle has used PowerShell to execute its payload.

T1059.001
PowerShell
MalwareShrinkLocker

ShrinkLocker uses PowerShell to disable protectors used to secure the BitLocker encryption key on victim machines and then delete the key from the system.

T1059.001
PowerShell
MalwareFlawedAmmyy

FlawedAmmyy has used PowerShell to execute commands.

T1059.001
PowerShell
MalwareSnip3

Snip3 can use a PowerShell script for second-stage execution.

T1059.001
PowerShell
MalwareRegDuke

RegDuke can extract and execute PowerShell scripts from C2 communications.

T1059.001
PowerShell
MalwareWhisperGate

WhisperGate can use PowerShell to support multiple actions including execution and defense evasion.

T1059.001
PowerShell
MalwareTRANSLATEXT

TRANSLATEXT has used PowerShell to collect system information and to upload the collected data to a Github repository.

T1059.001
PowerShell
MalwarePowerShower

PowerShower is a backdoor written in PowerShell.

T1059.001
PowerShell
MalwareCHIMNEYSWEEP

CHIMNEYSWEEP can invoke the PowerShell command `[Reflection.Assembly]::LoadFile(\"%s\")\n$i=\"\"\n$r=[%s]::%s(\"%s\",[ref] $i)\necho $r,$i\n` to execute secondary payloads.

T1059.001
PowerShell
MalwareFatDuke

FatDuke has the ability to execute PowerShell scripts.

T1059.001
PowerShell
MalwareGLASSTOKEN

GLASSTOKEN can use PowerShell for command execution.

T1059.001
PowerShell
MalwarePUNCHBUGGY

PUNCHBUGGY has used PowerShell scripts.

T1059.001
PowerShell
MalwareKeyBoy

KeyBoy uses PowerShell commands to download and execute payloads.

T1059.001
PowerShell
MalwarePOSHSPY

POSHSPY uses PowerShell to execute various commands, one to execute its payload.

T1059.001
PowerShell
MalwareDarkWatchman

DarkWatchman can execute PowerShell commands and has used PowerShell to execute a keylogger.

T1059.001
PowerShell
MalwareLumma Stealer

Lumma Stealer has used PowerShell for initial user execution and other fuctions.

T1059.001
PowerShell
MalwareSeaDuke

SeaDuke uses a module to execute Mimikatz with PowerShell to perform Pass the Ticket.

T1059.001
PowerShell
MalwareXbash

Xbash can use scripts to invoke PowerShell to download a malicious PE executable or PE DLL for execution.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.