Network Device CLI

T1059.008

Sub-technique of T1059 Command and Scripting Interpreter.View on attack.mitre.org

About this technique

Adversaries may abuse scripting or built-in command line interpreters (CLI) on network devices to execute malicious command and payloads. The CLI is the primary means through which users and administrators interact with the device in order to view system information, modify device operations, or perform diagnostic and administrative functions. CLIs typically contain various permission levels required for different commands.

Scripting interpreters automate tasks and extend functionality beyond the command set included in the network OS. The CLI and scripting interpreter are accessible through a direct console connection, or through remote means, such as telnet or SSH.

Adversaries can use the network CLI to change how network devices behave and operate. The CLI may be used to manipulate traffic flows to intercept or manipulate data, modify startup configuration parameters to load malicious system software, or to disable security features or logging to avoid detection.

Detection rules0

Rules on DetectionCode tagged with T1059.008.

Sigma0

No Sigma rules are mapped to this technique yet.

Splunk0

No Splunk rules are mapped to this technique yet.

Groups0

None recorded.

Software3

Campaigns2

Procedure examples5

Software3

Used byProcedure example
MalwareDRYHOOK

DRYHOOK has the ability to interact with Ivanti Connect Secure environments and to modify system components.

MalwareLine Dancer

Line Dancer can execute native commands in networking device command line interfaces.

MalwarePHASEJAM

PHASEJAM has leveraged native commands associated with the compromised network appliance to execute code.

Campaigns2

Used byProcedure example
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries leveraged the native CLI of the targeted FortiGate device.

CampaignRedPenguin

During RedPenguin, UNC3886 accessed the Junos OS CLI on targeted devices.

References1

  1. Cisco Synful Knock Evolution Open source
    Graham Holmes. (2015, October 8). Evolution of attacks on Cisco IOS devices. Retrieved October 19, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.