1200KM / simulation
T1059.001 PowerShell — Attack Simulation
Adversaries may abuse PowerShell commands and scripts for execution. PowerShell is a powerful interactive command-line interface and scripting environment included in the Windows operating system. Adversaries can use PowerShell to perform a number of actions, including discovery of information and execution of code. Examples include the Start-Process cmdlet which can be used to run an executable and the Invoke-Command cmdlet which runs a command…
Technique description
Adversaries may abuse PowerShell commands and scripts for execution. PowerShell is a powerful interactive command-line interface and scripting environment included in the Windows operating system. Adversaries can use PowerShell to perform a number of actions, including discovery of information and execution of code. Examples include the Start-Process cmdlet which can be used to run an executable and the Invoke-Command cmdlet which runs a command…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- Invoke-AppPathBypass
Procedure 06a220b6-7e29-4bd8-9d07-5b4d86742372; elevation not declared required; cleanup not declared. Not executed or individually validated.
- ATHPowerShellCommandLineParameter -EncodedCommand parameter variations with encoded arguments
Procedure 0d181431-ddf3-4826-8055-2dbf63ae848b; elevation not declared required; cleanup not declared. Not executed or individually validated.
- PowerUp Invoke-AllChecks
Procedure 1289f78d-22d2-4590-ac76-166737e1811b; elevation not declared required; cleanup not declared. Not executed or individually validated.
- ATHPowerShellCommandLineParameter -Command parameter variations with encoded arguments
Procedure 1c0a870f-dc74-49cf-9afc-eccc45e58790; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Powershell MsXml COM object - with prompt
Procedure 388a7340-dbc1-4c9d-8e59-b75ad8c6d5da; elevation not declared required; cleanup not declared. Not executed or individually validated.
- SOAPHound - Build Cache
Procedure 4099086c-1470-4223-8085-8186e1ed5948; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Powershell XML requests
Procedure 4396927f-e503-427b-b023-31049b9b09a6; elevation not declared required; cleanup not declared. Not executed or individually validated.
- PowerShell Invoke Known Malicious Cmdlets
Procedure 49eb9404-5e0f-4031-a179-b40f7be385e3; elevation required; cleanup not declared. Not executed or individually validated.
- ATHPowerShellCommandLineParameter -Command parameter variations
Procedure 686a9785-f99b-41d4-90df-66ed515f81d7; elevation not declared required; cleanup not declared. Not executed or individually validated.
- SOAPHound - Dump BloodHound Data
Procedure 6a5b2a50-d037-4879-bf01-43d4d6cbf73f; elevation not declared required; cleanup not declared. Not executed or individually validated.
- PowerShell Session Creation and Use
Procedure 7c1acec2-78fa-4305-a3e0-db2a54cddecd; elevation required; cleanup not declared. Not executed or individually validated.
- ATHPowerShellCommandLineParameter -EncodedCommand parameter variations
Procedure 86a43bad-12e3-4e85-b97c-4d5cf25b95c3; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Powershell invoke mshta.exe download
Procedure 8a2ad40b-12c7-4b25-8521-2737b0a415af; elevation not declared required; cleanup not declared. Not executed or individually validated.
- NTFS Alternate Data Stream Access
Procedure 8e5c5532-1181-4c1d-bb79-b3a9f5dbd680; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Abuse Nslookup with DNS Records
Procedure 999bff6d-dc15-44c9-9f5c-e1051bfc86e1; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Run BloodHound from local disk
Procedure a21bb23e-e677-4ee7-af90-6931b57b6350; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- PowerShell Command Execution
Procedure a538de64-1c74-46ed-aa60-b995ed302598; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Mimikatz - Cradlecraft PsSendKeys
Procedure af1800cf-9f9d-4fd1-a709-14b1e6de020d; elevation required; cleanup not declared. Not executed or individually validated.
- Run Bloodhound from Memory using Download Cradle
Procedure bf8c1441-4674-4dab-8e4e-39d93d08f9b7; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Powershell Invoke-DownloadCradle
Procedure cc50fa2a-a4be-42af-a88f-e347ba0bf4d7; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Mimikatz
Procedure f3132740-55bc-48c4-bcc0-758a459cd027; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- PowerShell Fileless Script Execution
Procedure fa050f5e-bc75-4230-af73-b6fd7852cd73; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
- APT28 · G0007
- Deep Panda · G0009
- Turla · G0010
- APT29 · G0016
- Molerats · G0021
- APT3 · G0022
- Threat Group-3390 · G0027
- Lazarus Group · G0032
- Poseidon Group · G0033
- Sandworm Team · G0034
- Dragonfly · G0035
- FIN6 · G0037
- Stealth Falcon · G0038
- Patchwork · G0040
- menuPass · G0045
- FIN7 · G0046
- Gamaredon Group · G0047
- OilRig · G0049
- APT32 · G0050
- FIN10 · G0051
- CopyKittens · G0052
- Magic Hound · G0059
- BRONZE BUTLER · G0060
- FIN8 · G0061
- TA459 · G0062
- APT33 · G0064
- Leviathan · G0065
- MuddyWater · G0069
- APT19 · G0073
- Thrip · G0076
- Gorgon Group · G0078
- DarkHydrus · G0079
- Cobalt Group · G0080
- APT38 · G0082
- Gallmaker · G0084
- APT39 · G0087
- WIRTE · G0090
- Silence · G0091
- TA505 · G0092
- GALLIUM · G0093
- Kimsuky · G0094
- APT41 · G0096
- APT-C-36 · G0099
- Inception · G0100
- Wizard Spider · G0102
- DarkVishnya · G0105
- Blue Mockingbird · G0108
- Chimera · G0114
- GOLD SOUTHFIELD · G0115
- Fox Kitten · G0117
- Indrik Spider · G0119
- Sidewinder · G0121
- HAFNIUM · G0125
- Mustang Panda · G0129
- Tonto Team · G0131
- Nomadic Octopus · G0133
- TeamTNT · G0139
- LazyScripter · G0140
- Confucius · G0142
- Aquatic Panda · G0143
- HEXANE · G1001
- Ember Bear · G1003
- Earth Lusca · G1006
- CURIUM · G1012
- Scattered Spider · G1015
- FIN13 · G1016
- Volt Typhoon · G1017
- TA2541 · G1018
- MoustachedBouncer · G1019
- Cinnamon Tempest · G1021
- ToddyCat · G1022
- APT5 · G1023
- Akira · G1024
- Saint Bear · G1031
- Daggerfly · G1034
- Winter Vivern · G1035
- RedCurl · G1039
- Play · G1040
- BlackByte · G1043
- APT42 · G1044
- Storm-1811 · G1046
- UNC3886 · G1048
- Medusa Group · G1051
- Storm-0501 · G1053
- VOID MANTICORE · G1055
Existing research
Connected anomaly research
Curated research views reached through an exact source technique, a catalog model, or a reviewed collection reference. These are navigation associations, not claims of detector effectiveness or sensor equivalence.
Telemetry contracts · Maintained query examples · Validation and blind spots
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.