T1059.001PowerShell
T1059.001 — PowerShell is a MITRE ATT&CK technique in the Execution tactic. Clankerusecase tracks 137 detection use cases covering it and 209 threat-intel articles citing it.
Execution
137Use cases
209Articles
0Sub-techniques
1Tactic
↑ Parent technique: T1059 · Command and Scripting Interpreter
Use cases covering this technique (137)
Fake CAPTCHA / clipboard-injected PowerShell (ClickFix / FakeCaptcha) Office app spawning script/LOLBin child process Phishing-link click correlated to endpoint execution PowerShell encoded / obfuscated command [WEEKLY] Brand-Impersonation Domain Fetch Followed by User-Context Loader Within 10 Minutes [WEEKLY] Cross-Platform ClickFix Paste-to-Pipe Loader (UI-Parent Shell with Decode-and-Execute Payload) [WEEKLY] Developer/AI tooling runtime spawns shell or egress LOLBin (unauth RCE post-expl) [WEEKLY] Developer package install spawning script-host with non-registry C2 within 5 minutes [WEEKLY] Internet-facing service process spawns shell/LOLBin within minutes of public inbound connection — post-RCE command execution [WEEKLY] Low-Code / AI Workflow Runtime Sandbox-Escape — Server Process Spawns Shell + Public Egress [WEEKLY] npm/yarn/pnpm Install-Hook Spawn → Credential-Store Read or Worm-Payload Drop in node_modules [WEEKLY] Package Manager / Dev-Tool Auto-Execution Triggers Non-Registry Egress or Credential-Store Access [WEEKLY] Package-manager install-time interpreter spawn with credential-file read and outbound egress within 120s [WEEKLY] Package manager lifecycle hook spawns network-fetching shell or runtime [WEEKLY] Package manager lifecycle hook spawns runtime with outbound egress to non-registry host within 5 minutes [WEEKLY] Script Interpreter or Package-Install Hook Egress to Free-Tier Edge SaaS Within 5 Minutes of Process Start [WEEKLY] Self-hosted application service spawns shell or SSH within seconds of inbound unauthenticated API write [WEEKLY] Server / AI-agent process spawns shell or LOLBIN with public egress — post-RCE behavioural chain [WEEKLY] Service-process parent spawns subprocess containing CLI-argument-injection tokens [WEEKLY] Web App Interpreter (Node/Python/Java/PHP) Spawns Shell or Net-Download LOLBin on Internet-Facing Host Detect Certify With PowerShell Script Block Logging Detect Empire with PowerShell Script Block Logging Detect Mimikatz With PowerShell Script Block Logging Exchange PowerShell Module Usage Get-ForestTrust with PowerShell Script Block GetLocalUser with PowerShell Script Block GetWmiObject User Account with PowerShell Script Block Malicious PowerShell Process - Execution Policy Bypass Malicious PowerShell Process With Obfuscation Techniques Nishang PowershellTCPOneLine Possible Lateral Movement PowerShell Spawn PowerShell 4104 Hunting PowerShell - Connect To Internet With Hidden Window Powershell COM Hijacking InprocServer32 Modification Powershell Creating Thread Mutex PowerShell Domain Enumeration PowerShell Enable PowerShell Remoting PowerShell Environment Variable Execution Powershell Execute COM Object Powershell Fileless Process Injection via GetProcAddress Powershell Fileless Script Contains Base64 Encoded Content Powershell Load Module in Meterpreter PowerShell Loading DotNET into Memory via Reflection PowerShell PInvoke Process Injection API Chain Powershell Processing Stream Of Data PowerShell Script Block With URL Chain PowerShell Start or Stop Service Powershell Using memory As Backing Store PowerShell WebRequest Using Memory Stream Recon Using WMI Class Set Default PowerShell Execution Policy To Unrestricted or Bypass Unloading AMSI via Reflection Windows Account Access Removal via Logoff Exec Windows Cobalt Strike PowerShell Loader Windows Crowdstrike RTR Script Execution Windows Default Cobalt Strike PowerShell Beacon Windows Enable PowerShell Web Access Windows Explorer.exe Spawning PowerShell or Cmd Windows Explorer LNK Exploit Process Launch With Padding Windows File Download Via PowerShell Windows MSExchange Management Mailbox Cmdlet Usage Windows Powershell Cryptography Namespace Windows PowerShell FakeCAPTCHA Clipboard Execution Windows PowerShell Get CIMInstance Remote Computer Windows Powershell Import Applocker Policy Windows PowerShell Invoke-RestMethod IP Information Collection Windows PowerShell Invoke-Sqlcmd Execution Windows Powershell Logoff User via Quser Windows PowerShell Module File Created Windows PowerShell MSIX Package Installation Windows PowerShell Process Implementing Manual Base64 Decoder Windows PowerShell Process With Malicious String Windows Powershell RemoteSigned File Windows PowerShell ScheduleTask Windows PowerShell Script Block With Malicious String Windows PowerShell Script From WindowsApps Directory Windows PowerShell Script TabExpansion Direct Call Windows PowerShell WMI Win32 ScheduledJob Windows PowGoop Beacon Decoding Windows Shell Process from CrushFTP Windows Software Discovery Via PowerShell Windows SSH Proxy Command Windows Suspicious React or Next.js Child Process Cisco Secure Firewall - Communication Over Suspicious Ports Cisco Secure Firewall - Veeam CVE-2023-27532 Exploitation Activity CrushFTP Authentication Bypass Exploitation Any Powershell DownloadFile Any Powershell DownloadString First time seen command line argument Suspicious Powershell Command-Line Arguments [LLM] splunkd spawning shell interpreters (CVE-2026-20253 post-exploit RCE) [LLM] AI coding agent (Claude Code / Cursor / Codex) spawning shell that fetch-and-executes remote payload [LLM] Shell/LOLBin spawned by LangGraph Python or Node runtime [LLM] PowerShell process invoking LDAP:// with hardcoded plaintext credential [LLM] Self-hosted AI agent process spawns shell/curl/wget then executes the fetched payload [LLM] Webserver / PHP interpreter spawns shell or LOLBin — post-upload RCE indicator [LLM] FireAnt Metakit updater spawning unexpected child (supply-chain compromise) [LLM] npm install lifecycle script spawns interpreter or network-fetcher child [LLM] Chrome browser spawning LOLBin children post-V8 sandbox-escape (CVE-2026-11645) [LLM] HTTP.sys / IIS w3wp.exe spawning shell or LOLBin (CVE-2026-47291 post-exploit) [LLM] BEAM / Erlang VM spawns shell or interpreter child (post-RCE — CVE-2026-8467) [LLM] WinRAR CVE-2025-8088 — archive tool writes payload to user Startup folder [LLM] Startup LNK spawns cmd.exe → PowerShell in-memory DLL loader (GIFTEDCROOK chain) [LLM] Web-server process (php-fpm / apache / nginx / w3wp) spawning shell or network tooling Article-specific behavioural hunt — Hypotheses, telemetry, and human judgment: Inside Cisco Talos Threat Hunting [LLM] PowerShell Invoke-WebRequest dropping script.ps1 to user AppData (KongTuke stage-2) [LLM] mcp-remote OAuth authorization_endpoint RCE (CVE-2025-6514) — node spawning shell [LLM] Argamal Scheduled Task Pointing at AppData\Local DLL via Color System Calibration Loader [LLM] Downloader or shell child of npm/pip install (postinstall RAT loader) [LLM] Post-exploit shell spawned by Vitest node.exe via rerun / saveTestFile (CVE-2026-47429) [LLM] Node.js process spawning native shell / interpreter — post-vm2-escape host execution [LLM] axios RAT Windows persistence: %PROGRAMDATA%\wt.exe drop + %TEMP%\6202033.vbs/.ps1 staging [LLM] PowerShell-parented taskkill of winrar.exe (Cloud Atlas LNK anti-forensic cleanup) [LLM] PowerShower dropped to user Pictures folder as googleearth.ps1 [LLM] SSH process spawned by Kopia invokes a shell child (ProxyCommand execution) [LLM] GlassFish java process spawning command shell (CVE-2026-2587 RCE) [LLM] Apache Camel JVM spawning shell or command interpreter via camel-exec (CVE-2026-47323 post-exploit) [LLM] MLflow server process spawning Claude Code CLI or shell — CVE-2026-2611 RCE chain [LLM] Web-server process (w3wp/php/nginx) spawns shell or LOLBin (post-SSTI RCE chain) [LLM] n8n Node.js parent spawning OS shell — post-exploit RCE indicator for CVE-2026-44791 [LLM] Post-exploit RCE: node.js (n8n) spawning shell or scripting interpreter Article-specific behavioural hunt — Kimsuky targets organizations with PebbleDash-based tools [LLM] Kimsuky JSE dropper: wscript -> powershell hidden + certutil -decode chain [LLM] Java/Tomcat process spawns OS command interpreter (post-Thymeleaf SSTI RCE) Article-specific behavioural hunt — axios Compromised on npm - Malicious Versions Drop Remote Access Trojan [LLM] PowerShell masquerading as Windows Terminal at %PROGRAMDATA%\wt.exe (Axios RAT Windows stage) [LLM] PowerShell copy masqueraded as Windows Terminal in %PROGRAMDATA% running 6202033.ps1 Article-specific behavioural hunt — Glassworm Strikes Popular React Native Phone Number Packages [LLM] MuddyWater SimpleHelp RMM client spawning shell or recon LOLBin [LLM] Pastebin-piping stager retrieved from rentry.co/openclaw-core (macOS/Linux ClawHub skill) Article-specific behavioural hunt — Fake Clawdbot VS Code Extension Installs ScreenConnect RAT Article-specific behavioural hunt — G_Wagon: npm Package Deploys Python Stealer Targeting 100+ Crypto Wallets Article-specific behavioural hunt — LongNosedGoblin tries to sniff out governmental affairs in Southeast Asia and Ja [LLM] NPM preinstall hook fetching Bun installer from bun.sh (Sha1-Hulud dropper) [LLM] Node.js process spawning interactive shell — suspected post-exploit RCE on Next.js / RSC server [LLM] Cursor IDE or VS Code spawning PowerShell/WScript from extensions folder (Solidity Language malware chain) [LLM] Tomcat/Java process spawns OS shell or LOLBin (post-webshell RCE)Articles citing this technique (209)
crit ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universities art-37
high Miasma and Hades Are Spreading Now: Detect Them on Developer Machines with Suspicious Files art-45
high Blinding the Watchmen: Abusing Cloud Logging Services for Defense Evasion and Visibility art-74
crit Researchers Build Self-Replicating AI Worm That Operates Entirely on Local, Open-Weight Models art-87
high Node-gyp Supply Chain Compromise: A Self-Propagating npm Worm That Hides in binding.gyp art-130
high Miasma supply chain attack: malicious code found in @redhat-cloud-services npm packages art-159
crit Cloud Atlas activity in the second half of 2025 and early 2026: new tools and a new payload art-219
med Foul play: Fake FIFA websites target soccer fans looking for World Cup tickets, merchandise art-220
crit Malicious node-ipc versions published to npm in suspected maintainer account compromise art-284
crit [GHSA / CRITICAL] CVE-2026-44789: n8n: HTTP Request Node Pagination Prototype Pollution to RCE art-301
crit Mini Shai-Hulud Is Back: npm Worm Hits over 160 Packages, including Mistral and Tanstack art-315
high "A Mini Shai-Hulud Has Appeared": Bun-Based Stealer Hits SAP @cap-js and mbt npm Packages art-348
high Don't Panic: The Thymeleaf Template Injection That Only Hurts If You Let It (CVE-2026-40478) art-349
high Malicious Release of elementary-data PyPI Package Steals Cloud Credentials from Data Engineers art-352
high CanisterWorm: How a Self-Propagating npm Worm Is Spreading Backdoors Across the Ecosystem art-429
crit Malicious Polymarket Bot Hides in Hijacked dev-protocol GitHub Org and Steals Wallet Keys art-433
crit ForceMemo: Hundreds of GitHub Python Repos Compromised via Account Takeover and Force-Push art-434
high DRILLAPP: new backdoor targeting Ukrainian entities with possible links to Laundry Bear art-470
high 20+ Popular NPM Packages Compromised (Chalk, Debug, Strip-ANSI, Color-Convert, Wrap-ANSI...) art-537
crit ESET Threat Report H2 2025 art-647
high How Harden Runner Detected the Sha1-Hulud Supply Chain Attack in CNCF's Backstage Repository art-652
high Security Advisory: Critical RCE Vulnerabilities in React Server Components (CVE-2025-55182) art-673
crit CISA KEV: CVE-2024-55956 — Cleo Multiple Products Unauthenticated File Upload Vulnerability art-1051
high Defense in Depth art-1278