Technique with 13 sub-techniques.View on attack.mitre.org
Adversaries may abuse command and script interpreters to execute commands, scripts, or binaries. These interfaces and languages provide ways of interacting with computer systems and are a common feature across many different platforms. Most systems come with some built-in command-line interface and scripting capabilities, for example, macOS and Linux distributions include some flavor of Unix Shell while Windows installations include the Windows Command Shell and PowerShell.
There are also cross-platform interpreters such as Python, as well as those commonly associated with client applications such as JavaScript and Visual Basic.
Adversaries may abuse these technologies in various ways as a means of executing arbitrary commands. Commands and scripts can be embedded in Initial Access payloads delivered to victims as lure documents or as secondary payloads downloaded from an existing C2. Adversaries may also execute commands through interactive terminals/shells, as well as utilize various Remote Services in order to achieve remote Execution.
Rules on DetectionCode tagged with T1059 or one of its sub-techniques.
| Rule | Type | Risk | Data source | Technique |
|---|---|---|---|---|
| Any Powershell DownloadFile | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1059.001 |
| Any Powershell DownloadString | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1059.001 |
| CHCP Command Execution | Anomaly | NULL | Sysmon EventID 1, CrowdStrike ProcessRollup2 | T1059 |
| Cisco IOS XE Guestshell Activation and Destroy | Anomaly | NULL | Cisco IOS Logs | T1059 |
| Cisco IOS XE Request Platform Package Describe Shell Pattern | TTP | NULL | Cisco IOS Logs | T1059 |
| Cisco NVM - Browser Spawned Unix Shell with External Connection | Anomaly | NULL | Cisco Network Visibility Module Flow Data | T1059 |
| Cisco NVM - Installation of Typosquatted Python Package | TTP | NULL | Cisco Network Visibility Module Flow Data | T1059 |
| Cisco NVM - MSHTML or MSHTA Network Execution Without URL in CLI | Anomaly | NULL | Cisco Network Visibility Module Flow Data | T1059.005 |
| Cisco NVM - Osascript Network Connection for a Long Duration | Anomaly | NULL | Cisco Network Visibility Module Flow Data | T1059.002 |
| Cisco NVM - Susp Script From Archive Triggering Network Activity | Anomaly | NULL | Cisco Network Visibility Module Flow Data | T1059.005 |
| Cisco NVM - Suspicious File Download via Headless Browser | TTP | NULL | Cisco Network Visibility Module Flow Data | T1059 |
| Cisco Secure Firewall - Binary File Type Download | Anomaly | NULL | Cisco Secure Firewall Threat Defense File Event | T1059 |
| Cisco Secure Firewall - Citrix NetScaler Memory Overread Attempt | TTP | NULL | Cisco Secure Firewall Threat Defense Intrusion Event | T1059 |
| Cisco Secure Firewall - Communication Over Suspicious Ports | Anomaly | NULL | Cisco Secure Firewall Threat Defense Connection Event | T1059.001 |
| Cisco Secure Firewall - High Volume of Intrusion Events Per Host | Anomaly | NULL | Cisco Secure Firewall Threat Defense Intrusion Event | T1059 |
| Cisco Secure Firewall - Possibly Compromised Host | Anomaly | NULL | Cisco Secure Firewall Threat Defense Intrusion Event | T1059 |
| Cisco Secure Firewall - Privileged Command Execution via HTTP | Anomaly | NULL | Cisco Secure Firewall Threat Defense Intrusion Event | T1059 |
| Cisco Secure Firewall - Veeam CVE-2023-27532 Exploitation Activity | TTP | NULL | Cisco Secure Firewall Threat Defense Intrusion Event | T1059.001 |
| Cisco Secure Firewall - Wget or Curl Download | Anomaly | NULL | Cisco Secure Firewall Threat Defense Connection Event | T1059 |
| CMD Carry Out String Command Parameter | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1059.003 |
| CMD Echo Pipe - Escalation | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1059.003 |
| Cmdline Tool Not Executed In CMD Shell | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1059.007 |
| CrushFTP Authentication Bypass Exploitation | TTP | NULL | CrushFTP | T1059.001 T1059.003 |
| Detect Certify With PowerShell Script Block Logging | TTP | NULL | Powershell Script Block Logging 4104 | T1059.001 |
| Detect Empire with PowerShell Script Block Logging | TTP | NULL | Powershell Script Block Logging 4104 | T1059.001 |
| Detect Mimikatz With PowerShell Script Block Logging | TTP | NULL | Powershell Script Block Logging 4104 | T1059.001 |
| Detect Outbound LDAP Traffic | Hunting | NULL | Palo Alto Network Traffic, Cisco Secure Firewall Threat Defense Connection Event, Cisco Secure Access Firewall | T1059 |
| Detect Prohibited Applications Spawning cmd exe | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1059.003 |
| Detect suspicious processnames using pretrained model in DSDL | Anomaly | NULL | Sysmon EventID 1 | T1059 |
| Detect Use of cmd exe to Launch Script Interpreters | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1059.003 |
| ESXi Reverse Shell Patterns | TTP | NULL | VMWare ESXi Syslog | T1059 |
| Excessive distinct processes from Windows Temp | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1059 |
| Excessive number of taskhost processes | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1059 |
| Exchange PowerShell Module Usage | TTP | NULL | Powershell Script Block Logging 4104 | T1059.001 |
| Execute Javascript With Jscript COM CLSID | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1059.005 |
| First time seen command line argument | Hunting | NULL | Sysmon EventID 1 | T1059.001 T1059.003 |
| Get-ForestTrust with PowerShell Script Block | TTP | NULL | Powershell Script Block Logging 4104 | T1059.001 |
| GetLocalUser with PowerShell Script Block | Hunting | NULL | Powershell Script Block Logging 4104 | T1059.001 |
| GetWmiObject User Account with PowerShell Script Block | Hunting | NULL | Powershell Script Block Logging 4104 | T1059.001 |
| Jscript Execution Using Cscript App | Anomaly | NULL | Sysmon EventID 1, CrowdStrike ProcessRollup2 | T1059.007 |
| Juniper Networks Remote Code Execution Exploit Detection | TTP | NULL | Suricata | T1059 |
| Linux Binary Executed from Shared Memory Directory | Anomaly | NULL | Sysmon for Linux EventID 1 | T1059 |
| Linux Decode Base64 to Shell | TTP | NULL | Sysmon for Linux EventID 1, Cisco Isovalent Process Exec | T1059.004 |
| Linux Docker Shell Execution | Anomaly | NULL | Sysmon for Linux EventID 1 | T1059.013 |
| Linux Ghostscript Exploitation | TTP | NULL | Sysmon for Linux EventID 1 | T1059 |
| Linux Magic SysRq Key Abuse | TTP | NULL | Linux Auditd Path, Linux Auditd Cwd | T1059.004 |
| Linux MOTD Script Added | Anomaly | NULL | Sysmon for Linux EventID 11 | T1059.004 |
| Linux Netcat Outbound Connection | Anomaly | NULL | Sysmon for Linux EventID 3 | T1059.004 |
| Linux Possible System Binary Backdoor | Anomaly | NULL | Sysmon for Linux EventID 11 | T1059.004 |
| Linux Shell Pseudo Device Reverse Shell | Anomaly | NULL | Sysmon for Linux EventID 1 | T1059 |
| Linux Suspicious Privileged Container Execution | Anomaly | NULL | Sysmon for Linux EventID 1 | T1059.004 |
| Linux Suspicious React or Next.js Child Process | TTP | NULL | Sysmon for Linux EventID 1 | T1059.004 |
| Linux Suspicious XDG Autostart | Anomaly | NULL | Sysmon for Linux EventID 11 | T1059.004 |
| Linux Unix Shell Enable All SysRq Functions | Anomaly | NULL | Sysmon for Linux EventID 1 | T1059.004 |
| Living Off The Land Detection | Correlation | NULL | T1059 | |
| Log4Shell CVE-2021-44228 Exploitation | Correlation | NULL | T1059 | |
| MacOS AMOS Stealer - Virtual Machine Check Activity | Anomaly | NULL | Osquery Results | T1059.002 |
| MacOS AppleScript Shell Execution and Compilation | Anomaly | NULL | Osquery Results | T1059.002 |
| MacOS LOLbin | TTP | NULL | Osquery Results | T1059.004 |
| MacOS Osascript Displaying Suspicious User Prompt | Anomaly | NULL | Osquery Results | T1059.002 |
| MacOS Osascript Executing Interactive Shell | Anomaly | NULL | Osquery Results | T1059.002 T1059.004 |
| MacOS Osascript Executing JavaScript Code With ObjC | Anomaly | NULL | Osquery Results | T1059.002 T1059.007 |
| Malicious PowerShell Process - Execution Policy Bypass | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1059.001 |
| Malicious PowerShell Process With Obfuscation Techniques | TTP | NULL | Sysmon EventID 1 | T1059.001 |
| MCP Filesystem Server Suspicious Extension Write | Hunting | NULL | MCP Server | T1059 |
| MCP Prompt Injection | TTP | NULL | MCP Server | T1059 |
| MS Scripting Process Loading Ldap Module | Anomaly | NULL | Sysmon EventID 7 | T1059.007 |
| MS Scripting Process Loading WMI Module | Anomaly | NULL | Sysmon EventID 7 | T1059.007 |
| Nishang PowershellTCPOneLine | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1059.001 |
| Ollama Suspicious Prompt Injection Jailbreak | Anomaly | NULL | Ollama Server | T1059 |
| Possible Lateral Movement PowerShell Spawn | Anomaly | NULL | Sysmon EventID 1, CrowdStrike ProcessRollup2 | T1059.001 |
| Potentially malicious code on commandline | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1059.003 |
| PowerShell - Connect To Internet With Hidden Window | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1059.001 |
| PowerShell 4104 Hunting | Hunting | NULL | Powershell Script Block Logging 4104 | T1059.001 |
| Powershell COM Hijacking InprocServer32 Modification | TTP | NULL | Powershell Script Block Logging 4104 | T1059.001 |
| Powershell Creating Thread Mutex | TTP | NULL | Powershell Script Block Logging 4104 | T1059.001 |
| Powershell Defender Threat Actions Set to Allow | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1059.001 |
| PowerShell Domain Enumeration | Anomaly | NULL | Powershell Script Block Logging 4104 | T1059.001 |
| PowerShell Enable PowerShell Remoting | Anomaly | NULL | Powershell Script Block Logging 4104 | T1059.001 |
| PowerShell Environment Variable Execution | Anomaly | NULL | Powershell Script Block Logging 4104 | T1059.001 |
| Powershell Execute COM Object | TTP | NULL | Powershell Script Block Logging 4104 | T1059.001 |
| Powershell Fileless Process Injection via GetProcAddress | TTP | NULL | Powershell Script Block Logging 4104 | T1059.001 |
| Powershell Fileless Script Contains Base64 Encoded Content | TTP | NULL | Powershell Script Block Logging 4104 | T1059.001 |
| Powershell Load Module in Meterpreter | TTP | NULL | Powershell Script Block Logging 4104 | T1059.001 |
| PowerShell Loading DotNET into Memory via Reflection | Anomaly | NULL | Powershell Script Block Logging 4104 | T1059.001 |
| PowerShell PInvoke Process Injection API Chain | TTP | NULL | Powershell Script Block Logging 4104 | T1059.001 |
| Powershell Processing Stream Of Data | Anomaly | NULL | Powershell Script Block Logging 4104 | T1059.001 |
| PowerShell Script Block With URL Chain | TTP | NULL | Powershell Script Block Logging 4104 | T1059.001 |
| PowerShell Start or Stop Service | Anomaly | NULL | Powershell Script Block Logging 4104 | T1059.001 |
| Powershell Using memory As Backing Store | TTP | NULL | Powershell Script Block Logging 4104 | T1059.001 |
| PowerShell WebRequest Using Memory Stream | TTP | NULL | Powershell Script Block Logging 4104 | T1059.001 |
| Process Writing DynamicWrapperX | Hunting | NULL | Sysmon EventID 11 | T1059 |
| PTC Windchill Gateway Command Execution | Anomaly | NULL | Windchill Log4j | T1059 |
| PTC Windchill GW READY OK Probe | Anomaly | NULL | Windchill Log4j | T1059 |
| Python Network Traffic During Package Build | Anomaly | NULL | Sysmon EventID 1 AND Sysmon EventID 3 | T1059.006 |
| Recon Using WMI Class | Anomaly | NULL | Powershell Script Block Logging 4104 | T1059.001 |
| Ryuk Wake on LAN Command | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1059.003 |
| Set Default PowerShell Execution Policy To Unrestricted or Bypass | TTP | NULL | Sysmon EventID 13 | T1059.001 |
| Socat Network Listener Binding an Executable | TTP | NULL | Osquery Results, Sysmon for Linux EventID 1 | T1059 |
| Socat Remote TCP Connection with Local Echo Disabled | Anomaly | NULL | Osquery Results, Sysmon for Linux EventID 1 | T1059 |
| Suspicious Linux Discovery Commands | TTP | NULL | Sysmon for Linux EventID 1 | T1059.004 |
| Suspicious Powershell Command-Line Arguments | TTP | NULL | Sysmon EventID 1 | T1059.001 |
| Suspicious Process DNS Query Known Abuse Web Services | TTP | NULL | Sysmon EventID 22 | T1059.005 |
| Suspicious Process With Discord DNS Query | Anomaly | NULL | Sysmon EventID 22 | T1059.005 |
| Unloading AMSI via Reflection | TTP | NULL | Powershell Script Block Logging 4104 | T1059.001 |
| Vbscript Execution Using Wscript App | TTP | NULL | Sysmon EventID 1, CrowdStrike ProcessRollup2 | T1059.005 |
| Wermgr Process Spawned CMD Or Powershell Process | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1059 |
| Windows Account Access Removal via Logoff Exec | Anomaly | NULL | Sysmon EventID 1 | T1059.001 |
| Windows Apache Benchmark Binary | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1059 |
| Windows AutoIt3 Execution | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1059 |
| Windows Cmdline Tool Execution From Non-Shell Process | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1059.007 |
| Windows Cobalt Strike PowerShell Loader | TTP | NULL | Powershell Script Block Logging 4104 | T1059.001 |
| Windows Command and Scripting Interpreter Hunting Path Traversal | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1059 |
| Windows Command and Scripting Interpreter Path Traversal Exec | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1059 |
| Windows Command Shell DCRat ForkBomb Payload | TTP | NULL | Sysmon EventID 1, CrowdStrike ProcessRollup2 | T1059.003 |
| Windows Common Abused Cmd Shell Risk Behavior | Correlation | NULL | T1059 | |
| Windows connhost exe started forcefully | TTP | NULL | Sysmon EventID 1 | T1059.003 |
| Windows Content Copied from Browser was Executed | TTP | NULL | Sysmon EventID 13 AND Sysmon EventID 24 | T1059.001 T1059.003 |
| Windows Crowdstrike RTR Script Execution | Anomaly | NULL | Sysmon EventID 1, CrowdStrike ProcessRollup2 | T1059.001 |
| Windows Default Cobalt Strike PowerShell Beacon | TTP | NULL | Powershell Script Block Logging 4104 | T1059.001 |
| Windows Defender ASR Audit Events | Anomaly | NULL | Windows Event Log Defender 1122, Windows Event Log Defender 1125, Windows Event Log Defender 1126, Windows Event Log Defender 1132, Windows Event Log Defender 1134 | T1059 |
| Windows Defender ASR Block Events | Anomaly | NULL | Windows Event Log Defender 1121, Windows Event Log Defender 1126, Windows Event Log Defender 1129, Windows Event Log Defender 1131, Windows Event Log Defender 1133 | T1059 |
| Windows Defender ASR Rules Stacking | Hunting | NULL | Windows Event Log Defender 1121, Windows Event Log Defender 1122, Windows Event Log Defender 1125, Windows Event Log Defender 1126, Windows Event Log Defender 1129, Windows Event Log Defender 1131, Windows Event Log Defender 1133, Windows Event Log Defender 1134, Windows Event Log Defender 5007 | T1059 |
| Windows Enable PowerShell Web Access | TTP | NULL | Powershell Script Block Logging 4104 | T1059.001 |
| Windows Explorer LNK Exploit Process Launch With Padding | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688 | T1059.001 |
| Windows Explorer.exe Spawning PowerShell or Cmd | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688 | T1059.001 |
| Windows File Association Modification via Ftype | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1059.003 |
| Windows File Download Via PowerShell | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2, Cisco Network Visibility Module Flow Data | T1059.001 |
| Windows For Loop Usage Within Cmd.exe To Execute Commands | Anomaly | NULL | Sysmon EventID 1, CrowdStrike ProcessRollup2 | T1059.003 |
| Windows GrimResource - MMC Process Accessing APDS DLL | TTP | NULL | Windows Event Log Security 4663 | T1059.007 |
| Windows Identify Protocol Handlers | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1059 |
| Windows MSExchange Management Mailbox Cmdlet Usage | Anomaly | NULL | T1059.001 | |
| Windows Node.exe Executing JS Script In Immediate Folder | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1059.007 |
| Windows Outlook Macro Created by Suspicious Process | TTP | NULL | Sysmon EventID 11 | T1059.005 |
| Windows PaperCut NG Spawn Shell | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1059 |
| Windows Powershell Commands from DNS TXT | Anomaly | NULL | Powershell Script Block Logging 4104 | T1059.001 |
| Windows Powershell Cryptography Namespace | Anomaly | NULL | Powershell Script Block Logging 4104 | T1059.001 |
| Windows PowerShell FakeCAPTCHA Clipboard Execution | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2, Cisco Network Visibility Module Flow Data | T1059.001 T1059.003 |
| Windows PowerShell Get CIMInstance Remote Computer | Anomaly | NULL | Powershell Script Block Logging 4104 | T1059.001 |
| Windows Powershell History File Deletion | Anomaly | NULL | Powershell Script Block Logging 4104 | T1059.003 |
| Windows Powershell Import Applocker Policy | Anomaly | NULL | Powershell Script Block Logging 4104 | T1059.001 |
| Windows PowerShell Invoke-RestMethod IP Information Collection | Anomaly | NULL | Powershell Script Block Logging 4104 | T1059.001 |
| Windows PowerShell Invoke-Sqlcmd Execution | Hunting | NULL | Powershell Script Block Logging 4104 | T1059.001 T1059.003 |
| Windows Powershell Logoff User via Quser | Anomaly | NULL | Powershell Script Block Logging 4104 | T1059.001 |
| Windows PowerShell Module File Created | Anomaly | NULL | Sysmon EventID 11 | T1059.001 |
| Windows PowerShell MSIX Package Installation | TTP | NULL | Powershell Script Block Logging 4104 | T1059.001 |
| Windows PowerShell Process Implementing Manual Base64 Decoder | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1059.001 |
| Windows PowerShell Process With Malicious String | TTP | NULL | Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2 | T1059.001 |
| Windows Powershell RemoteSigned File | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1059.001 |
| Windows PowerShell ScheduleTask | Anomaly | NULL | Powershell Script Block Logging 4104 | T1059.001 |
| Windows PowerShell Script Block With Malicious String | TTP | NULL | Powershell Script Block Logging 4104 | T1059.001 |
| Windows PowerShell Script From WindowsApps Directory | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1059.001 |
| Windows PowerShell Script TabExpansion Direct Call | Anomaly | NULL | Powershell Script Block Logging 4104 | T1059.001 |
| Windows PowerShell WMI Win32 ScheduledJob | TTP | NULL | Powershell Script Block Logging 4104 | T1059.001 |
| Windows PowGoop Beacon Decoding | TTP | NULL | Sysmon EventID 1, CrowdStrike ProcessRollup2 | T1059.001 |
| Windows Process Accessing IronLanguages Repository On GitHub | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1059 |
| Windows Process Accessing Windows Recall Directory | Anomaly | NULL | Windows Event Log Security 4663 | T1059 |
| Windows Process Execution From RDP Share | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1059 |
| Windows Remote Image Load | Anomaly | NULL | Sysmon EventID 7 | T1059 |
| Windows Scheduled Task Service Spawned Shell | TTP | NULL | Sysmon EventID 1, CrowdStrike ProcessRollup2 | T1059 |
| Windows Shell Process from CrushFTP | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1059.001 T1059.003 |
| Windows Software Discovery Via PowerShell | Anomaly | NULL | Powershell Script Block Logging 4104 | T1059.001 |
| Windows SQL Server Extended Procedure DLL Loading Hunt | Hunting | NULL | Windows Event Log Application 8128 | T1059.009 |
| Windows SQLCMD Execution | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1059.003 |
| Windows SSH Proxy Command | Anomaly | NULL | Sysmon EventID 1, CrowdStrike ProcessRollup2 | T1059.001 |
| Windows Suspicious Child Process of Consent.EXE | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1059 |
| Windows Suspicious React or Next.js Child Process | TTP | NULL | Sysmon EventID 1, CrowdStrike ProcessRollup2 | T1059.001 T1059.003 |
| Windows Suspicious VMWare Tools Child Process | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1059 |
| Windows TeamCity Payload Execution from Temp Directory | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1059 |
| Windows TeamCity Plugin Installed | Anomaly | NULL | Sysmon EventID 11 | T1059 |
| Windows TinyCC Shellcode Execution | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688 | T1059.003 |
| Windows WinDBG Spawning AutoIt3 | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1059 |
| Windows XLL File Creation Outside of Typical Location | Anomaly | NULL | Sysmon EventID 11 | T1059 |
| ID | Name | Examples |
|---|---|---|
| T1059.001 | PowerShell | 233 |
| T1059.002 | AppleScript | 6 |
| T1059.003 | Windows Command Shell | 386 |
| T1059.004 | Unix Shell | 66 |
| T1059.005 | Visual Basic | 131 |
| T1059.006 | Python | 63 |
| T1059.007 | JavaScript | 75 |
| T1059.008 | Network Device CLI | 5 |
| T1059.009 | Cloud API | 6 |
| T1059.010 | AutoHotKey & AutoIT | 6 |
| T1059.011 | Lua | 5 |
| T1059.012 | Hypervisor CLI | 4 |
| T1059.013 | Container CLI/API | 3 |
| Used by | Procedure example |
|---|---|
| GroupAPT19 | APT19 downloaded and launched code within a SCT file. |
| GroupAPT32 | APT32 has used COM scriptlets to download Cobalt Strike beacons. |
| GroupAPT37 | APT37 has used Ruby scripts to execute payloads. |
| GroupAPT39 | APT39 has utilized custom scripts to perform internal reconnaissance. |
| GroupDragonfly | Dragonfly has used the command line for execution. |
| GroupFIN5 | FIN5 scans processes on all victim systems in the environment and uses automated scripts to pull back the results. |
| GroupFIN6 | FIN6 has used scripting to iterate through a list of compromised PoS systems, copy data to a log file, and remove the original data files. |
| GroupFIN7 | FIN7 used SQL scripts to help perform tasks on the victim's machine. |
| Used by | Procedure example |
|---|---|
| MalwareBandook | Bandook can support commands to execute Java-based payloads. |
| MalwareBonadan | Bonadan can create bind and reverse shells on the infected system. |
| MalwareCHOPSTICK | CHOPSTICK is capable of performing remote command execution. |
| MalwareDarkComet | DarkComet can execute various types of scripts on the victim’s machine. |
| ToolDonut | Donut can generate shellcode outputs that execute via Ruby. |
| ToolEmpire | Empire uses a command-line interface to interact with systems. |
| MalwareFIVEHANDS | FIVEHANDS can receive a command line argument to limit file encryption to specified directories. |
| MalwareGet2 | Get2 has the ability to run executables with command-line arguments. |
| Used by | Procedure example |
|---|---|
| CampaignArcaneDoor | ArcaneDoor included the adversary executing command line interface (CLI) commands. |
| CampaignCutting Edge | During Cutting Edge, threat actors used Perl scripts to enable the deployment of the THINSPOOL shell script dropper and for enumerating host data. |
| CampaignFLORAHOX Activity | FLORAHOX Activity has executed PHP and Shell scripts to identify and infect subsequent routers for the ORB network. |
| CampaignOperation Spalax | For Operation Spalax, the threat actors used Nullsoft Scriptable Install System (NSIS) scripts to install malware. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.