FORENSIA

ATT&CK · T1059

Command and Scripting Interpreter

Tactics: execution

About

Adversaries may abuse command and script interpreters to execute commands, scripts, or binaries. These interfaces and languages provide ways of interacting with computer systems and are a common feature across many different platforms. Most systems come with some built-in command-line interface and scripting capabilities, for example, macOS and Linux distributions include some flavor of Unix Shell while Windows installations include the Windows Command Shell and PowerShell. There are also cross-platform interpreters such as Python, as well as those commonly associated with client applications such as JavaScript and Visual Basic. Adversaries may abuse these technologies in various ways as a means of executing arbitrary commands. Commands and scripts can be embedded in Initial Access payloads delivered to victims as lure documents or as secondary payloads downloaded from an existing C2. Adversaries may also execute commands through interactive terminals/shells, as well as utilize various Remote Services in order to achieve remote Execution.

Platforms: Containers, ESXi, IaaS, Identity Provider, Linux, macOS, Network Devices, Office Suite, SaaS, WindowsMITRE ATT&CK ↗

Used by actors

17 known groups

Software

23 malware/tools implement this

CHOPSTICKgh0st RATMatryoshkaWINERACKBandookZeus PandaDarkCometEmpireSpeakUpImminent MonitorGet2BonadanKesselP.A.S. WebshellFIVEHANDSDonutSLIGHTPULSERaspberry RobinZeroCleareVersaMemNICECURLStarProxyMuddyViper

Corpus indicators tagged with this technique

744 indicators in the corpus carry T1059.

IndicatorTypeFamilySevSrc
cve-2013-3307cve852
cve-2017-17215cve852
cve-2022-47945cve851
cve-2016-5681cve852
cve-2024-1781cve851
cve-2018-8007cve851
cve-2025-11837cve852
cc918f0da51794f0174437d336e6f3edfdd3cbe4hash802
de1a114a2c5552387a1bbb61501bf129hashransomware801
ac10f5b1d5ecab22b7b418d6e98fa18e32bbdeabhash802
3dfc3d81572e16ceaae3d07922255eb88068b91dhash802
3a8f6454927b8993aded75de0de2bd00hashphishing802
7ee17efef04bb7c9de90d5210263ed6993f867e5a11f86e65e3bb1362c7de237sha256ransomware801
2194271c7991d60ae82436129d7f25c0a689050ahash802
a40ee8ff313e59aa92d48592c494a4c3d81449afhash802
8cc249b16adf7e4a658af7fa31d7998ehash802
87480b151e465b73151220533c965f3a77046138f079ca3ceb961a7d5fee9a33hash801
c85eedd51dced48b3764c2d5bdb8febefe4210a2d9611e0fb14ffc937b80e302hash801
d35695f2366a43628231e73ffa83ca106306a8fahash802
b371fbdce6935039218d4b4272db3521881c9cec48ef82dec1e9e0188a32d3adhash801
03b51af0a04467cebfa235199db4c02ehashwallet_compromise801
c2eb1033bc01ab0fd732a7ba4967be02c0690bf0hash802
4650f7dc1a2ddbb6d73bf5bfd1b69dd6b79e0cddhashphishing802
7105caa6d4fd8a2c67523d385277528e556ae4f6hash802
82e579bd49d69845133c9aa8585f8bd26736437bhash802
f96bcd875836da89800912de1e557891697c7cf4hash802
fe0161fb8a26a0bf4afad746c7ebf89499dcd3a7hash802
185b7a487316454da04e9cc0fe6eb370bb2955cf6096fe3e8c02c46f8989ba37hashphishing802
f8cbe44fde6914bc8d06426c03c92ed536c891470292e567a586b54af29c2442hash802
9ca9432b0d29204cb5420a1a6b01533d4552130c2a8a5ecd7837efadefb4a046sha256ransomware801

Showing the top 30 by severity of 744.