Sub-technique of T1059 Command and Scripting Interpreter.View on attack.mitre.org
Adversaries may abuse the Windows command shell for execution. The Windows command shell (cmd) is the primary command prompt on Windows systems. The Windows command prompt can be used to control almost any aspect of a system, with various permission levels required for different subsets of commands. The command prompt can be invoked remotely via Remote Services such as SSH.
Batch files (ex: .bat or .cmd) also provide the shell with a list of sequential commands to run, as well as normal scripting operations such as conditionals and loops. Common uses of batch files include long or repetitive tasks, or the need to run the same set of commands on multiple systems.
Adversaries may leverage cmd to execute various commands and payloads. Common uses include cmd to execute a single command, or abusing cmd interactively with input and output forwarded over a command and control channel.
Rules on DetectionCode tagged with T1059.003.
| Rule | Type | Risk | Data source |
|---|---|---|---|
| CMD Carry Out String Command Parameter | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| CMD Echo Pipe - Escalation | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| CrushFTP Authentication Bypass Exploitation | TTP | NULL | CrushFTP |
| Detect Prohibited Applications Spawning cmd exe | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Detect Use of cmd exe to Launch Script Interpreters | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| First time seen command line argument | Hunting | NULL | Sysmon EventID 1 |
| Potentially malicious code on commandline | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Ryuk Wake on LAN Command | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows Command Shell DCRat ForkBomb Payload | TTP | NULL | Sysmon EventID 1, CrowdStrike ProcessRollup2 |
| Windows connhost exe started forcefully | TTP | NULL | Sysmon EventID 1 |
| Windows Content Copied from Browser was Executed | TTP | NULL | Sysmon EventID 13 AND Sysmon EventID 24 |
| Windows File Association Modification via Ftype | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows For Loop Usage Within Cmd.exe To Execute Commands | Anomaly | NULL | Sysmon EventID 1, CrowdStrike ProcessRollup2 |
| Windows PowerShell FakeCAPTCHA Clipboard Execution | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2, Cisco Network Visibility Module Flow Data |
| Windows Powershell History File Deletion | Anomaly | NULL | Powershell Script Block Logging 4104 |
| Windows PowerShell Invoke-Sqlcmd Execution | Hunting | NULL | Powershell Script Block Logging 4104 |
| Windows Shell Process from CrushFTP | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows SQLCMD Execution | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows Suspicious React or Next.js Child Process | TTP | NULL | Sysmon EventID 1, CrowdStrike ProcessRollup2 |
| Windows TinyCC Shellcode Execution | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688 |
| Used by | Procedure example |
|---|---|
| Groupadmin@338 | Following exploitation with LOWBALL malware, admin@338 actors created a file containing a list of commands to be executed on the compromised computer. |
| GroupAgrius | Agrius uses ASPXSpy web shells to enable follow-on command execution via |
| GroupAPT1 | APT1 has used the Windows command shell to execute commands, and batch scripting to automate execution. |
| GroupAPT18 | APT18 uses cmd.exe to execute commands on the victim’s machine. |
| GroupAPT28 | An APT28 loader Trojan uses a cmd.exe and batch script to run its payload. The group has also used macros to execute payloads. |
| GroupAPT3 | An APT3 downloader uses the Windows command |
| GroupAPT32 | APT32 has used cmd.exe for execution. |
| GroupAPT37 | APT37 has used the command-line interface. |
| Used by | Procedure example |
|---|---|
| Malware4H RAT | 4H RAT has the capability to create a remote shell. |
| MalwareABK | ABK has the ability to use cmd to run a Portable Executable (PE) on the compromised host. |
| MalwareAction RAT | Action RAT can use `cmd.exe` to execute commands on an infected host. |
| Malwareadbupd | adbupd can run a copy of cmd.exe. |
| MalwareADVSTORESHELL | ADVSTORESHELL can create a remote shell and run a given command. |
| MalwareAkira | Akira executes from the Windows command line and can take various arguments for execution. |
| MalwareAnchor | Anchor has used cmd.exe to run its self deletion routine. |
| MalwareAstaroth | Astaroth spawns a CMD process to execute commands. |
View all 295 software examples
| Used by | Procedure example |
|---|---|
| Campaign2016 Ukraine Electric Power Attack | During the 2016 Ukraine Electric Power Attack, Sandworm Team used the `xp_cmdshell` command in MS-SQL. |
| Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries leveraged PsExec to run `cmd.exe` commands on multiple victim machines. |
| CampaignAPT28 Nearest Neighbor Campaign | During APT28 Nearest Neighbor Campaign, APT28 used |
| CampaignC0015 | During C0015, the threat actors used `cmd.exe` to execute commands and run malicious binaries. |
| CampaignC0017 | During C0017, APT41 used `cmd.exe` to execute reconnaissance commands. |
| CampaignFrankenstein | During Frankenstein, the threat actors ran a command script to set up persistence as a scheduled task named "WinUpdate", as well as other encoded commands from the command-line |
| CampaignFunnyDream | During FunnyDream, the threat actors used `cmd.exe` to execute the wmiexec.vbs script. |
| CampaignHomeLand Justice | During HomeLand Justice, threat actors used Windows batch files for persistence and execution. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.