T1059.001PowerShell
T1059.001 — PowerShell is a MITRE ATT&CK technique in the Execution tactic. Clankerusecase tracks 125 detection use cases covering it and 274 threat-intel articles citing it.
Execution
125Use cases
274Articles
0Sub-techniques
1Tactic
↑ Parent technique: T1059 · Command and Scripting Interpreter
Use cases covering this technique (125)
Fake CAPTCHA / clipboard-injected PowerShell (ClickFix / FakeCaptcha) Office app spawning script/LOLBin child process Phishing-link click correlated to endpoint execution PowerShell encoded / obfuscated command [WEEKLY] Brand-Impersonation Domain Fetch Followed by User-Context Loader Within 10 Minutes [WEEKLY] Cross-Platform ClickFix Paste-to-Pipe Loader (UI-Parent Shell with Decode-and-Execute Payload) [WEEKLY] Developer/AI tooling runtime spawns shell or egress LOLBin (unauth RCE post-expl) [WEEKLY] Developer package install spawning script-host with non-registry C2 within 5 minutes [WEEKLY] Internet-facing service process spawns shell/LOLBin within minutes of public inbound connection — post-RCE command execution [WEEKLY] Low-Code / AI Workflow Runtime Sandbox-Escape — Server Process Spawns Shell + Public Egress [WEEKLY] npm/yarn/pnpm Install-Hook Spawn → Credential-Store Read or Worm-Payload Drop in node_modules [WEEKLY] Package Manager / Dev-Tool Auto-Execution Triggers Non-Registry Egress or Credential-Store Access [WEEKLY] Package-manager install-time interpreter spawn with credential-file read and outbound egress within 120s [WEEKLY] Package manager lifecycle hook spawns network-fetching shell or runtime [WEEKLY] Package manager lifecycle hook spawns runtime with outbound egress to non-registry host within 5 minutes [WEEKLY] Script Interpreter or Package-Install Hook Egress to Free-Tier Edge SaaS Within 5 Minutes of Process Start [WEEKLY] Self-hosted application service spawns shell or SSH within seconds of inbound unauthenticated API write [WEEKLY] Server / AI-agent process spawns shell or LOLBIN with public egress — post-RCE behavioural chain [WEEKLY] Service-process parent spawns subprocess containing CLI-argument-injection tokens [WEEKLY] Web App Interpreter (Node/Python/Java/PHP) Spawns Shell or Net-Download LOLBin on Internet-Facing Host PowerShell - Connect To Internet With Hidden Window Detect Certify With PowerShell Script Block Logging Detect Empire with PowerShell Script Block Logging Detect Mimikatz With PowerShell Script Block Logging Exchange PowerShell Module Usage Get-ForestTrust with PowerShell Script Block GetLocalUser with PowerShell Script Block GetWmiObject User Account with PowerShell Script Block Malicious PowerShell Process - Execution Policy Bypass Malicious PowerShell Process With Obfuscation Techniques Nishang PowershellTCPOneLine Possible Lateral Movement PowerShell Spawn PowerShell 4104 Hunting Powershell COM Hijacking InprocServer32 Modification Powershell Creating Thread Mutex Powershell Defender Threat Actions Set to Allow PowerShell Domain Enumeration PowerShell Enable PowerShell Remoting PowerShell Environment Variable Execution Powershell Execute COM Object Powershell Fileless Process Injection via GetProcAddress Powershell Fileless Script Contains Base64 Encoded Content Powershell Load Module in Meterpreter PowerShell Loading DotNET into Memory via Reflection PowerShell PInvoke Process Injection API Chain Powershell Processing Stream Of Data PowerShell Script Block With URL Chain PowerShell Start or Stop Service Powershell Using memory As Backing Store PowerShell WebRequest Using Memory Stream Recon Using WMI Class Set Default PowerShell Execution Policy To Unrestricted or Bypass Unloading AMSI via Reflection Windows Account Access Removal via Logoff Exec Windows Cobalt Strike PowerShell Loader Windows Crowdstrike RTR Script Execution Windows Default Cobalt Strike PowerShell Beacon Windows Enable PowerShell Web Access Windows Explorer.exe Spawning PowerShell or Cmd Windows Explorer LNK Exploit Process Launch With Padding Windows File Download Via PowerShell Windows MSExchange Management Mailbox Cmdlet Usage Windows Powershell Cryptography Namespace Windows PowerShell FakeCAPTCHA Clipboard Execution Windows PowerShell Get CIMInstance Remote Computer Windows Powershell Import Applocker Policy Windows PowerShell Invoke-RestMethod IP Information Collection Windows PowerShell Invoke-Sqlcmd Execution Windows Powershell Logoff User via Quser Windows PowerShell Module File Created Windows PowerShell MSIX Package Installation Windows PowerShell Process Implementing Manual Base64 Decoder Windows PowerShell Process With Malicious String Windows Powershell RemoteSigned File Windows PowerShell ScheduleTask Windows PowerShell Script Block With Malicious String Windows PowerShell Script From WindowsApps Directory Windows PowerShell Script TabExpansion Direct Call Windows PowerShell WMI Win32 ScheduledJob Windows PowGoop Beacon Decoding Windows Shell Process from CrushFTP Windows Software Discovery Via PowerShell Windows SSH Proxy Command Windows Suspicious React or Next.js Child Process Cisco Secure Firewall - Communication Over Suspicious Ports Cisco Secure Firewall - Veeam CVE-2023-27532 Exploitation Activity CrushFTP Authentication Bypass Exploitation Any Powershell DownloadFile Any Powershell DownloadString First time seen command line argument Suspicious Powershell Command-Line Arguments [LLM] Node.js spawning shell/recon binaries or detached node -e loader [LLM] TeamCity server (java) process spawning an OS command interpreter — CVE-2026-63077 RCE [LLM] Payload or JSP web shell written by the TeamCity server process — CVE-2026-63077 [LLM] n8n/Node.js process spawning shell or recon utility (sandbox-escape RCE) [LLM] supportdev.exe Inno Setup loader spawning hidden-window PowerShell [LLM] OpenAM/Tomcat Java process spawning a shell — post-deserialization RCE (CVE-2026-62263) [LLM] ClickFix PowerShell loader spawning wscript to run downloaded VBScript [LLM] Hidden PowerShell pulls installer.exe from pixeldrain.com to %Temp% (self-deleting dropper) [LLM] Ruby interpreter spawning PowerShell -ExecutionPolicy bypass or /bin/sh (SleeperGem dropper) [LLM] MSHTA remote HTA launched by explorer→powershell chain (ACR Stealer fileless campaign) [LLM] Masqueraded 'Autoupdate' scheduled task run by PowerShell loader (ACR Stealer persistence) [LLM] PowerShell AMSI/ETW bypass reflection (UAT-11795 WLDR evasion) [LLM] In-memory WLDR PowerShell C2 implant (fileless, no -File, unusual parent) [LLM] SiYuan Electron renderer (nodeIntegration) spawning shell/LOLBin child — XSS-to-RCE [LLM] ZDI-CAN-25373 (CVE-2025-9491) LNK spawning PowerShell to fetch BusySnake loader Article-specific behavioural hunt — Missed incidents, persistent threats, and response gaps: Insights from compromis [LLM] npm/node postinstall script spawning a download or shell process (Mastra dropper pattern) [LLM] Gamaredon stealer exfiltration to S3-compatible cloud storage (Wasabi/Tebi/Intercolo) [LLM] axios RAT Windows payload drop (6202033.vbs/.ps1, ProgramData\wt) during npm install [LLM] Downloader or shell child of npm/pip install (postinstall RAT loader) [LLM] axios RAT Windows persistence: %PROGRAMDATA%\wt.exe drop + %TEMP%\6202033.vbs/.ps1 staging [LLM] Java/Tomcat process spawns OS command interpreter (post-Thymeleaf SSTI RCE) Article-specific behavioural hunt — axios Compromised on npm - Malicious Versions Drop Remote Access Trojan [LLM] PowerShell masquerading as Windows Terminal at %PROGRAMDATA%\wt.exe (Axios RAT Windows stage) [LLM] PowerShell copy masqueraded as Windows Terminal in %PROGRAMDATA% running 6202033.ps1 Article-specific behavioural hunt — Glassworm Strikes Popular React Native Phone Number Packages [LLM] MuddyWater SimpleHelp RMM client spawning shell or recon LOLBin [LLM] Pastebin-piping stager retrieved from rentry.co/openclaw-core (macOS/Linux ClawHub skill) [LLM] AI coding agent spawns remote fetch-and-execute (curl | bash / curl | source) Article-specific behavioural hunt — LongNosedGoblin tries to sniff out governmental affairs in Southeast Asia and Ja [LLM] Node.js process spawning interactive shell — suspected post-exploit RCE on Next.js / RSC server [LLM] Cursor IDE or VS Code spawning PowerShell/WScript from extensions folder (Solidity Language malware chain) [LLM] Tomcat/Java process spawns OS shell or LOLBin (post-webshell RCE) [LLM] Log4Shell RCE execution: java/javaw spawning a shell or LOLBinArticles citing this technique (274)
crit Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads art-06
crit CTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account Hijacking art-74
crit Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE art-75
crit Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller art-97
crit Begun, the Patch Wars have art-150
high GoSerpent: a persistent threat evolves with sophisticated data collection and exfiltration art-153
crit Winning 54% of the time art-214
crit ESET Threat Report H1 2026 art-221
crit When checking the URL isn’t enough: a Device Code Phishing attack via a Microsoft website art-246
high Catan and Mouse art-261
high The Global Namespace Risk: Universal Bucket Hijacking Technique for Cloud Data Exfiltration art-312
high Miasma and Hades Are Spreading Now: Detect Them on Developer Machines with Suspicious Files art-317
high Node-gyp Supply Chain Compromise: A Self-Propagating npm Worm That Hides in binding.gyp art-362
high Miasma supply chain attack: malicious code found in @redhat-cloud-services npm packages art-380
med Foul play: Fake FIFA websites target soccer fans looking for World Cup tickets, merchandise art-402
high The AntV Supply Chain Campaign Expands: Microsoft's `durabletask` PyPI Package Compromised art-422
crit Malicious node-ipc versions published to npm in suspected maintainer account compromise art-431
crit Mini Shai-Hulud Is Back: npm Worm Hits over 160 Packages, including Mistral and Tanstack art-440
high "A Mini Shai-Hulud Has Appeared": Bun-Based Stealer Hits SAP @cap-js and mbt npm Packages art-471
high Don't Panic: The Thymeleaf Template Injection That Only Hurts If You Let It (CVE-2026-40478) art-472
high Malicious Release of elementary-data PyPI Package Steals Cloud Credentials from Data Engineers art-475
high CanisterWorm: How a Self-Propagating npm Worm Is Spreading Backdoors Across the Ecosystem art-551
crit Malicious Polymarket Bot Hides in Hijacked dev-protocol GitHub Org and Steals Wallet Keys art-555
crit ForceMemo: Hundreds of GitHub Python Repos Compromised via Account Takeover and Force-Push art-556
high DRILLAPP: new backdoor targeting Ukrainian entities with possible links to Laundry Bear art-590
high 20+ Popular NPM Packages Compromised (Chalk, Debug, Strip-ANSI, Color-Convert, Wrap-ANSI...) art-640
crit ESET Threat Report H2 2025 art-732
high Security Advisory: Critical RCE Vulnerabilities in React Server Components (CVE-2025-55182) art-753
crit CISA KEV: CVE-2024-55956 — Cleo Multiple Products Unauthenticated File Upload Vulnerability art-1121
crit CISA KEV: CVE-2024-38226 — Microsoft Publisher Protection Mechanism Failure Vulnerability art-1230
high Defense in Depth art-1391
high Ethical hacking techniques art-1698
high Ethical Hacking: Top Tools art-1702
crit API Security Guide art-1751
high Securing the web (forward) art-1803
high Cybersecurity Hygiene 101 art-1824
crit Secure Python URL validation art-1937
high Securing PHP containers art-2082
crit CISA KEV: CVE-2014-6287 — Rejetto HTTP File Server (HFS) Remote Code Execution Vulnerability art-2438
high Snyk joins OpenSSF: Tackling open source supply chain security with a developer-first approach art-3066
med Python Poetry package manager and security integration with software composition analysis tool art-3260
crit XSS Attacks: The Next Wave art-3641
high A CEO's guide to Emacs art-3693