T1059.003Windows Command Shell
T1059.003 — Windows Command Shell is a MITRE ATT&CK technique in the Execution tactic. Clankerusecase tracks 58 detection use cases covering it and 45 threat-intel articles citing it.
Execution
58Use cases
45Articles
0Sub-techniques
1Tactic
↑ Parent technique: T1059 · Command and Scripting Interpreter
Use cases covering this technique (58)
[WEEKLY] Developer/Data-tooling Daemon Spawns Shell Child Seconds After POST to Runner/Exec Endpoint [WEEKLY] Internet-Facing Service Daemon Spawns Shell or Ingress Tool Then Beacons Out [WEEKLY] Server / AI-agent process spawns shell or LOLBIN with public egress — post-RCE behavioural chain [WEEKLY] Service-process parent spawns subprocess containing CLI-argument-injection tokens CMD Carry Out String Command Parameter CMD Echo Pipe - Escalation Detect Prohibited Applications Spawning cmd exe Detect Use of cmd exe to Launch Script Interpreters Ryuk Wake on LAN Command Windows Command Shell DCRat ForkBomb Payload Windows File Association Modification via Ftype Windows PowerShell FakeCAPTCHA Clipboard Execution Windows Powershell History File Deletion Windows PowerShell Invoke-Sqlcmd Execution Windows Shell Process from CrushFTP Windows SQLCMD Execution Windows Suspicious React or Next.js Child Process Windows TinyCC Shellcode Execution CrushFTP Authentication Bypass Exploitation First time seen command line argument Potentially malicious code on commandline Windows connhost exe started forcefully [LLM] PTC Windchill Java/Tomcat process spawning shell or flst.txt recon [LLM] SAP Commerce (Hybris) Java process spawning OS command shell — CVE-2026-58231 RCE payoff [LLM] Jewelbug XG-Web native-messaging host 'com.microsoft.runedge' registered [LLM] Browser directly spawning cmd.exe (XG-Web native-messaging shell) [LLM] ColdFusion server process spawning OS shell / LOLBin (CVE-2026-48362 / CVE-2026-48273 RCE) [LLM] Nuxt/Vite dev server (node.exe) spawns shell or LOLBin child — DevTools RPC RCE [LLM] Flowise Node.js process spawning shell/interpreter child (CSVAgent RCE) [LLM] OctLurk deployment via 'GoogleUpDate' scheduled task launching Videos\1.bat [LLM] OpenAM/Tomcat java process spawning shell or LOLBin — CVE-2026-62379 post-exploitation [LLM] Node.js host process spawning OS shell (Nunjucks SSTI child_process.execSync RCE) [LLM] Node.js process spawning shell / recon binary (velocityjs SSTI RCE execution) [LLM] ClickFix mshta.exe silently executing remote HTA then dropping batch (UAT-11795 initial access) [LLM] SiYuan Electron renderer (nodeIntegration) spawning shell/LOLBin child — XSS-to-RCE [LLM] npm/node postinstall script spawning a download or shell process (Mastra dropper pattern) [LLM] EchoCreep Discord API beacon from non-browser process (Webworm 2025) [LLM] Java/Tomcat process spawns OS command interpreter (post-Thymeleaf SSTI RCE) [LLM] Force-install of IDE extension via cmd.exe with --install-extension flag spawned by node host [LLM] IoliteLabs VSCode extension dropper: VS Code child process reaching rraghh.com / oortt.com C2 [LLM] MuddyWater SimpleHelp RMM client spawning shell or recon LOLBin [LLM] Node.js process spawning interactive shell — suspected post-exploit RCE on Next.js / RSC server [LLM] Tomcat/Java process spawns OS shell or LOLBin (post-webshell RCE) [LLM] .NET build (dotnet/MSBuild) spawns git config to harvest user.email [LLM] Node.js process spawning a command interpreter (deserialization RCE child_process exec) [LLM] Java process (java.exe/javaw.exe) spawning OS command shell — SnakeYAML RCE [LLM] Git argument injection via --upload-pack option spawned by web-app runtime [LLM] Mercurial argument injection via --config alias/hooks or --debugger from app runtime [LLM] git/hg spawning a shell as child of a web-app runtime (argument-injection RCE evidence) [LLM] Tomcat/Java JVM spawning command shell (Spring4Shell webshell command execution) [LLM] npm/yarn install spawning anomalous shell or working-dir binary (.npmrc/.yarnrc config override RCE) [LLM] Magento web process (w3wp/php-fpm/php-cgi) spawning OS shell — CVE-2022-24086 RCE [LLM] Java/Tomcat process spawning OS shell (Log4Shell Runtime.exec post-exploitation) [LLM] Java (java.exe/javaw.exe) spawning shell or LOLBin — Log4Shell post-exploitation [LLM] Node.js (Express) process spawning a command shell — express-fileupload prototype-pollution RCE outcome [LLM] Node.js process spawning OS command shell (child_process.exec backdoor) [LLM] Zip Slip RCE: archive-extraction process spawns command interpreter [LLM] Apache Struts web app (java/Tomcat) spawning OS shell or recon — post-exploit RCE (CVE-2017-5638 / CVE-2017-9805)Articles citing this technique (45)
crit Begun, the Patch Wars have art-253
high Don't Panic: The Thymeleaf Template Injection That Only Hurts If You Let It (CVE-2026-40478) art-517