Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Execution/ T1059.004

T1059.004Unix Shell

T1059.004 — Unix Shell is a MITRE ATT&CK technique in the Execution tactic. Clankerusecase tracks 146 detection use cases covering it and 98 threat-intel articles citing it.

Execution
View on the matrix → Filter Detection Library MITRE official spec ↗
146Use cases
98Articles
0Sub-techniques
1Tactic

Use cases covering this technique (146)

[WEEKLY] AI-Agent Server (PraisonAI/MCP) Spawns OS Shell or Recon LOLBin — Unauthenticated RCE Exploitation Internal exploit · alerting DSΣPDDCS [WEEKLY] AI/LLM Agent Framework Runtime Spawning Shell, Recon, or Egress Child Process Internal exploit · alerting DSΣPDDCS [WEEKLY] AI/LLM Framework Web Service Spawns Shell or Network Tool (Agent-Framework Unauthenticated RCE) Internal exploit · alerting DSΣPDDCS [WEEKLY] Cross-Platform ClickFix Paste-to-Pipe Loader (UI-Parent Shell with Decode-and-Execute Payload) Internal delivery · alerting DSΣP [WEEKLY] Developer/AI tooling runtime spawns shell or egress LOLBin (unauth RCE post-expl) Internal exploit · alerting DSPDDCS [WEEKLY] Developer/Data-tooling Daemon Spawns Shell Child Seconds After POST to Runner/Exec Endpoint Internal exploit · alerting DSPDD [WEEKLY] Internet-Exposed AI Agent/LLM Service Spawns Shell or LOLBin After Inbound Connection Internal exploit · alerting DSΣPDDCS [WEEKLY] Internet-Facing Service Process Spawning Unix Shell or Ingress-Tool LOLBin (Edge Zero-Day Post-Exploit) Internal install · alerting DSΣPDD [WEEKLY] Internet-facing service process spawns shell/LOLBin within minutes of public inbound connection — post-RCE command execution Internal exploit · alerting DSΣPDD [WEEKLY] Low-Code / AI Workflow Runtime Sandbox-Escape — Server Process Spawns Shell + Public Egress Internal exploit · alerting DSΣPDD [WEEKLY] Package install lifecycle hook spawns interpreter that reads developer credential stores Internal install · alerting DSPCS [WEEKLY] Package Manager / Dev-Tool Auto-Execution Triggers Non-Registry Egress or Credential-Store Access Internal install · alerting DSPDD [WEEKLY] Package-Manager Install -> Interpreter Child -> Non-Registry Egress Within 5 Minutes Internal install · alerting DSPDD [WEEKLY] Package manager lifecycle hook spawns network-fetching shell or runtime Internal install · alerting DSΣPDD [WEEKLY] Package manager spawns network-fetching child to public code-hosting within minutes of install Internal install · alerting DSPDD [WEEKLY] Self-hosted application service spawns shell or SSH within seconds of inbound unauthenticated API write Internal exploit · alerting DSPDD [WEEKLY] Server / AI-agent process spawns shell or LOLBIN with public egress — post-RCE behavioural chain Internal exploit · alerting DSΣPDD [WEEKLY] Service-process parent spawns subprocess containing CLI-argument-injection tokens Internal exploit · alerting DSΣPDD [WEEKLY] Web App Interpreter (Node/Python/Java/PHP) Spawns Shell or Net-Download LOLBin on Internet-Facing Host Internal exploit · alerting DSPDD [WEEKLY] Web-Server Process Post-Exploit Anchor: Plugin/Extension RCE Leading to Shell Spawn or Webroot Script Drop Internal install · alerting DSΣPDD Linux Decode Base64 to Shell ESCU actions · alerting P Linux Magic SysRq Key Abuse ESCU actions · alerting P Linux Suspicious React or Next.js Child Process ESCU actions · alerting P Linux Unix Shell Enable All SysRq Functions ESCU actions · hunting P MacOS LOLbin ESCU actions · alerting P Suspicious Linux Discovery Commands ESCU actions · alerting P [LLM] Cisco FMC www account runs package_info.pl on staged /var/tmp/license.tmp (CVE-2026-20316/20079) Bespoke exploit · alerting SΣPDD [LLM] Fluentd config injection via Flow/Output CRD record_transformer (block-close + @type exec) Bespoke exploit · alerting SΣPDD [LLM] Fluentd aggregator pod spawns a shell (out_exec RCE execution) Bespoke install · alerting DSΣPDDCS [LLM] Shell/curl spawned under Fluentd aggregator makes external network egress (post-RCE C2/exfil) Bespoke c2 · hunting DSPDDCS [LLM] JFrog Artifactory service process spawning a shell or downloader (RCE exploitation) Bespoke exploit · alerting DSΣPCS [LLM] Ruflo MCP bridge unauthenticated tools/call terminal_execute (RufRoot CVE-2026-59726) Bespoke exploit · alerting SΣPDD [LLM] Ruflo/Node MCP bridge spawning interactive shell inside container (RufRoot RCE) Bespoke exploit · alerting DSΣPDDCS [LLM] Gitea git process spawning shell / network tool via planted hook (CVE-2026-60004 RCE) Bespoke exploit · alerting DSΣPDDCS [LLM] JFrog Artifactory service process spawning a shell or network tool (RCE) Bespoke exploit · alerting DSΣPCS [LLM] vBulletin web-server process (php-fpm/apache/nginx) spawning OS shell after CVE-2026-61511 Bespoke actions · alerting DSΣPDDCS [LLM] LuCI luci-app-commands / ddns command injection with shell metacharacters — root RCE Bespoke exploit · alerting SP [LLM] n8n/Node.js process spawning shell or recon utility (sandbox-escape RCE) Bespoke exploit · alerting DSΣPDDCS [LLM] GitLab Puma/Ruby worker (running as git) spawns shell or network tool — Oj .ipynb RCE landing Bespoke exploit · hunting DSΣPDDCS [LLM] OpenAM/Tomcat java process spawning shell or LOLBin — CVE-2026-62379 post-exploitation Bespoke install · alerting DSΣPDDCS [LLM] OpenAM/Tomcat Java process spawning a shell — post-deserialization RCE (CVE-2026-62263) Bespoke exploit · alerting DSΣPDDCS [LLM] Node.js host process spawning OS shell (Nunjucks SSTI child_process.execSync RCE) Bespoke exploit · hunting DSΣPDDCS [LLM] Node.js process spawning shell / recon binary (velocityjs SSTI RCE execution) Bespoke exploit · alerting DSΣPDDCS [LLM] redis-server spawns a shell/interpreter (system() from Redis RCE chain) Bespoke exploit · alerting DSΣPCS [LLM] SleeperGem loader: ruby install script spawns shell running deploy.sh Bespoke install · alerting DSΣPDDCS [LLM] Ruby interpreter spawning PowerShell -ExecutionPolicy bypass or /bin/sh (SleeperGem dropper) Bespoke exploit · hunting DSΣPDDCS [LLM] Web server daemon (php-fpm/apache/nginx/w3wp) spawning a shell or network tool — wp2shell post-exploit code execution Bespoke exploit · alerting DSΣPDDCS [LLM] Pheditor terminal RCE: web-server/PHP process spawns shell (CVE-2026-55579) Bespoke exploit · alerting DSΣPDDCS [LLM] Reverse shell via cron/webshell payload dropped through Anyquery AFW (/dev/tcp) Bespoke c2 · alerting DSΣPDDCS [LLM] DIRAC FileCatalog checkDataset SQL injection carrying Python eval gadget (CVE-2026-61667) Bespoke exploit · hunting SPDD [LLM] DIRAC FileCatalog service Python process spawns shell or recon binary (eval RCE) Bespoke install · alerting DSΣPDDCS [LLM] DIRAC ReqManager service (CVE-2026-45579) spawning a shell or recon/egress binary Bespoke exploit · alerting DSΣP [LLM] File Browser hook-auth pre-auth RCE: filebrowser spawns shell/recon commands (CVE-2026-54088) Bespoke exploit · alerting DSΣPCS [LLM] File Browser hook-auth RCE follow-on: reverse shell / egress tooling under filebrowser (CVE-2026-54088) Bespoke c2 · alerting DSΣPCS [LLM] YesWiki Bazar CalcField eval() RCE — dangerous PHP functions in form-save request Bespoke exploit · alerting SΣP [LLM] YesWiki post-RCE — php-fpm/apache spawns Unix shell or recon binary (www-data) Bespoke install · alerting DSΣPDDCS [LLM] YesWiki CalcField exploit attempts — PHP parse/fatal errors from CalcField.php in syslog Bespoke exploit · hunting SPDD [LLM] YesWiki web-server process spawning an OS shell (deserialization RCE outcome) Bespoke exploit · alerting DSΣPDDCS [LLM] Git-spawned hook execution during recursive clone (CVE-2024-32002) Bespoke exploit · alerting DSΣPDDCS [LLM] Joro native plugin RCE: joro process spawns interactive /bin/bash shell (CVE-2026-53649) Bespoke exploit · alerting DSΣPCS [LLM] Nuclio CronJob container args carry injected shell (CVE-2026-52831 header/body OS command injection) Bespoke exploit · alerting SPDD [LLM] EGroupware web runtime (php-fpm/apache) spawning a shell or network tool — CVE-2026-27823 RCE execution Bespoke actions · hunting DSΣPCS [LLM] DOGLEASH ELF payload download from UAT-7810 servers on Linux/embedded devices Bespoke install · hunting DSΣPDDCS [LLM] Langroid Python agent spawning shell/downloader child (os.system RCE) Bespoke exploit · hunting DSΣPCS [LLM] Craft/PHP/IIS web worker spawning a command shell (Formie SSTI RCE outcome) Bespoke exploit · alerting DSΣPDDCS [LLM] 9router unauthenticated MCP / cli-tools route RCE via process spawn — CVE-2026-46339 Bespoke exploit · alerting DSΣPCS [LLM] 9router (node) process spawning 'sudo -S sh' — CVE-2026-59800 command injection primitive Bespoke exploit · hunting DSΣPDDCS [LLM] 9router chain: node fetches tailscale.com/install.sh then spawns sudo -S sh within seconds Bespoke exploit · alerting DSPCS [LLM] Mautic Twig SSTI RCE: PHP/web process spawns OS shell (CVE-2026-9558) Bespoke exploit · alerting DSΣPDDCS [LLM] cluw macOS stealer shell dropper fetching payload from ClawHavoc/AMOS C2 IP Bespoke install · hunting DSΣPCS [LLM] OpenClaw paste-site (rentry.co/glot.io) curl-pipe-bash semantic-hijack dropper Bespoke delivery · hunting DSΣPCS [LLM] macOS.Gaslight self-staged standalone CPython 3.10.18 fetch (astral-sh python-build-standalone) Bespoke install · alerting DSΣPCS [LLM] Atomic Arch payload execution: JS runtime spawning shell/network tooling under AUR build (or known payload hash) Bespoke install · alerting DSPDDCS [LLM] Phantom Gyp: node-gyp install-time code execution via weaponized binding.gyp Bespoke exploit · alerting DSΣPDDCS [LLM] PHP CLI drops hidden /tmp dropper artefacts (Laravel-Lang autoload payload) Bespoke install · alerting DSΣPDDCS [LLM] Composer install of malicious helpers.php in laravel-lang vendor package Bespoke delivery · hunting DSΣPDDCS [LLM] Megalodon harvester: curl POST to C2 /collect endpoint on Linux runner Bespoke actions · alerting DSΣPDDCS [LLM] Stage-3 exfil archive trin.tar.gz POST via curl --data-binary Bespoke actions · alerting DSΣPDDCS [LLM] Java/Tomcat process spawns OS command interpreter (post-Thymeleaf SSTI RCE) Bespoke actions · alerting DSΣPDDCS [LLM] Qinglong CVE-2026-4047 case-mismatch auth bypass via /aPi/system/command-run Bespoke exploit · alerting DSΣPDD [LLM] Qinglong .fullgc cryptominer execution with nohup backgrounding Bespoke install · alerting DSΣPDD [LLM] Stage-2 implant masquerading as node-health-check daemon (/tmp/.kh, /tmp/.ns) Bespoke install · alerting DSΣPDD [LLM] node process spawning bash/curl chain to fetch Velora DEX install.sh dropper Bespoke delivery · alerting DSΣPDDCS [LLM] hackerbot-claw second-stage download: curl -sSfL pipe-bash from hackmoltrepeat.com/molt Bespoke install · alerting DSΣPDDCS [LLM] Python process spawning shell with TeamPCP recon chain (hostname; whoami; uname; ip addr fallback) Bespoke actions · alerting DSΣPDDCS [LLM] npm postinstall SSH-backdoor chain: node spawning sudo ufw allow 22/tcp + chown ~/.ssh Bespoke install · alerting DSΣPDD [LLM] Bash-spawned curl to xygeni-action C2 nip.io endpoint with /b/in /b/q /b/r path on CI runner Bespoke c2 · alerting DSΣPDDCS [LLM] Cloudflare-tunnel curl-piped Python stager (kamikaze.sh / kube.py) Bespoke delivery · alerting DSΣPDDCS [LLM] Exfiltration to kubernetes-el attacker webhook.site UUIDs (Pwn Request payload) Bespoke c2 · alerting DSΣPDD [LLM] Compromised kubernetes.el destructive payload — Emacs spawning `rm -rf / --no-preserve-root` Bespoke actions · alerting DSΣPDD [LLM] Local AI coding agents (claude/gemini/q) launched with permission-bypass flags during package install — s1ngularity Bespoke install · alerting DSΣPDDCS [LLM] tj-actions/changed-files compromise: memdump.py secret-exfiltration shell pattern on runner (CVE-2025-30066) Bespoke actions · alerting DSΣPDD [LLM] Pastebin-piping stager retrieved from rentry.co/openclaw-core (macOS/Linux ClawHub skill) Bespoke delivery · alerting DSPDDCS [LLM] SKILL.md file written referencing fabricated openclaw-core prerequisite (ClawHub skill social engineering hook) Bespoke weapon · hunting DSPDDCS [LLM] Installation of credential-leaking ClawHub skills (moltyverse-email, buy-anything, prompt-log, youtube-data) Bespoke install · alerting DSΣPDDCS [LLM] AI agent skill leaks Stripe key or card PAN/CVC verbatim in curl command line Bespoke actions · alerting DSΣPDDCS [LLM] AI coding agent spawns remote fetch-and-execute (curl | bash / curl | source) Bespoke install · alerting DSΣPDDCS [LLM] Node.js process spawning interactive shell — suspected post-exploit RCE on Next.js / RSC server Bespoke exploit · alerting DSΣPDDCS [LLM] AI coding agent CLI (claude/gemini/q) invoked with permission-bypass flags Bespoke actions · alerting DSΣPDDCS [LLM] Malicious tj-actions base64 payload prefix observed in process command line Bespoke exploit · alerting DSΣPDDCS [LLM] Apache Spark CVE-2022-33891 doAs command injection — shell spawned by Spark JVM running 'id -Gn' with metacharacters Bespoke exploit · alerting DSΣPDDCS [LLM] GitPython CVE-2022-24439 RCE — git 'ext::sh' transport command injection via crafted clone URL Bespoke exploit · alerting DSΣPDDCS [LLM] GitHub Actions branch-name template injection — bash brace-expansion shell signature Bespoke exploit · alerting DSΣPDDCS [LLM] Outbound fetch of file.sh via attacker-controlled commit d8daa0b... on raw.githubusercontent.com Bespoke c2 · alerting DSΣPDDCS [LLM] ImageMagick 'convert -resize' command injection via sh -c in Go web app Bespoke exploit · hunting DSΣPDDCS [LLM] cups-browsed spawning foomatic-rip or shell child (CVE-2024-47177 RCE) Bespoke exploit · alerting DSΣPDDCS [LLM] Tomcat/Java process spawns OS shell or LOLBin (post-webshell RCE) Bespoke actions · alerting DSΣPDDCS [LLM] PHP web-server process initiating outbound TCP (fsockopen reverse shell to attacker) Bespoke c2 · alerting DSΣPCS [LLM] PHP CLI dev server (php -S) spawning a shell or child interpreter (proc_open php -a) Bespoke exploit · alerting DSΣPDDCS [LLM] macOS Text Replacements exfiltration via `defaults read NSUserDictionaryReplacementItems` Bespoke actions · alerting DSΣPCS [LLM] Node.js process spawning a command interpreter (deserialization RCE child_process exec) Bespoke exploit · alerting DSΣPDDCS [LLM] Package-manager install hook spawning host-recon curl/wget exfil (pre.sh pattern) Bespoke install · alerting DSΣPDDCS [LLM] Install of ypvpctpbamdhxtkzdu malicious package set (django-yauth + siblings) Bespoke delivery · hunting DSΣPDDCS [LLM] Ruby/Rails app server spawning a Unix shell (post-deserialization RCE) Bespoke exploit · alerting DSΣPCS [LLM] Git argument injection via --upload-pack option spawned by web-app runtime Bespoke exploit · alerting DSΣPDDCS [LLM] Mercurial argument injection via --config alias/hooks or --debugger from app runtime Bespoke exploit · alerting DSΣPDDCS [LLM] git/hg spawning a shell as child of a web-app runtime (argument-injection RCE evidence) Bespoke exploit · hunting DSPDDCS [LLM] Bash reverse shell via /dev/tcp file-descriptor redirection Bespoke install · alerting DSPDDCS [LLM] Server application runtime spawning shell with /dev/tcp redirection (RCE to reverse shell) Bespoke exploit · alerting DSΣPCS [LLM] Reverse shell via ncat -e spawned by Node.js app (SonicJS GraphQL path-traversal RCE) Bespoke c2 · alerting DSΣPDDCS [LLM] Tomcat/Java JVM spawning command shell (Spring4Shell webshell command execution) Bespoke actions · hunting DSΣPDDCS [LLM] Java/Tomcat spawns command shell or download tool (Spring4Shell RCE execution) Bespoke exploit · alerting DSΣPDDCS [LLM] npm/yarn install spawning anomalous shell or working-dir binary (.npmrc/.yarnrc config override RCE) Bespoke exploit · hunting DSΣPDDCS [LLM] Magento php-fpm/web-server spawning shell or download utility (CVE-2022-24086 RCE) Bespoke exploit · hunting DSΣPCS [LLM] Magento web process (w3wp/php-fpm/php-cgi) spawning OS shell — CVE-2022-24086 RCE Bespoke exploit · alerting DSΣPDDCS [LLM] Celery worker (Python) spawning a shell — CVE-2021-23727 stored command injection Bespoke exploit · hunting DSΣPCS [LLM] Root shell spawned by pkexec with empty parent command line (PwnKit post-exploitation) Bespoke install · alerting DSΣPCS [LLM] Log4Shell RCE execution: java/javaw spawning a shell or LOLBin Bespoke exploit · alerting DSΣPDDCS [LLM] Java/Tomcat process spawning OS shell (Log4Shell Runtime.exec post-exploitation) Bespoke install · alerting DSΣPDDCS [LLM] Java (java.exe/javaw.exe) spawning shell or LOLBin — Log4Shell post-exploitation Bespoke install · alerting DSΣPDDCS [LLM] npm/node install lifecycle spawning interactive or reverse shell Bespoke install · hunting DSΣPDDCS [LLM] ImageMagick convert spawning shell/LOLBin child (ImageTragick CVE-2016-3714 RCE) Bespoke exploit · alerting DSΣPCS [LLM] systeminformation inetChecksite curl argument injection (CVE-2020-7752) Bespoke exploit · alerting DSΣPDDCS [LLM] Arbitrary child process from systeminformation inetChecksite shell pipeline Bespoke actions · hunting DSΣP [LLM] Node.js (Express) process spawning a command shell — express-fileupload prototype-pollution RCE outcome Bespoke exploit · hunting DSΣPDDCS [LLM] Apache Airflow Celery worker spawns non-airflow child (command-injection RCE, CVE-2020-11981) Bespoke exploit · alerting DSΣPCS [LLM] World-writable executable run as a shell (-c) — minimist polluted shell privesc payload Bespoke install · hunting DSΣPDDCS [LLM] Node.js process spawning OS command shell (child_process.exec backdoor) Bespoke install · hunting DSΣPDDCS [LLM] Webmin password_change.cgi unauthenticated command injection exploit attempt (CVE-2019-15107) Bespoke exploit · hunting SΣP [LLM] Webmin RCE: miniserv/password_change.cgi spawning reverse shell (CVE-2019-15107) Bespoke exploit · alerting DSΣPDDCS [LLM] Rails/Ruby app worker (puma/unicorn/passenger) spawning a shell — post-eval RCE Bespoke actions · hunting DSΣPCS [LLM] runc /proc/self/exe re-exec abuse (CVE-2019-5736 exploit primitive) Bespoke exploit · hunting DSΣPDDCS [LLM] Zip Slip RCE: archive-extraction process spawns command interpreter Bespoke exploit · hunting DSΣPDDCS [LLM] Apache Struts web app (java/Tomcat) spawning OS shell or recon — post-exploit RCE (CVE-2017-5638 / CVE-2017-9805) Bespoke exploit · alerting DSΣPDDCS [LLM] Node.js process spawning shell/curl to read and exfiltrate /etc/passwd (Dust.js post-exploit) Bespoke actions · alerting DSΣPDDCS [LLM] ImageMagick binary spawning shell/recon process (ImageTragick CVE-2016-3714 delegate RCE) Bespoke exploit · hunting DSΣPCS

Articles citing this technique (98)