ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1059×

23 examples

TechniqueUsed byProcedure example
T1059
Command and Scripting Interpreter
MalwareNICECURL

NICECURL has provided an arbitrary command execution interface.

T1059
Command and Scripting Interpreter
MalwareGet2

Get2 has the ability to run executables with command-line arguments.

T1059
Command and Scripting Interpreter
MalwareVersaMem

VersaMem was delivered as a Java Archive (JAR) that runs by attaching itself to the Apache Tomcat Java servlet and web server.

T1059
Command and Scripting Interpreter
MalwareZeus Panda

Zeus Panda can launch remote scripts on the victim’s machine.

T1059
Command and Scripting Interpreter
MalwareMatryoshka

Matryoshka is capable of providing Meterpreter shell access.

T1059
Command and Scripting Interpreter
MalwareP.A.S. Webshell

P.A.S. Webshell has the ability to create reverse shells with Perl scripts.

T1059
Command and Scripting Interpreter
MalwareWINERACK

WINERACK can create a reverse shell that utilizes statically-linked Wine cmd.exe code to emulate Windows command prompt commands.

T1059
Command and Scripting Interpreter
MalwareBonadan

Bonadan can create bind and reverse shells on the infected system.

T1059
Command and Scripting Interpreter
MalwareRaspberry Robin

Raspberry Robin variants can be delivered via highly obfuscated Windows Script Files (WSF) for initial execution.

T1059
Command and Scripting Interpreter
MalwareDarkComet

DarkComet can execute various types of scripts on the victim’s machine.

T1059
Command and Scripting Interpreter
MalwareMuddyViper

MuddyViper has launched a reverse shell using a provided command line.

T1059
Command and Scripting Interpreter
MalwareBandook

Bandook can support commands to execute Java-based payloads.

T1059
Command and Scripting Interpreter
Malwaregh0st RAT

gh0st RAT is able to open a remote shell to execute commands.

T1059
Command and Scripting Interpreter
MalwareSpeakUp

SpeakUp uses Perl scripts.

T1059
Command and Scripting Interpreter
MalwareKessel

Kessel can create a reverse shell between the infected host and a specified system.

T1059
Command and Scripting Interpreter
MalwareCHOPSTICK

CHOPSTICK is capable of performing remote command execution.

T1059
Command and Scripting Interpreter
MalwareSLIGHTPULSE

SLIGHTPULSE contains functionality to execute arbitrary commands passed to it.

T1059
Command and Scripting Interpreter
MalwareStarProxy

StarProxy has used the command line for execution of commands.

T1059
Command and Scripting Interpreter
MalwareFIVEHANDS

FIVEHANDS can receive a command line argument to limit file encryption to specified directories.

T1059
Command and Scripting Interpreter
ToolEmpire

Empire uses a command-line interface to interact with systems.

T1059
Command and Scripting Interpreter
ToolImminent Monitor

Imminent Monitor has a CommandPromptPacket and ScriptPacket module(s) for creating a remote shell and executing scripts.

T1059
Command and Scripting Interpreter
ToolDonut

Donut can generate shellcode outputs that execute via Ruby.

T1059
Command and Scripting Interpreter
MalwareZeroCleare

ZeroCleare can receive command line arguments from an operator to corrupt the file system using the RawDisk driver.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.