Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Execution/ T1059.003

T1059.003Windows Command Shell

T1059.003 — Windows Command Shell is a MITRE ATT&CK technique in the Execution tactic. Clankerusecase tracks 59 detection use cases covering it and 46 threat-intel articles citing it.

Execution
View on the matrix → Filter Detection Library MITRE official spec ↗
59Use cases
46Articles
0Sub-techniques
1Tactic

Use cases covering this technique (59)

[WEEKLY] Developer/Data-tooling Daemon Spawns Shell Child Seconds After POST to Runner/Exec Endpoint Internal exploit · alerting DSPDD [WEEKLY] Server / AI-agent process spawns shell or LOLBIN with public egress — post-RCE behavioural chain Internal exploit · alerting DSΣPDD [WEEKLY] Service-process parent spawns subprocess containing CLI-argument-injection tokens Internal exploit · alerting DSΣPDD CMD Carry Out String Command Parameter ESCU actions · hunting P CMD Echo Pipe - Escalation ESCU actions · alerting P Detect Prohibited Applications Spawning cmd exe ESCU actions · hunting P Detect Use of cmd exe to Launch Script Interpreters ESCU actions · hunting P Ryuk Wake on LAN Command ESCU actions · alerting P Windows Command Shell DCRat ForkBomb Payload ESCU actions · alerting P Windows File Association Modification via Ftype ESCU actions · hunting P Windows PowerShell FakeCAPTCHA Clipboard Execution ESCU actions · alerting P Windows Powershell History File Deletion ESCU actions · hunting P Windows PowerShell Invoke-Sqlcmd Execution ESCU actions · hunting P Windows Shell Process from CrushFTP ESCU actions · alerting P Windows SQLCMD Execution ESCU actions · hunting P Windows Suspicious React or Next.js Child Process ESCU actions · alerting P Windows TinyCC Shellcode Execution ESCU actions · alerting P CrushFTP Authentication Bypass Exploitation ESCU actions · alerting P First time seen command line argument ESCU actions · hunting P Potentially malicious code on commandline ESCU actions · hunting P Windows connhost exe started forcefully ESCU actions · alerting P [LLM] TeamCity server (java) process spawning an OS command interpreter — CVE-2026-63077 RCE Bespoke exploit · alerting DSΣPDDCS [LLM] n8n/Node.js process spawning shell or recon utility (sandbox-escape RCE) Bespoke exploit · alerting DSΣPDDCS [LLM] PTC Windchill Java/Tomcat web tier spawning OS command shell (web shell RCE) Bespoke exploit · alerting DSΣPDDCS [LLM] OpenAM/Tomcat java process spawning shell or LOLBin — CVE-2026-62379 post-exploitation Bespoke install · alerting DSΣPDDCS [LLM] Node.js host process spawning OS shell (Nunjucks SSTI child_process.execSync RCE) Bespoke exploit · hunting DSΣPDDCS [LLM] Node.js process spawning shell / recon binary (velocityjs SSTI RCE execution) Bespoke exploit · alerting DSΣPDDCS [LLM] MSSQL sqlservr.exe spawning OS shell via xp_cmdshell (XEntry Team) Bespoke exploit · alerting DSΣPDDCS [LLM] ClickFix mshta.exe silently executing remote HTA then dropping batch (UAT-11795 initial access) Bespoke delivery · alerting DSΣPDDCS [LLM] Python setup.py install-time code execution spawning shell/LOLBin Bespoke exploit · alerting DSΣPDDCS [LLM] SiYuan Electron renderer (nodeIntegration) spawning shell/LOLBin child — XSS-to-RCE Bespoke exploit · alerting DSΣPDDCS [LLM] Craft/PHP/IIS web worker spawning a command shell (Formie SSTI RCE outcome) Bespoke exploit · alerting DSΣPDDCS [LLM] Mautic Twig SSTI RCE: PHP/web process spawns OS shell (CVE-2026-9558) Bespoke exploit · alerting DSΣPDDCS [LLM] Web shell execution: web server process spawning command interpreters Bespoke exploit · alerting DSΣPDDCS [LLM] npm/node postinstall script spawning a download or shell process (Mastra dropper pattern) Bespoke install · hunting DSΣPDDCS [LLM] IIS web shell (w3wp.exe) spawning recon, curl exfil, or RAR staging Bespoke exploit · hunting DSΣPDDCS [LLM] EchoCreep Discord API beacon from non-browser process (Webworm 2025) Bespoke c2 · hunting DSΣPDDCS [LLM] Java/Tomcat process spawns OS command interpreter (post-Thymeleaf SSTI RCE) Bespoke actions · alerting DSΣPDDCS [LLM] Force-install of IDE extension via cmd.exe with --install-extension flag spawned by node host Bespoke install · alerting DSΣPDD [LLM] IoliteLabs VSCode extension dropper: VS Code child process reaching rraghh.com / oortt.com C2 Bespoke delivery · alerting DSΣPDD [LLM] VSCode/VSCodium spawning shell or curl to raw.githubusercontent.com/BlokTrooper Bespoke delivery · alerting DSΣPDDCS [LLM] MuddyWater SimpleHelp RMM client spawning shell or recon LOLBin Bespoke install · alerting DSΣP [LLM] Node.js process spawning interactive shell — suspected post-exploit RCE on Next.js / RSC server Bespoke exploit · alerting DSΣPDDCS [LLM] Tomcat/Java process spawns OS shell or LOLBin (post-webshell RCE) Bespoke actions · alerting DSΣPDDCS [LLM] .NET build (dotnet/MSBuild) spawns git config to harvest user.email Bespoke actions · hunting DSΣPDDCS [LLM] Node.js process spawning a command interpreter (deserialization RCE child_process exec) Bespoke exploit · alerting DSΣPDDCS [LLM] Java process (java.exe/javaw.exe) spawning OS command shell — SnakeYAML RCE Bespoke exploit · hunting DSΣPDDCS [LLM] Git argument injection via --upload-pack option spawned by web-app runtime Bespoke exploit · alerting DSΣPDDCS [LLM] Mercurial argument injection via --config alias/hooks or --debugger from app runtime Bespoke exploit · alerting DSΣPDDCS [LLM] git/hg spawning a shell as child of a web-app runtime (argument-injection RCE evidence) Bespoke exploit · hunting DSPDDCS [LLM] Tomcat/Java JVM spawning command shell (Spring4Shell webshell command execution) Bespoke actions · hunting DSΣPDDCS [LLM] npm/yarn install spawning anomalous shell or working-dir binary (.npmrc/.yarnrc config override RCE) Bespoke exploit · hunting DSΣPDDCS [LLM] Magento web process (w3wp/php-fpm/php-cgi) spawning OS shell — CVE-2022-24086 RCE Bespoke exploit · alerting DSΣPDDCS [LLM] Java/Tomcat process spawning OS shell (Log4Shell Runtime.exec post-exploitation) Bespoke install · alerting DSΣPDDCS [LLM] Java (java.exe/javaw.exe) spawning shell or LOLBin — Log4Shell post-exploitation Bespoke install · alerting DSΣPDDCS [LLM] Node.js (Express) process spawning a command shell — express-fileupload prototype-pollution RCE outcome Bespoke exploit · hunting DSΣPDDCS [LLM] Node.js process spawning OS command shell (child_process.exec backdoor) Bespoke install · hunting DSΣPDDCS [LLM] Zip Slip RCE: archive-extraction process spawns command interpreter Bespoke exploit · hunting DSΣPDDCS [LLM] Apache Struts web app (java/Tomcat) spawning OS shell or recon — post-exploit RCE (CVE-2017-5638 / CVE-2017-9805) Bespoke exploit · alerting DSΣPDDCS

Articles citing this technique (46)