T1059.003Windows Command Shell
T1059.003 — Windows Command Shell is a MITRE ATT&CK technique in the Execution tactic. Clankerusecase tracks 52 detection use cases covering it and 41 threat-intel articles citing it.
Execution
52Use cases
41Articles
0Sub-techniques
1Tactic
↑ Parent technique: T1059 · Command and Scripting Interpreter
Use cases covering this technique (52)
[WEEKLY] Developer/Data-tooling Daemon Spawns Shell Child Seconds After POST to Runner/Exec Endpoint [WEEKLY] Server / AI-agent process spawns shell or LOLBIN with public egress — post-RCE behavioural chain [WEEKLY] Service-process parent spawns subprocess containing CLI-argument-injection tokens CMD Carry Out String Command Parameter CMD Echo Pipe - Escalation Detect Prohibited Applications Spawning cmd exe Detect Use of cmd exe to Launch Script Interpreters Ryuk Wake on LAN Command Windows Command Shell DCRat ForkBomb Payload Windows File Association Modification via Ftype Windows PowerShell FakeCAPTCHA Clipboard Execution Windows Powershell History File Deletion Windows PowerShell Invoke-Sqlcmd Execution Windows Shell Process from CrushFTP Windows SQLCMD Execution Windows Suspicious React or Next.js Child Process Windows TinyCC Shellcode Execution CrushFTP Authentication Bypass Exploitation First time seen command line argument Potentially malicious code on commandline Windows connhost exe started forcefully [LLM] splunkd spawning shell interpreters (CVE-2026-20253 post-exploit RCE) [LLM] AI coding agent (Claude Code / Cursor / Codex) spawning shell that fetch-and-executes remote payload [LLM] Webserver / PHP interpreter spawns shell or LOLBin — post-upload RCE indicator [LLM] Public-facing MSSQL sqlservr.exe spawns suspicious child (OceanLotus transport-construction intrusion vector) [LLM] FireAnt Metakit updater spawning unexpected child (supply-chain compromise) [LLM] npm install lifecycle script spawns interpreter or network-fetcher child [LLM] Chrome browser spawning LOLBin children post-V8 sandbox-escape (CVE-2026-11645) [LLM] DbGate node process spawning shell child (post-exploit RCE) [LLM] Stata binary spawning OS shell (CVE-2026-47708 stata-mcp log_file_name injection) [LLM] Post-exploit shell spawned by Vitest node.exe via rerun / saveTestFile (CVE-2026-47429) [LLM] Node.js process spawning native shell / interpreter — post-vm2-escape host execution [LLM] Node.js process spawning OS shell with enumeration commands — vm2 sandbox escape (CVE-2026-47137) [LLM] node.exe spawning child_process targets — vm2 Promise species sandbox escape post-exploitation [LLM] EchoCreep Discord API beacon from non-browser process (Webworm 2025) [LLM] Kopia process spawns ssh with -oProxyCommand= argument (CVE-2026-45695) [LLM] SSH process spawned by Kopia invokes a shell child (ProxyCommand execution) [LLM] GlassFish java process spawning command shell (CVE-2026-2587 RCE) [LLM] Apache Camel JVM spawning shell or command interpreter via camel-exec (CVE-2026-47323 post-exploit) [LLM] MLflow server process spawning Claude Code CLI or shell — CVE-2026-2611 RCE chain [LLM] Web-server process (w3wp/php/nginx) spawns shell or LOLBin (post-SSTI RCE chain) [LLM] Flowise node.exe Spawning OS Shell or Command-Line Utility - Post-Exploit RCE (CVE-2026-46442) [LLM] Java/Tomcat process spawns OS command interpreter (post-Thymeleaf SSTI RCE) [LLM] Force-install of IDE extension via cmd.exe with --install-extension flag spawned by node host [LLM] IoliteLabs VSCode extension dropper: VS Code child process reaching rraghh.com / oortt.com C2 [LLM] VSCode/VSCodium spawning shell or curl to raw.githubusercontent.com/BlokTrooper [LLM] MuddyWater SimpleHelp RMM client spawning shell or recon LOLBin [LLM] APT28 MacroMaze: schtasks creating wscript-launched persistence with 20/30/61-minute repeat [LLM] Node.js process spawning interactive shell — suspected post-exploit RCE on Next.js / RSC server [LLM] SnakeStealer Wi-Fi Credential Harvest via netsh wlan show profile key=clear [LLM] Tomcat/Java process spawns OS shell or LOLBin (post-webshell RCE) [LLM] .NET build (dotnet/MSBuild) spawns git config to harvest user.emailArticles citing this technique (41)
crit [GHSA / CRITICAL] CVE-2026-47208: vm2 is Vulnerable to Sandbox Breakout Through Promise Species art-176
crit From PDB strings to MaaS: Tracking a commodity BadIIS ecosystem used by Chinese-speaking threat art-265
high Don't Panic: The Thymeleaf Template Injection That Only Hurts If You Let It (CVE-2026-40478) art-349