T1059.001PowerShell
T1059.001 — PowerShell is a MITRE ATT&CK technique in the Execution tactic. Clankerusecase tracks 118 detection use cases covering it and 281 threat-intel articles citing it.
Execution
118Use cases
281Articles
0Sub-techniques
1Tactic
↑ Parent technique: T1059 · Command and Scripting Interpreter
Use cases covering this technique (118)
Fake CAPTCHA / clipboard-injected PowerShell (ClickFix / FakeCaptcha) Office app spawning script/LOLBin child process Phishing-link click correlated to endpoint execution PowerShell encoded / obfuscated command [WEEKLY] Brand-Impersonation Domain Fetch Followed by User-Context Loader Within 10 Minutes [WEEKLY] Cross-Platform ClickFix Paste-to-Pipe Loader (UI-Parent Shell with Decode-and-Execute Payload) [WEEKLY] Developer/AI tooling runtime spawns shell or egress LOLBin (unauth RCE post-expl) [WEEKLY] Developer package install spawning script-host with non-registry C2 within 5 minutes [WEEKLY] Internet-facing service process spawns shell/LOLBin within minutes of public inbound connection — post-RCE command execution [WEEKLY] Low-Code / AI Workflow Runtime Sandbox-Escape — Server Process Spawns Shell + Public Egress [WEEKLY] npm/yarn/pnpm Install-Hook Spawn → Credential-Store Read or Worm-Payload Drop in node_modules [WEEKLY] Package Manager / Dev-Tool Auto-Execution Triggers Non-Registry Egress or Credential-Store Access [WEEKLY] Package-manager install-time interpreter spawn with credential-file read and outbound egress within 120s [WEEKLY] Package manager lifecycle hook spawns network-fetching shell or runtime [WEEKLY] Package manager lifecycle hook spawns runtime with outbound egress to non-registry host within 5 minutes [WEEKLY] Public-facing app auth/authz bypass into server-side code execution (patch-bypass wave) [WEEKLY] Script Interpreter or Package-Install Hook Egress to Free-Tier Edge SaaS Within 5 Minutes of Process Start [WEEKLY] Self-hosted application service spawns shell or SSH within seconds of inbound unauthenticated API write [WEEKLY] Server / AI-agent process spawns shell or LOLBIN with public egress — post-RCE behavioural chain [WEEKLY] Service-process parent spawns subprocess containing CLI-argument-injection tokens [WEEKLY] Web App Interpreter (Node/Python/Java/PHP) Spawns Shell or Net-Download LOLBin on Internet-Facing Host Detect Certify With PowerShell Script Block Logging Detect Empire with PowerShell Script Block Logging Detect Mimikatz With PowerShell Script Block Logging Exchange PowerShell Module Usage Get-ForestTrust with PowerShell Script Block GetLocalUser with PowerShell Script Block GetWmiObject User Account with PowerShell Script Block Malicious PowerShell Process - Execution Policy Bypass Malicious PowerShell Process With Obfuscation Techniques Nishang PowershellTCPOneLine Possible Lateral Movement PowerShell Spawn PowerShell 4104 Hunting Powershell COM Hijacking InprocServer32 Modification Powershell Creating Thread Mutex Powershell Defender Threat Actions Set to Allow PowerShell Domain Enumeration PowerShell Enable PowerShell Remoting PowerShell Environment Variable Execution Powershell Execute COM Object Powershell Fileless Process Injection via GetProcAddress Powershell Fileless Script Contains Base64 Encoded Content Powershell Load Module in Meterpreter PowerShell Loading DotNET into Memory via Reflection PowerShell PInvoke Process Injection API Chain Powershell Processing Stream Of Data PowerShell Script Block With URL Chain PowerShell Start or Stop Service Powershell Using memory As Backing Store PowerShell WebRequest Using Memory Stream Recon Using WMI Class Set Default PowerShell Execution Policy To Unrestricted or Bypass Unloading AMSI via Reflection Windows Account Access Removal via Logoff Exec Windows Cobalt Strike PowerShell Loader Windows Crowdstrike RTR Script Execution Windows Default Cobalt Strike PowerShell Beacon Windows Enable PowerShell Web Access Windows Explorer.exe Spawning PowerShell or Cmd Windows Explorer LNK Exploit Process Launch With Padding Windows File Download Via PowerShell Windows MSExchange Management Mailbox Cmdlet Usage Windows Powershell Commands from DNS TXT Windows Powershell Cryptography Namespace Windows PowerShell FakeCAPTCHA Clipboard Execution Windows PowerShell Get CIMInstance Remote Computer Windows Powershell Import Applocker Policy Windows PowerShell Invoke-RestMethod IP Information Collection Windows PowerShell Invoke-Sqlcmd Execution Windows Powershell Logoff User via Quser Windows PowerShell Module File Created Windows PowerShell MSIX Package Installation Windows PowerShell Process Implementing Manual Base64 Decoder Windows PowerShell Process With Malicious String Windows Powershell RemoteSigned File Windows PowerShell ScheduleTask Windows PowerShell Script Block With Malicious String Windows PowerShell Script From WindowsApps Directory Windows PowerShell Script TabExpansion Direct Call Windows PowerShell WMI Win32 ScheduledJob Windows PowGoop Beacon Decoding Windows Shell Process from CrushFTP Windows Software Discovery Via PowerShell Windows SSH Proxy Command Windows Suspicious React or Next.js Child Process Cisco Secure Firewall - Communication Over Suspicious Ports Cisco Secure Firewall - Veeam CVE-2023-27532 Exploitation Activity CrushFTP Authentication Bypass Exploitation Any Powershell DownloadFile Any Powershell DownloadString First time seen command line argument PowerShell - Connect To Internet With Hidden Window Suspicious Powershell Command-Line Arguments [LLM] Nuxt/Vite dev server (node.exe) spawns shell or LOLBin child — DevTools RPC RCE [LLM] Flowise node runtime spawns shell interpreter (post-exploit command execution) [LLM] ClickFix execution reaching CaptiveCrunch infrastructure or dropping svchost32 Article-specific behavioural hunt — OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage cam [LLM] OpenAM/Tomcat Java process spawning a shell — post-deserialization RCE (CVE-2026-62263) [LLM] Ruby interpreter spawning PowerShell -ExecutionPolicy bypass or /bin/sh (SleeperGem dropper) [LLM] PowerShell AMSI/ETW bypass reflection (UAT-11795 WLDR evasion) [LLM] In-memory WLDR PowerShell C2 implant (fileless, no -File, unusual parent) [LLM] SiYuan Electron renderer (nodeIntegration) spawning shell/LOLBin child — XSS-to-RCE [LLM] npm/node postinstall script spawning a download or shell process (Mastra dropper pattern) [LLM] Gamaredon stealer exfiltration to S3-compatible cloud storage (Wasabi/Tebi/Intercolo) [LLM] axios RAT Windows payload drop (6202033.vbs/.ps1, ProgramData\wt) during npm install [LLM] Downloader or shell child of npm/pip install (postinstall RAT loader) [LLM] axios RAT Windows persistence: %PROGRAMDATA%\wt.exe drop + %TEMP%\6202033.vbs/.ps1 staging [LLM] Java/Tomcat process spawns OS command interpreter (post-Thymeleaf SSTI RCE) Article-specific behavioural hunt — axios Compromised on npm - Malicious Versions Drop Remote Access Trojan [LLM] PowerShell masquerading as Windows Terminal at %PROGRAMDATA%\wt.exe (Axios RAT Windows stage) [LLM] MuddyWater SimpleHelp RMM client spawning shell or recon LOLBin [LLM] Pastebin-piping stager retrieved from rentry.co/openclaw-core (macOS/Linux ClawHub skill) [LLM] AI coding agent spawns remote fetch-and-execute (curl | bash / curl | source) Article-specific behavioural hunt — LongNosedGoblin tries to sniff out governmental affairs in Southeast Asia and Ja [LLM] Node.js process spawning interactive shell — suspected post-exploit RCE on Next.js / RSC server [LLM] Cursor IDE or VS Code spawning PowerShell/WScript from extensions folder (Solidity Language malware chain) [LLM] Tomcat/Java process spawns OS shell or LOLBin (post-webshell RCE) [LLM] Log4Shell RCE execution: java/javaw spawning a shell or LOLBinArticles citing this technique (281)
crit Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware art-28
crit Apple macOS Screen Sharing Flaw Exploited on Internet-Exposed Macs to Install Monero Miner art-38
high Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware art-40
high Chrome DevTools Technique Enables Authenticated Session Hijacking in Live Windows Browsers art-44
crit APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit art-48
crit ThreatsDay: GhostJacking AI Attacks, EtherHiding ClickFix, Cursor CLI Flaw + 17 More Stories art-51
high Curiouser and Curiouser art-52
crit AmnesiaStealer Hijacks Chromium Sessions to Give Attackers Live Browser Control on macOS art-55
high OpenAI, Anthropic, Google API Flaw Let Weaker AI Models Decode Stronger Models' Reasoning art-69
high DeadLock Ransomware Uses Polygon Smart Contracts to Make Extortion Infra Harder to Disrupt art-82
crit A Malicious SIM Card Can Run Attacker Code Inside the Modems Behind Cellular IoT Devices art-85
crit Mozilla Revokes Firefox and Thunderbird Linux Signing Key After Key Lands in Private Repo art-86
crit Researchers Built a Fake Crypto Startup and Hired Three Suspected North Korean IT Workers art-88
high Malicious MCP Servers Can Split Instructions to Make AI Coding Agents Exfiltrate Secrets art-90
high Project CAV3RN continues: Google Apps Script as C2 relay and DNS-based C2 channel selection art-91
crit The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications art-96
crit Show, Don't Tell: What Evo Continuous Offensive Security Found in a Real Enterprise SaaS art-101
crit Compromised PyPI Package: mrmustard 0.7.4 Steals SSH, Cloud, and Kubernetes Credentials art-193
crit Begun, the Patch Wars have art-253
crit ESET Threat Report H1 2026 art-312
high Miasma and Hades Are Spreading Now: Detect Them on Developer Machines with Suspicious Files art-365
high Node-gyp Supply Chain Compromise: A Self-Propagating npm Worm That Hides in binding.gyp art-408
high Miasma supply chain attack: malicious code found in @redhat-cloud-services npm packages art-426
med Foul play: Fake FIFA websites target soccer fans looking for World Cup tickets, merchandise art-448
high The AntV Supply Chain Campaign Expands: Microsoft's `durabletask` PyPI Package Compromised art-468
crit Malicious node-ipc versions published to npm in suspected maintainer account compromise art-477
crit Mini Shai-Hulud Is Back: npm Worm Hits over 160 Packages, including Mistral and Tanstack art-486
high "A Mini Shai-Hulud Has Appeared": Bun-Based Stealer Hits SAP @cap-js and mbt npm Packages art-515
high Don't Panic: The Thymeleaf Template Injection That Only Hurts If You Let It (CVE-2026-40478) art-517
high Malicious Release of elementary-data PyPI Package Steals Cloud Credentials from Data Engineers art-520
high CanisterWorm: How a Self-Propagating npm Worm Is Spreading Backdoors Across the Ecosystem art-592
crit Malicious Polymarket Bot Hides in Hijacked dev-protocol GitHub Org and Steals Wallet Keys art-596
crit ForceMemo: Hundreds of GitHub Python Repos Compromised via Account Takeover and Force-Push art-597
high DRILLAPP: new backdoor targeting Ukrainian entities with possible links to Laundry Bear art-623
high 20+ Popular NPM Packages Compromised (Chalk, Debug, Strip-ANSI, Color-Convert, Wrap-ANSI...) art-673
crit ESET Threat Report H2 2025 art-762
high Security Advisory: Critical RCE Vulnerabilities in React Server Components (CVE-2025-55182) art-782
crit CISA KEV: CVE-2024-55956 — Cleo Multiple Products Unauthenticated File Upload Vulnerability art-1144
crit CISA KEV: CVE-2024-38226 — Microsoft Publisher Protection Mechanism Failure Vulnerability art-1253
high Defense in Depth art-1415
high Ethical hacking techniques art-1721
high Ethical Hacking: Top Tools art-1725
crit API Security Guide art-1774
high Securing the web (forward) art-1826
high Cybersecurity Hygiene 101 art-1847
crit Secure Python URL validation art-1960
high Securing PHP containers art-2105
crit CISA KEV: CVE-2014-6287 — Rejetto HTTP File Server (HFS) Remote Code Execution Vulnerability art-2461
high Snyk joins OpenSSF: Tackling open source supply chain security with a developer-first approach art-3089
med Python Poetry package manager and security integration with software composition analysis tool art-3283
crit XSS Attacks: The Next Wave art-3664
high A CEO's guide to Emacs art-3716