T1059.003Windows Command Shell
T1059.003 — Windows Command Shell is a MITRE ATT&CK technique in the Execution tactic. Clankerusecase tracks 59 detection use cases covering it and 46 threat-intel articles citing it.
Execution
59Use cases
46Articles
0Sub-techniques
1Tactic
↑ Parent technique: T1059 · Command and Scripting Interpreter
Use cases covering this technique (59)
[WEEKLY] Developer/Data-tooling Daemon Spawns Shell Child Seconds After POST to Runner/Exec Endpoint [WEEKLY] Server / AI-agent process spawns shell or LOLBIN with public egress — post-RCE behavioural chain [WEEKLY] Service-process parent spawns subprocess containing CLI-argument-injection tokens CMD Carry Out String Command Parameter CMD Echo Pipe - Escalation Detect Prohibited Applications Spawning cmd exe Detect Use of cmd exe to Launch Script Interpreters Ryuk Wake on LAN Command Windows Command Shell DCRat ForkBomb Payload Windows File Association Modification via Ftype Windows PowerShell FakeCAPTCHA Clipboard Execution Windows Powershell History File Deletion Windows PowerShell Invoke-Sqlcmd Execution Windows Shell Process from CrushFTP Windows SQLCMD Execution Windows Suspicious React or Next.js Child Process Windows TinyCC Shellcode Execution CrushFTP Authentication Bypass Exploitation First time seen command line argument Potentially malicious code on commandline Windows connhost exe started forcefully [LLM] TeamCity server (java) process spawning an OS command interpreter — CVE-2026-63077 RCE [LLM] n8n/Node.js process spawning shell or recon utility (sandbox-escape RCE) [LLM] PTC Windchill Java/Tomcat web tier spawning OS command shell (web shell RCE) [LLM] OpenAM/Tomcat java process spawning shell or LOLBin — CVE-2026-62379 post-exploitation [LLM] Node.js host process spawning OS shell (Nunjucks SSTI child_process.execSync RCE) [LLM] Node.js process spawning shell / recon binary (velocityjs SSTI RCE execution) [LLM] MSSQL sqlservr.exe spawning OS shell via xp_cmdshell (XEntry Team) [LLM] ClickFix mshta.exe silently executing remote HTA then dropping batch (UAT-11795 initial access) [LLM] Python setup.py install-time code execution spawning shell/LOLBin [LLM] SiYuan Electron renderer (nodeIntegration) spawning shell/LOLBin child — XSS-to-RCE [LLM] Craft/PHP/IIS web worker spawning a command shell (Formie SSTI RCE outcome) [LLM] Mautic Twig SSTI RCE: PHP/web process spawns OS shell (CVE-2026-9558) [LLM] Web shell execution: web server process spawning command interpreters [LLM] npm/node postinstall script spawning a download or shell process (Mastra dropper pattern) [LLM] IIS web shell (w3wp.exe) spawning recon, curl exfil, or RAR staging [LLM] EchoCreep Discord API beacon from non-browser process (Webworm 2025) [LLM] Java/Tomcat process spawns OS command interpreter (post-Thymeleaf SSTI RCE) [LLM] Force-install of IDE extension via cmd.exe with --install-extension flag spawned by node host [LLM] IoliteLabs VSCode extension dropper: VS Code child process reaching rraghh.com / oortt.com C2 [LLM] VSCode/VSCodium spawning shell or curl to raw.githubusercontent.com/BlokTrooper [LLM] MuddyWater SimpleHelp RMM client spawning shell or recon LOLBin [LLM] Node.js process spawning interactive shell — suspected post-exploit RCE on Next.js / RSC server [LLM] Tomcat/Java process spawns OS shell or LOLBin (post-webshell RCE) [LLM] .NET build (dotnet/MSBuild) spawns git config to harvest user.email [LLM] Node.js process spawning a command interpreter (deserialization RCE child_process exec) [LLM] Java process (java.exe/javaw.exe) spawning OS command shell — SnakeYAML RCE [LLM] Git argument injection via --upload-pack option spawned by web-app runtime [LLM] Mercurial argument injection via --config alias/hooks or --debugger from app runtime [LLM] git/hg spawning a shell as child of a web-app runtime (argument-injection RCE evidence) [LLM] Tomcat/Java JVM spawning command shell (Spring4Shell webshell command execution) [LLM] npm/yarn install spawning anomalous shell or working-dir binary (.npmrc/.yarnrc config override RCE) [LLM] Magento web process (w3wp/php-fpm/php-cgi) spawning OS shell — CVE-2022-24086 RCE [LLM] Java/Tomcat process spawning OS shell (Log4Shell Runtime.exec post-exploitation) [LLM] Java (java.exe/javaw.exe) spawning shell or LOLBin — Log4Shell post-exploitation [LLM] Node.js (Express) process spawning a command shell — express-fileupload prototype-pollution RCE outcome [LLM] Node.js process spawning OS command shell (child_process.exec backdoor) [LLM] Zip Slip RCE: archive-extraction process spawns command interpreter [LLM] Apache Struts web app (java/Tomcat) spawning OS shell or recon — post-exploit RCE (CVE-2017-5638 / CVE-2017-9805)Articles citing this technique (46)
crit Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE art-75
crit Begun, the Patch Wars have art-150
high Don't Panic: The Thymeleaf Template Injection That Only Hurts If You Let It (CVE-2026-40478) art-472