TACTIC: EXECUTION

PowerShell (T1059.001): real cases

MITRE Definition ↗
Adversaries abuse the Windows PowerShell command environment to execute commands and download malicious payloads.

Key Facts

Technique ID
T1059.001
Execution
Mapped Cases
2
Primary sources
Related Laws
0
Criminal statutes
  • ATT&CK Technique Identifier: T1059.001.
  • Tactical Phase: Execution.
  • Substantiated in 2 primary court prosecution cases.
  • Every associated case includes verbatim evidentiary excerpts from indictments or sworn affidavits.

Verified Evidentiary Case Records

Primary Source Evidence Excerpt: Indictment ¶ 16, Page 9
"Malicious macros embedded in the documents launched hidden PowerShell scripts to download the Carbanak malware suite."
U.S. District Court for the Western District of Washington View full case dossier →
Primary Source Evidence Excerpt: Indictment ¶ 33, Page 14
"Defendants used custom X-Agent malware and executed PowerShell scripts to automate file collection across internal exchange servers."
U.S. District Court for the District of Columbia View full case dossier →