ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

4628 examples

TechniqueUsed byProcedure example
T1057
Process Discovery
GroupEarth Lusca

Earth Lusca has used Tasklist to obtain information from a compromised host.

T1057
Process Discovery
GroupMolerats

Molerats actors obtained a list of active processes on the victim and sent them to C2 servers.

T1057
Process Discovery
GroupInception

Inception has used a reconnaissance module to identify active processes and other associated loaded modules.

T1057
Process Discovery
GroupPlay

Play has used the information stealer Grixba to check for a list of security processes.

T1057
Process Discovery
GroupHEXANE

HEXANE has enumerated processes on targeted systems.

T1057
Process Discovery
GroupMagic Hound

Magic Hound malware can list running processes.

T1059
Command and Scripting Interpreter
GroupDragonfly

Dragonfly has used the command line for execution.

T1059
Command and Scripting Interpreter
GroupAPT32

APT32 has used COM scriptlets to download Cobalt Strike beacons.

T1059
Command and Scripting Interpreter
GroupFIN6

FIN6 has used scripting to iterate through a list of compromised PoS systems, copy data to a log file, and remove the original data files.

T1059
Command and Scripting Interpreter
GroupFIN7

FIN7 used SQL scripts to help perform tasks on the victim's machine.

T1059
Command and Scripting Interpreter
GroupMustang Panda

Mustang Panda has utilized meterpreter shellcode.

T1059
Command and Scripting Interpreter
GroupAPT39

APT39 has utilized custom scripts to perform internal reconnaissance.

T1059
Command and Scripting Interpreter
GroupAPT37

APT37 has used Ruby scripts to execute payloads.

T1059
Command and Scripting Interpreter
GroupOilRig

OilRig has used various types of scripting for execution.

T1059
Command and Scripting Interpreter
GroupWindigo

Windigo has used a Perl script for information gathering.

T1059
Command and Scripting Interpreter
GroupKe3chang

Malware used by Ke3chang can run commands on the command-line interface.

T1059
Command and Scripting Interpreter
GroupSaint Bear

Saint Bear has used the Windows Script Host (wscript) to execute intermediate files written to victim machines.

T1059
Command and Scripting Interpreter
GroupWinter Vivern

Winter Vivern used XLM 4.0 macros for initial code execution for malicious document files.

T1059
Command and Scripting Interpreter
GroupFIN5

FIN5 scans processes on all victim systems in the environment and uses automated scripts to pull back the results.

T1059
Command and Scripting Interpreter
GroupStealth Falcon

Stealth Falcon malware uses WMI to script data collection and command execution on the victim.

T1059
Command and Scripting Interpreter
GroupWhitefly

Whitefly has used a simple remote shell tool that will call back to the C2 server and wait for commands.

T1059
Command and Scripting Interpreter
GroupFox Kitten

Fox Kitten has used a Perl reverse shell to communicate with C2.

T1059
Command and Scripting Interpreter
GroupAPT19

APT19 downloaded and launched code within a SCT file.

T1059.001
PowerShell
GroupAPT38

APT38 has used PowerShell to execute commands and other operational tasks.

T1059.001
PowerShell
GroupIndrik Spider

Indrik Spider has used PowerShell Empire for execution of malware.

T1059.001
PowerShell
GroupBlackByte

BlackByte used encoded PowerShell commands during operations. BlackByte has used remote PowerShell commands in victim networks.

T1059.001
PowerShell
GroupGALLIUM

GALLIUM used PowerShell for execution to assist in lateral movement as well as for dumping credentials stored on compromised machines.

T1059.001
PowerShell
GroupAPT3

APT3 has used PowerShell on victim systems to download and run payloads after exploitation.

T1059.001
PowerShell
GroupKimsuky

Kimsuky has executed a variety of PowerShell scripts including Invoke-Mimikatz. Kimsuky has also utilized PowerShell scripts for execution, persistence, and defense evasion. Kimsuky has leveraged PowerShell’s cmdlet `Expand-Archive` to extract contents of zip files into the same directory. Kimsuky has employed ClickFix type tactics enticing victims to copy and paste malicious PowerShell commands and scripts, where the scripts ultimately led to QuasarRAT.

T1059.001
PowerShell
GroupVolt Typhoon

Volt Typhoon has used PowerShell including for remote system discovery.

T1059.001
PowerShell
GroupPatchwork

Patchwork used PowerSploit to download payloads, run a reverse shell, and execute malware on the victim's machine.

T1059.001
PowerShell
GroupAPT41

APT41 leveraged PowerShell to deploy malware families in victims’ environments.

T1059.001
PowerShell
GroupDragonfly

Dragonfly has used PowerShell scripts for execution.

T1059.001
PowerShell
GroupGorgon Group

Gorgon Group malware can use PowerShell commands to download and execute a payload and open a decoy document on the victim’s machine.

T1059.001
PowerShell
GroupmenuPass

menuPass uses PowerSploit to inject shellcode into PowerShell.

T1059.001
PowerShell
GroupAPT32

APT32 has used PowerShell-based tools, PowerShell one-liners, and shellcode loaders for execution.

T1059.001
PowerShell
GroupHAFNIUM

HAFNIUM has used the Exchange Power Shell module Set-OabVirtualDirectoryPowerShell to export mailbox data.

T1059.001
PowerShell
GroupMuddyWater

MuddyWater has used PowerShell for execution.

T1059.001
PowerShell
GroupFIN6

FIN6 has used PowerShell to gain access to merchant's networks, and a Metasploit PowerShell module to download and execute shellcode and to set up a local listener.

T1059.001
PowerShell
GroupGamaredon Group

Gamaredon Group has used obfuscated PowerShell scripts for staging. Additionally, (LinkById : G0047) has used PowerShell based tools later in its attack chain. Additionally, Gamaredon Group has used the PowerShell cmdlet `Get-Command` to download and execute the next stage payload.

T1059.001
PowerShell
GroupGallmaker

Gallmaker used PowerShell to download additional payloads and for execution.

T1059.001
PowerShell
GroupStorm-1811

Storm-1811 has used PowerShell for multiple purposes, such as using PowerShell scripts executing in an infinite loop to create an SSH connection to a command and control server.

T1059.001
PowerShell
GroupTeamTNT

TeamTNT has executed PowerShell commands in batch scripts.

T1059.001
PowerShell
GroupFIN7

FIN7 used a PowerShell script to launch shellcode that retrieved an additional payload. Additionally, FIN7 has executed a custom obfuscation of the shellcode invoker in PowerSploit called POWERTRASH.

T1059.001
PowerShell
GroupSandworm Team

Sandworm Team has used PowerShell scripts to run a credential harvesting tool in memory to evade defenses.

T1059.001
PowerShell
GroupCURIUM

CURIUM has leveraged PowerShell scripts for initial process execution and data gathering in victim environments.

T1059.001
PowerShell
GroupSidewinder

Sidewinder has used PowerShell to drop and execute malware loaders.

T1059.001
PowerShell
GroupMustang Panda

Mustang Panda has used malicious PowerShell scripts to enable execution.

T1059.001
PowerShell
GroupScattered Spider

Scattered Spider has used the PowerShell cmdlet Get-ADUser.

T1059.001
PowerShell
GroupAPT39

APT39 has used PowerShell to execute malicious code.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.