Real-world descriptions of how a group, tool or campaign used a technique.
23 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1059 Command and Scripting Interpreter |
MalwareNICECURL | NICECURL has provided an arbitrary command execution interface. |
| T1059 Command and Scripting Interpreter |
MalwareGet2 | Get2 has the ability to run executables with command-line arguments. |
| T1059 Command and Scripting Interpreter |
MalwareVersaMem | VersaMem was delivered as a Java Archive (JAR) that runs by attaching itself to the Apache Tomcat Java servlet and web server. |
| T1059 Command and Scripting Interpreter |
MalwareZeus Panda | Zeus Panda can launch remote scripts on the victim’s machine. |
| T1059 Command and Scripting Interpreter |
MalwareMatryoshka | Matryoshka is capable of providing Meterpreter shell access. |
| T1059 Command and Scripting Interpreter |
MalwareP.A.S. Webshell | P.A.S. Webshell has the ability to create reverse shells with Perl scripts. |
| T1059 Command and Scripting Interpreter |
MalwareWINERACK | WINERACK can create a reverse shell that utilizes statically-linked Wine cmd.exe code to emulate Windows command prompt commands. |
| T1059 Command and Scripting Interpreter |
MalwareBonadan | Bonadan can create bind and reverse shells on the infected system. |
| T1059 Command and Scripting Interpreter |
MalwareRaspberry Robin | Raspberry Robin variants can be delivered via highly obfuscated Windows Script Files (WSF) for initial execution. |
| T1059 Command and Scripting Interpreter |
MalwareDarkComet | DarkComet can execute various types of scripts on the victim’s machine. |
| T1059 Command and Scripting Interpreter |
MalwareMuddyViper | MuddyViper has launched a reverse shell using a provided command line. |
| T1059 Command and Scripting Interpreter |
MalwareBandook | Bandook can support commands to execute Java-based payloads. |
| T1059 Command and Scripting Interpreter |
Malwaregh0st RAT | gh0st RAT is able to open a remote shell to execute commands. |
| T1059 Command and Scripting Interpreter |
MalwareSpeakUp | SpeakUp uses Perl scripts. |
| T1059 Command and Scripting Interpreter |
MalwareKessel | Kessel can create a reverse shell between the infected host and a specified system. |
| T1059 Command and Scripting Interpreter |
MalwareCHOPSTICK | CHOPSTICK is capable of performing remote command execution. |
| T1059 Command and Scripting Interpreter |
MalwareSLIGHTPULSE | SLIGHTPULSE contains functionality to execute arbitrary commands passed to it. |
| T1059 Command and Scripting Interpreter |
MalwareStarProxy | StarProxy has used the command line for execution of commands. |
| T1059 Command and Scripting Interpreter |
MalwareFIVEHANDS | FIVEHANDS can receive a command line argument to limit file encryption to specified directories. |
| T1059 Command and Scripting Interpreter |
ToolEmpire | Empire uses a command-line interface to interact with systems. |
| T1059 Command and Scripting Interpreter |
ToolImminent Monitor | Imminent Monitor has a CommandPromptPacket and ScriptPacket module(s) for creating a remote shell and executing scripts. |
| T1059 Command and Scripting Interpreter |
ToolDonut | Donut can generate shellcode outputs that execute via Ruby. |
| T1059 Command and Scripting Interpreter |
MalwareZeroCleare | ZeroCleare can receive command line arguments from an operator to corrupt the file system using the RawDisk driver. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.