Real-world descriptions of how a group, tool or campaign used a technique.
4628 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1057 Process Discovery |
GroupEarth Lusca | Earth Lusca has used Tasklist to obtain information from a compromised host. |
| T1057 Process Discovery |
GroupMolerats | Molerats actors obtained a list of active processes on the victim and sent them to C2 servers. |
| T1057 Process Discovery |
GroupInception | Inception has used a reconnaissance module to identify active processes and other associated loaded modules. |
| T1057 Process Discovery |
GroupPlay | Play has used the information stealer Grixba to check for a list of security processes. |
| T1057 Process Discovery |
GroupHEXANE | HEXANE has enumerated processes on targeted systems. |
| T1057 Process Discovery |
GroupMagic Hound | Magic Hound malware can list running processes. |
| T1059 Command and Scripting Interpreter |
GroupDragonfly | Dragonfly has used the command line for execution. |
| T1059 Command and Scripting Interpreter |
GroupAPT32 | APT32 has used COM scriptlets to download Cobalt Strike beacons. |
| T1059 Command and Scripting Interpreter |
GroupFIN6 | FIN6 has used scripting to iterate through a list of compromised PoS systems, copy data to a log file, and remove the original data files. |
| T1059 Command and Scripting Interpreter |
GroupFIN7 | FIN7 used SQL scripts to help perform tasks on the victim's machine. |
| T1059 Command and Scripting Interpreter |
GroupMustang Panda | Mustang Panda has utilized meterpreter shellcode. |
| T1059 Command and Scripting Interpreter |
GroupAPT39 | APT39 has utilized custom scripts to perform internal reconnaissance. |
| T1059 Command and Scripting Interpreter |
GroupAPT37 | APT37 has used Ruby scripts to execute payloads. |
| T1059 Command and Scripting Interpreter |
GroupOilRig | OilRig has used various types of scripting for execution. |
| T1059 Command and Scripting Interpreter |
GroupWindigo | Windigo has used a Perl script for information gathering. |
| T1059 Command and Scripting Interpreter |
GroupKe3chang | Malware used by Ke3chang can run commands on the command-line interface. |
| T1059 Command and Scripting Interpreter |
GroupSaint Bear | Saint Bear has used the Windows Script Host (wscript) to execute intermediate files written to victim machines. |
| T1059 Command and Scripting Interpreter |
GroupWinter Vivern | Winter Vivern used XLM 4.0 macros for initial code execution for malicious document files. |
| T1059 Command and Scripting Interpreter |
GroupFIN5 | FIN5 scans processes on all victim systems in the environment and uses automated scripts to pull back the results. |
| T1059 Command and Scripting Interpreter |
GroupStealth Falcon | Stealth Falcon malware uses WMI to script data collection and command execution on the victim. |
| T1059 Command and Scripting Interpreter |
GroupWhitefly | Whitefly has used a simple remote shell tool that will call back to the C2 server and wait for commands. |
| T1059 Command and Scripting Interpreter |
GroupFox Kitten | Fox Kitten has used a Perl reverse shell to communicate with C2. |
| T1059 Command and Scripting Interpreter |
GroupAPT19 | APT19 downloaded and launched code within a SCT file. |
| T1059.001 PowerShell |
GroupAPT38 | APT38 has used PowerShell to execute commands and other operational tasks. |
| T1059.001 PowerShell |
GroupIndrik Spider | Indrik Spider has used PowerShell Empire for execution of malware. |
| T1059.001 PowerShell |
GroupBlackByte | BlackByte used encoded PowerShell commands during operations. BlackByte has used remote PowerShell commands in victim networks. |
| T1059.001 PowerShell |
GroupGALLIUM | GALLIUM used PowerShell for execution to assist in lateral movement as well as for dumping credentials stored on compromised machines. |
| T1059.001 PowerShell |
GroupAPT3 | APT3 has used PowerShell on victim systems to download and run payloads after exploitation. |
| T1059.001 PowerShell |
GroupKimsuky | Kimsuky has executed a variety of PowerShell scripts including Invoke-Mimikatz. Kimsuky has also utilized PowerShell scripts for execution, persistence, and defense evasion. Kimsuky has leveraged PowerShell’s cmdlet `Expand-Archive` to extract contents of zip files into the same directory. Kimsuky has employed ClickFix type tactics enticing victims to copy and paste malicious PowerShell commands and scripts, where the scripts ultimately led to QuasarRAT. |
| T1059.001 PowerShell |
GroupVolt Typhoon | Volt Typhoon has used PowerShell including for remote system discovery. |
| T1059.001 PowerShell |
GroupPatchwork | Patchwork used PowerSploit to download payloads, run a reverse shell, and execute malware on the victim's machine. |
| T1059.001 PowerShell |
GroupAPT41 | APT41 leveraged PowerShell to deploy malware families in victims’ environments. |
| T1059.001 PowerShell |
GroupDragonfly | Dragonfly has used PowerShell scripts for execution. |
| T1059.001 PowerShell |
GroupGorgon Group | Gorgon Group malware can use PowerShell commands to download and execute a payload and open a decoy document on the victim’s machine. |
| T1059.001 PowerShell |
GroupmenuPass | menuPass uses PowerSploit to inject shellcode into PowerShell. |
| T1059.001 PowerShell |
GroupAPT32 | APT32 has used PowerShell-based tools, PowerShell one-liners, and shellcode loaders for execution. |
| T1059.001 PowerShell |
GroupHAFNIUM | HAFNIUM has used the Exchange Power Shell module |
| T1059.001 PowerShell |
GroupMuddyWater | MuddyWater has used PowerShell for execution. ClearSky MuddyWater Nov 2018DHS CISA AA22-055A MuddyWater February 2022FireEye MuddyWater Mar 2018MuddyWater TrendMicro June 2018NaumaanProofpoint_GlobalClickFix_April2025Reaqta MuddyWater November 2017Securelist MuddyWater Oct 2018Symantec MuddyWater Dec 2018Talos MuddyWater Jan 2022Talos MuddyWater May 2019Trend Micro Muddy Water March 2021 |
| T1059.001 PowerShell |
GroupFIN6 | FIN6 has used PowerShell to gain access to merchant's networks, and a Metasploit PowerShell module to download and execute shellcode and to set up a local listener. |
| T1059.001 PowerShell |
GroupGamaredon Group | Gamaredon Group has used obfuscated PowerShell scripts for staging. Additionally, (LinkById : G0047) has used PowerShell based tools later in its attack chain. Additionally, Gamaredon Group has used the PowerShell cmdlet `Get-Command` to download and execute the next stage payload. |
| T1059.001 PowerShell |
GroupGallmaker | Gallmaker used PowerShell to download additional payloads and for execution. |
| T1059.001 PowerShell |
GroupStorm-1811 | Storm-1811 has used PowerShell for multiple purposes, such as using PowerShell scripts executing in an infinite loop to create an SSH connection to a command and control server. |
| T1059.001 PowerShell |
GroupTeamTNT | TeamTNT has executed PowerShell commands in batch scripts. |
| T1059.001 PowerShell |
GroupFIN7 | FIN7 used a PowerShell script to launch shellcode that retrieved an additional payload. Additionally, FIN7 has executed a custom obfuscation of the shellcode invoker in PowerSploit called POWERTRASH. |
| T1059.001 PowerShell |
GroupSandworm Team | Sandworm Team has used PowerShell scripts to run a credential harvesting tool in memory to evade defenses. |
| T1059.001 PowerShell |
GroupCURIUM | CURIUM has leveraged PowerShell scripts for initial process execution and data gathering in victim environments. |
| T1059.001 PowerShell |
GroupSidewinder | Sidewinder has used PowerShell to drop and execute malware loaders. |
| T1059.001 PowerShell |
GroupMustang Panda | Mustang Panda has used malicious PowerShell scripts to enable execution. |
| T1059.001 PowerShell |
GroupScattered Spider | Scattered Spider has used the PowerShell cmdlet Get-ADUser. |
| T1059.001 PowerShell |
GroupAPT39 | APT39 has used PowerShell to execute malicious code. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.