Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Execution/ T1059.001

T1059.001PowerShell

T1059.001 — PowerShell is a MITRE ATT&CK technique in the Execution tactic. Clankerusecase tracks 125 detection use cases covering it and 274 threat-intel articles citing it.

Execution
View on the matrix → Filter Detection Library MITRE official spec ↗
125Use cases
274Articles
0Sub-techniques
1Tactic

Use cases covering this technique (125)

Fake CAPTCHA / clipboard-injected PowerShell (ClickFix / FakeCaptcha) Internal exploit · alerting DSΣP Office app spawning script/LOLBin child process Internal exploit · alerting DSΣP Phishing-link click correlated to endpoint execution Internal delivery · alerting DSP PowerShell encoded / obfuscated command Internal exploit · alerting DSΣP [WEEKLY] Brand-Impersonation Domain Fetch Followed by User-Context Loader Within 10 Minutes Internal delivery · alerting DSPDD [WEEKLY] Cross-Platform ClickFix Paste-to-Pipe Loader (UI-Parent Shell with Decode-and-Execute Payload) Internal delivery · alerting DSΣP [WEEKLY] Developer/AI tooling runtime spawns shell or egress LOLBin (unauth RCE post-expl) Internal exploit · alerting DSPDDCS [WEEKLY] Developer package install spawning script-host with non-registry C2 within 5 minutes Internal install · alerting DSPDD [WEEKLY] Internet-facing service process spawns shell/LOLBin within minutes of public inbound connection — post-RCE command execution Internal exploit · alerting DSΣPDD [WEEKLY] Low-Code / AI Workflow Runtime Sandbox-Escape — Server Process Spawns Shell + Public Egress Internal exploit · alerting DSΣPDD [WEEKLY] npm/yarn/pnpm Install-Hook Spawn → Credential-Store Read or Worm-Payload Drop in node_modules Internal install · alerting DSΣPDD [WEEKLY] Package Manager / Dev-Tool Auto-Execution Triggers Non-Registry Egress or Credential-Store Access Internal install · alerting DSPDD [WEEKLY] Package-manager install-time interpreter spawn with credential-file read and outbound egress within 120s Internal install · alerting DSPDD [WEEKLY] Package manager lifecycle hook spawns network-fetching shell or runtime Internal install · alerting DSΣPDD [WEEKLY] Package manager lifecycle hook spawns runtime with outbound egress to non-registry host within 5 minutes Internal install · alerting DSPDD [WEEKLY] Script Interpreter or Package-Install Hook Egress to Free-Tier Edge SaaS Within 5 Minutes of Process Start Internal c2 · alerting DSΣPDD [WEEKLY] Self-hosted application service spawns shell or SSH within seconds of inbound unauthenticated API write Internal exploit · alerting DSPDD [WEEKLY] Server / AI-agent process spawns shell or LOLBIN with public egress — post-RCE behavioural chain Internal exploit · alerting DSΣPDD [WEEKLY] Service-process parent spawns subprocess containing CLI-argument-injection tokens Internal exploit · alerting DSΣPDD [WEEKLY] Web App Interpreter (Node/Python/Java/PHP) Spawns Shell or Net-Download LOLBin on Internet-Facing Host Internal exploit · alerting DSPDD PowerShell - Connect To Internet With Hidden Window ESCU actions · hunting P Detect Certify With PowerShell Script Block Logging ESCU actions · alerting P Detect Empire with PowerShell Script Block Logging ESCU actions · alerting P Detect Mimikatz With PowerShell Script Block Logging ESCU actions · alerting P Exchange PowerShell Module Usage ESCU actions · alerting P Get-ForestTrust with PowerShell Script Block ESCU actions · alerting P GetLocalUser with PowerShell Script Block ESCU actions · hunting P GetWmiObject User Account with PowerShell Script Block ESCU actions · hunting P Malicious PowerShell Process - Execution Policy Bypass ESCU actions · hunting P Malicious PowerShell Process With Obfuscation Techniques ESCU actions · alerting P Nishang PowershellTCPOneLine ESCU actions · alerting P Possible Lateral Movement PowerShell Spawn ESCU actions · hunting P PowerShell 4104 Hunting ESCU actions · hunting P Powershell COM Hijacking InprocServer32 Modification ESCU actions · alerting P Powershell Creating Thread Mutex ESCU actions · alerting P Powershell Defender Threat Actions Set to Allow ESCU actions · alerting P PowerShell Domain Enumeration ESCU actions · hunting P PowerShell Enable PowerShell Remoting ESCU actions · hunting P PowerShell Environment Variable Execution ESCU actions · hunting P Powershell Execute COM Object ESCU actions · alerting P Powershell Fileless Process Injection via GetProcAddress ESCU actions · alerting P Powershell Fileless Script Contains Base64 Encoded Content ESCU actions · alerting P Powershell Load Module in Meterpreter ESCU actions · alerting P PowerShell Loading DotNET into Memory via Reflection ESCU actions · hunting P PowerShell PInvoke Process Injection API Chain ESCU actions · alerting P Powershell Processing Stream Of Data ESCU actions · hunting P PowerShell Script Block With URL Chain ESCU actions · alerting P PowerShell Start or Stop Service ESCU actions · hunting P Powershell Using memory As Backing Store ESCU actions · alerting P PowerShell WebRequest Using Memory Stream ESCU actions · alerting P Recon Using WMI Class ESCU actions · hunting P Set Default PowerShell Execution Policy To Unrestricted or Bypass ESCU actions · alerting P Unloading AMSI via Reflection ESCU actions · alerting P Windows Account Access Removal via Logoff Exec ESCU actions · hunting P Windows Cobalt Strike PowerShell Loader ESCU actions · alerting P Windows Crowdstrike RTR Script Execution ESCU actions · hunting P Windows Default Cobalt Strike PowerShell Beacon ESCU actions · alerting P Windows Enable PowerShell Web Access ESCU actions · alerting P Windows Explorer.exe Spawning PowerShell or Cmd ESCU actions · hunting P Windows Explorer LNK Exploit Process Launch With Padding ESCU actions · alerting P Windows File Download Via PowerShell ESCU actions · hunting P Windows MSExchange Management Mailbox Cmdlet Usage ESCU actions · hunting P Windows Powershell Cryptography Namespace ESCU actions · hunting P Windows PowerShell FakeCAPTCHA Clipboard Execution ESCU actions · alerting P Windows PowerShell Get CIMInstance Remote Computer ESCU actions · hunting P Windows Powershell Import Applocker Policy ESCU actions · hunting P Windows PowerShell Invoke-RestMethod IP Information Collection ESCU actions · hunting P Windows PowerShell Invoke-Sqlcmd Execution ESCU actions · hunting P Windows Powershell Logoff User via Quser ESCU actions · hunting P Windows PowerShell Module File Created ESCU actions · hunting P Windows PowerShell MSIX Package Installation ESCU actions · alerting P Windows PowerShell Process Implementing Manual Base64 Decoder ESCU actions · hunting P Windows PowerShell Process With Malicious String ESCU actions · alerting P Windows Powershell RemoteSigned File ESCU actions · hunting P Windows PowerShell ScheduleTask ESCU actions · hunting P Windows PowerShell Script Block With Malicious String ESCU actions · alerting P Windows PowerShell Script From WindowsApps Directory ESCU actions · alerting P Windows PowerShell Script TabExpansion Direct Call ESCU actions · hunting P Windows PowerShell WMI Win32 ScheduledJob ESCU actions · alerting P Windows PowGoop Beacon Decoding ESCU actions · alerting P Windows Shell Process from CrushFTP ESCU actions · alerting P Windows Software Discovery Via PowerShell ESCU actions · hunting P Windows SSH Proxy Command ESCU actions · hunting P Windows Suspicious React or Next.js Child Process ESCU actions · alerting P Cisco Secure Firewall - Communication Over Suspicious Ports ESCU actions · hunting P Cisco Secure Firewall - Veeam CVE-2023-27532 Exploitation Activity ESCU actions · alerting P CrushFTP Authentication Bypass Exploitation ESCU actions · alerting P Any Powershell DownloadFile ESCU actions · alerting P Any Powershell DownloadString ESCU actions · alerting P First time seen command line argument ESCU actions · hunting P Suspicious Powershell Command-Line Arguments ESCU actions · alerting P [LLM] Node.js spawning shell/recon binaries or detached node -e loader Bespoke exploit · hunting DSΣPDDCS [LLM] TeamCity server (java) process spawning an OS command interpreter — CVE-2026-63077 RCE Bespoke exploit · alerting DSΣPDDCS [LLM] Payload or JSP web shell written by the TeamCity server process — CVE-2026-63077 Bespoke install · hunting DSΣPDDCS [LLM] n8n/Node.js process spawning shell or recon utility (sandbox-escape RCE) Bespoke exploit · alerting DSΣPDDCS [LLM] supportdev.exe Inno Setup loader spawning hidden-window PowerShell Bespoke install · alerting DSΣPDDCS [LLM] OpenAM/Tomcat Java process spawning a shell — post-deserialization RCE (CVE-2026-62263) Bespoke exploit · alerting DSΣPDDCS [LLM] ClickFix PowerShell loader spawning wscript to run downloaded VBScript Bespoke exploit · alerting DSΣPDDCS [LLM] Hidden PowerShell pulls installer.exe from pixeldrain.com to %Temp% (self-deleting dropper) Bespoke install · alerting DSΣPDDCS [LLM] Ruby interpreter spawning PowerShell -ExecutionPolicy bypass or /bin/sh (SleeperGem dropper) Bespoke exploit · hunting DSΣPDDCS [LLM] MSHTA remote HTA launched by explorer→powershell chain (ACR Stealer fileless campaign) Bespoke delivery · alerting DSΣPDDCS [LLM] Masqueraded 'Autoupdate' scheduled task run by PowerShell loader (ACR Stealer persistence) Bespoke install · alerting DSΣPDDCS [LLM] PowerShell AMSI/ETW bypass reflection (UAT-11795 WLDR evasion) Bespoke exploit · hunting DSΣPDDCS [LLM] In-memory WLDR PowerShell C2 implant (fileless, no -File, unusual parent) Bespoke c2 · hunting DSPDDCS [LLM] SiYuan Electron renderer (nodeIntegration) spawning shell/LOLBin child — XSS-to-RCE Bespoke exploit · alerting DSΣPDDCS [LLM] ZDI-CAN-25373 (CVE-2025-9491) LNK spawning PowerShell to fetch BusySnake loader Bespoke delivery · alerting DSΣPDDCS Article-specific behavioural hunt — Missed incidents, persistent threats, and response gaps: Insights from compromis Bespoke exploit · hunting DSP [LLM] npm/node postinstall script spawning a download or shell process (Mastra dropper pattern) Bespoke install · hunting DSΣPDDCS [LLM] Gamaredon stealer exfiltration to S3-compatible cloud storage (Wasabi/Tebi/Intercolo) Bespoke actions · alerting DSΣPDDCS [LLM] axios RAT Windows payload drop (6202033.vbs/.ps1, ProgramData\wt) during npm install Bespoke install · alerting DSΣPDDCS [LLM] Downloader or shell child of npm/pip install (postinstall RAT loader) Bespoke install · alerting DSΣPDDCS [LLM] axios RAT Windows persistence: %PROGRAMDATA%\wt.exe drop + %TEMP%\6202033.vbs/.ps1 staging Bespoke install · alerting DSΣPDDCS [LLM] Java/Tomcat process spawns OS command interpreter (post-Thymeleaf SSTI RCE) Bespoke actions · alerting DSΣPDDCS Article-specific behavioural hunt — axios Compromised on npm - Malicious Versions Drop Remote Access Trojan Bespoke exploit · hunting DSP [LLM] PowerShell masquerading as Windows Terminal at %PROGRAMDATA%\wt.exe (Axios RAT Windows stage) Bespoke install · alerting DSΣPDDCS [LLM] PowerShell copy masqueraded as Windows Terminal in %PROGRAMDATA% running 6202033.ps1 Bespoke install · alerting DSΣPDD Article-specific behavioural hunt — Glassworm Strikes Popular React Native Phone Number Packages Bespoke exploit · hunting DSP [LLM] MuddyWater SimpleHelp RMM client spawning shell or recon LOLBin Bespoke install · alerting DSΣP [LLM] Pastebin-piping stager retrieved from rentry.co/openclaw-core (macOS/Linux ClawHub skill) Bespoke delivery · alerting DSPDDCS [LLM] AI coding agent spawns remote fetch-and-execute (curl | bash / curl | source) Bespoke install · alerting DSΣPDDCS Article-specific behavioural hunt — LongNosedGoblin tries to sniff out governmental affairs in Southeast Asia and Ja Bespoke exploit · hunting DSP [LLM] Node.js process spawning interactive shell — suspected post-exploit RCE on Next.js / RSC server Bespoke exploit · alerting DSΣPDDCS [LLM] Cursor IDE or VS Code spawning PowerShell/WScript from extensions folder (Solidity Language malware chain) Bespoke exploit · alerting DSΣPDDCS [LLM] Tomcat/Java process spawns OS shell or LOLBin (post-webshell RCE) Bespoke actions · alerting DSΣPDDCS [LLM] Log4Shell RCE execution: java/javaw spawning a shell or LOLBin Bespoke exploit · alerting DSΣPDDCS

Articles citing this technique (274)