Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Execution/ T1059.004

T1059.004Unix Shell

T1059.004 — Unix Shell is a MITRE ATT&CK technique in the Execution tactic. Clankerusecase tracks 158 detection use cases covering it and 99 threat-intel articles citing it.

Execution
View on the matrix → Filter Detection Library MITRE official spec ↗
158Use cases
99Articles
0Sub-techniques
1Tactic

Use cases covering this technique (158)

[WEEKLY] AI-Agent Server (PraisonAI/MCP) Spawns OS Shell or Recon LOLBin — Unauthenticated RCE Exploitation Internal exploit · alerting DSΣPDDCS [WEEKLY] AI/LLM Agent Framework Runtime Spawning Shell, Recon, or Egress Child Process Internal exploit · alerting DSΣPDDCS [WEEKLY] AI/LLM Framework Web Service Spawns Shell or Network Tool (Agent-Framework Unauthenticated RCE) Internal exploit · alerting DSΣPDDCS [WEEKLY] Cross-Platform ClickFix Paste-to-Pipe Loader (UI-Parent Shell with Decode-and-Execute Payload) Internal delivery · alerting DSΣP [WEEKLY] Developer/AI tooling runtime spawns shell or egress LOLBin (unauth RCE post-expl) Internal exploit · alerting DSPDDCS [WEEKLY] Developer/Data-tooling Daemon Spawns Shell Child Seconds After POST to Runner/Exec Endpoint Internal exploit · alerting DSPDD [WEEKLY] Gitea Service Account Post-Exploitation: git/gitea Spawning Interpreters or Egressing to Cloud Metadata Internal exploit · alerting DSΣPDDCS [WEEKLY] Internet-Exposed AI Agent/LLM Service Spawns Shell or LOLBin After Inbound Connection Internal exploit · alerting DSΣPDDCS [WEEKLY] Internet-Facing Service Daemon Spawns Shell or Ingress Tool Then Beacons Out Internal exploit · alerting DSΣPDDCS [WEEKLY] Internet-Facing Service Process Spawning Unix Shell or Ingress-Tool LOLBin (Edge Zero-Day Post-Exploit) Internal install · alerting DSΣPDD [WEEKLY] Internet-facing service process spawns shell/LOLBin within minutes of public inbound connection — post-RCE command execution Internal exploit · alerting DSΣPDD [WEEKLY] Low-Code / AI Workflow Runtime Sandbox-Escape — Server Process Spawns Shell + Public Egress Internal exploit · alerting DSΣPDD [WEEKLY] Package install lifecycle hook spawns interpreter that reads developer credential stores Internal install · alerting DSPCS [WEEKLY] Package Manager / Dev-Tool Auto-Execution Triggers Non-Registry Egress or Credential-Store Access Internal install · alerting DSPDD [WEEKLY] Package-Manager Install -> Interpreter Child -> Non-Registry Egress Within 5 Minutes Internal install · alerting DSPDD [WEEKLY] Package manager lifecycle hook spawns network-fetching shell or runtime Internal install · alerting DSΣPDD [WEEKLY] Package manager spawns network-fetching child to public code-hosting within minutes of install Internal install · alerting DSPDD [WEEKLY] Public-facing app auth/authz bypass into server-side code execution (patch-bypass wave) Internal exploit · alerting DSΣPDDCS [WEEKLY] Self-hosted application service spawns shell or SSH within seconds of inbound unauthenticated API write Internal exploit · alerting DSPDD [WEEKLY] Server / AI-agent process spawns shell or LOLBIN with public egress — post-RCE behavioural chain Internal exploit · alerting DSΣPDD [WEEKLY] Service-process parent spawns subprocess containing CLI-argument-injection tokens Internal exploit · alerting DSΣPDD [WEEKLY] Web App Interpreter (Node/Python/Java/PHP) Spawns Shell or Net-Download LOLBin on Internet-Facing Host Internal exploit · alerting DSPDD [WEEKLY] Web-Server Process Post-Exploit Anchor: Plugin/Extension RCE Leading to Shell Spawn or Webroot Script Drop Internal install · alerting DSΣPDD [WEEKLY] Web-tier interpreter post-exploitation: shell/net-tool spawn, secret-file read, or cloud IMDS reach Internal install · alerting DSΣPDDCSCW Linux Decode Base64 to Shell ESCU actions · alerting P Linux Magic SysRq Key Abuse ESCU actions · alerting P Linux MOTD Script Added ESCU actions · hunting P Linux Netcat Outbound Connection ESCU actions · hunting P Linux Possible System Binary Backdoor ESCU actions · hunting P Linux Suspicious Privileged Container Execution ESCU actions · hunting P Linux Suspicious React or Next.js Child Process ESCU actions · alerting P Linux Suspicious XDG Autostart ESCU actions · hunting P Linux Unix Shell Enable All SysRq Functions ESCU actions · hunting P MacOS LOLbin ESCU actions · alerting P Suspicious Linux Discovery Commands ESCU actions · alerting P [LLM] Ray raylet/python spawning shell + ingress tooling (ShadowRay payload execution) Bespoke install · alerting DSΣPDDCS [LLM] Credential exfil via shell command injection: base64-encoded secrets curled to OAST domain Bespoke actions · alerting DSΣPDDCS [LLM] Node.js runtime spawning a shell/command interpreter (vm2 sandbox breakout RCE) Bespoke exploit · hunting DSΣPDDCS [LLM] Node.js runtime spawning shell/recon child process (vm2 CVE-2026-47686 escape RCE) Bespoke exploit · hunting DSΣPDDCS [LLM] conflibot command injection: shell spawned by Node action with git + shell metacharacters (CVE-2026-55158) Bespoke exploit · alerting DSΣPCS [LLM] Evooo1Bot wget.sh fetch-and-execute loader chain on Linux Bespoke install · hunting DSΣPDDCS [LLM] AmnesiaStealer ClickFix loader: macOS shell fetching payload from fake-GitHub / Amnesia C2 host Bespoke delivery · alerting DSΣPCS [LLM] Execution/write of known TeamPCP stealer binary by SHA256 Bespoke install · hunting DSΣPDDCS [LLM] Evooo1Bot loader download cradle (wget.sh / wget||curl pipe-to-shell into /tmp) Bespoke install · alerting DSΣPDDCS [LLM] SAP Commerce (Hybris) Java process spawning OS command shell — CVE-2026-58231 RCE payoff Bespoke exploit · hunting DSΣPDDCS [LLM] macOS screensharingd spawning a shell or downloader as root (post-exploit RCE) Bespoke exploit · alerting DSΣPCS [LLM] macOS ClickFix: Terminal spawns shell decoding Base64 / curl-pipe payload Bespoke delivery · hunting DSΣPCS [LLM] macOS captured-password validation via dscl authonly + keychain unlock with cleartext password Bespoke actions · hunting DSΣPCS [LLM] Flowise (node) process spawning a shell — CVE-2026-70477 pyodide→child_process RCE landing Bespoke exploit · alerting DSΣPCS [LLM] Reverse shell / egress from Flowise node-spawned interpreter (CVE-2026-70477 post-exploit) Bespoke c2 · hunting DSPCS [LLM] Flowise Node process burst-spawning shell/recon children within seconds (post-RCE) Bespoke exploit · alerting DSPDDCS [LLM] Flowise Node.js process spawning OS shell/recon (Pyodide js-interop RCE sink) Bespoke actions · alerting DSΣPDDCS [LLM] Flowise node runtime spawns shell interpreter (post-exploit command execution) Bespoke exploit · alerting DSΣPCS [LLM] Flowise node.js spawns Unix shell/command binaries as root (CSVAgent Pyodide RCE) Bespoke exploit · alerting DSΣPDDCS [LLM] Reverse shell / Meterpreter egress from Flowise node or its shell child Bespoke c2 · hunting DSPCS [LLM] Flowise/node process spawning Unix shell or netcat reverse shell (CVE-2026-69254 vm2 escape) Bespoke install · alerting DSΣPDDCS [LLM] Reverse-shell egress from Flowise node process tree (nc/shell child dialing out) Bespoke c2 · alerting DSPCS [LLM] Flowise node process spawning shell/netcat (TypeORM DataSource RCE) Bespoke exploit · alerting DSΣPDDCS [LLM] Reverse-shell egress from netcat/socat on Flowise host Bespoke c2 · alerting DSΣPCS [LLM] PostgreSQL container process spawning shell — COPY TO PROGRAM RCE (CVE-2026-52887) Bespoke install · alerting DSΣPCS [LLM] XCSSET v40 chrome_remote CDP backdoor binary execution Bespoke install · alerting DSΣPCS [LLM] XCSSET v40 trojanized Xcode build spawning curl-to-shell downloader Bespoke delivery · hunting DSΣPCS [LLM] Ruby/Puma Rails web process spawns a shell (post-file-read RCE via forged secret_key_base cookie) Bespoke exploit · alerting DSΣPCS [LLM] Fluentd aggregator pod spawns shell/curl via injected out_exec (CVE-2026-54680 RCE) Bespoke exploit · alerting DSΣPDDCS [LLM] Unexpected write to Fluentd fluent.conf introducing exec/block-close directives Bespoke install · hunting DSΣPDDCS [LLM] OpenAM/Tomcat java process spawning shell or LOLBin — CVE-2026-62379 post-exploitation Bespoke install · alerting DSΣPDDCS [LLM] OpenAM/Tomcat Java process spawning a shell — post-deserialization RCE (CVE-2026-62263) Bespoke exploit · alerting DSΣPDDCS [LLM] Node.js host process spawning OS shell (Nunjucks SSTI child_process.execSync RCE) Bespoke exploit · hunting DSΣPDDCS [LLM] Node.js process spawning shell / recon binary (velocityjs SSTI RCE execution) Bespoke exploit · alerting DSΣPDDCS [LLM] SleeperGem loader: ruby install script spawns shell running deploy.sh Bespoke install · alerting DSΣPDDCS [LLM] Ruby interpreter spawning PowerShell -ExecutionPolicy bypass or /bin/sh (SleeperGem dropper) Bespoke exploit · hunting DSΣPDDCS [LLM] Web server daemon (php-fpm/apache/nginx/w3wp) spawning a shell or network tool — wp2shell post-exploit code execution Bespoke exploit · alerting DSΣPDDCS [LLM] Pheditor terminal RCE: web-server/PHP process spawns shell (CVE-2026-55579) Bespoke exploit · alerting DSΣPDDCS [LLM] Reverse shell via cron/webshell payload dropped through Anyquery AFW (/dev/tcp) Bespoke c2 · alerting DSΣPDDCS [LLM] DIRAC FileCatalog checkDataset SQL injection carrying Python eval gadget (CVE-2026-61667) Bespoke exploit · hunting SPDD [LLM] DIRAC FileCatalog service Python process spawns shell or recon binary (eval RCE) Bespoke install · alerting DSΣPDDCS [LLM] DIRAC ReqManager service (CVE-2026-45579) spawning a shell or recon/egress binary Bespoke exploit · alerting DSΣP [LLM] File Browser hook-auth pre-auth RCE: filebrowser spawns shell/recon commands (CVE-2026-54088) Bespoke exploit · alerting DSΣPCS [LLM] File Browser hook-auth RCE follow-on: reverse shell / egress tooling under filebrowser (CVE-2026-54088) Bespoke c2 · alerting DSΣPCS [LLM] YesWiki Bazar CalcField eval() RCE — dangerous PHP functions in form-save request Bespoke exploit · alerting SΣP [LLM] YesWiki post-RCE — php-fpm/apache spawns Unix shell or recon binary (www-data) Bespoke install · alerting DSΣPDDCS [LLM] YesWiki CalcField exploit attempts — PHP parse/fatal errors from CalcField.php in syslog Bespoke exploit · hunting SPDD [LLM] YesWiki web-server process spawning an OS shell (deserialization RCE outcome) Bespoke exploit · alerting DSΣPDDCS [LLM] Git-spawned hook execution during recursive clone (CVE-2024-32002) Bespoke exploit · alerting DSΣPDDCS [LLM] macOS.Gaslight self-staged standalone CPython 3.10.18 fetch (astral-sh python-build-standalone) Bespoke install · alerting DSΣPCS [LLM] Atomic Arch payload execution: JS runtime spawning shell/network tooling under AUR build (or known payload hash) Bespoke install · alerting DSPDDCS [LLM] Phantom Gyp: node-gyp install-time code execution via weaponized binding.gyp Bespoke exploit · alerting DSΣPDDCS [LLM] PHP CLI drops hidden /tmp dropper artefacts (Laravel-Lang autoload payload) Bespoke install · alerting DSΣPDDCS [LLM] Composer install of malicious helpers.php in laravel-lang vendor package Bespoke delivery · hunting DSΣPDDCS [LLM] Megalodon harvester: curl POST to C2 /collect endpoint on Linux runner Bespoke actions · alerting DSΣPDDCS [LLM] Stage-3 exfil archive trin.tar.gz POST via curl --data-binary Bespoke actions · alerting DSΣPDDCS [LLM] Java/Tomcat process spawns OS command interpreter (post-Thymeleaf SSTI RCE) Bespoke actions · alerting DSΣPDDCS [LLM] Qinglong CVE-2026-4047 case-mismatch auth bypass via /aPi/system/command-run Bespoke exploit · alerting DSΣPDD [LLM] Qinglong .fullgc cryptominer execution with nohup backgrounding Bespoke install · alerting DSΣPDD [LLM] Stage-2 implant masquerading as node-health-check daemon (/tmp/.kh, /tmp/.ns) Bespoke install · alerting DSΣPDD [LLM] node process spawning bash/curl chain to fetch Velora DEX install.sh dropper Bespoke delivery · alerting DSΣPDDCS [LLM] hackerbot-claw second-stage download: curl -sSfL pipe-bash from hackmoltrepeat.com/molt Bespoke install · alerting DSΣPDDCS [LLM] Python process spawning shell with TeamPCP recon chain (hostname; whoami; uname; ip addr fallback) Bespoke actions · alerting DSΣPDDCS [LLM] npm postinstall SSH-backdoor chain: node spawning sudo ufw allow 22/tcp + chown ~/.ssh Bespoke install · alerting DSΣPDD [LLM] Bash-spawned curl to xygeni-action C2 nip.io endpoint with /b/in /b/q /b/r path on CI runner Bespoke c2 · alerting DSΣPDDCS [LLM] Exfiltration to kubernetes-el attacker webhook.site UUIDs (Pwn Request payload) Bespoke c2 · alerting DSΣPDD [LLM] Compromised kubernetes.el destructive payload — Emacs spawning `rm -rf / --no-preserve-root` Bespoke actions · alerting DSΣPDD [LLM] Local AI coding agents (claude/gemini/q) launched with permission-bypass flags during package install — s1ngularity Bespoke install · alerting DSΣPDDCS [LLM] tj-actions/changed-files compromise: memdump.py secret-exfiltration shell pattern on runner (CVE-2025-30066) Bespoke actions · alerting DSΣPDD [LLM] Pastebin-piping stager retrieved from rentry.co/openclaw-core (macOS/Linux ClawHub skill) Bespoke delivery · alerting DSPDDCS [LLM] SKILL.md file written referencing fabricated openclaw-core prerequisite (ClawHub skill social engineering hook) Bespoke weapon · hunting DSPDDCS [LLM] Installation of credential-leaking ClawHub skills (moltyverse-email, buy-anything, prompt-log, youtube-data) Bespoke install · alerting DSΣPDDCS [LLM] AI agent skill leaks Stripe key or card PAN/CVC verbatim in curl command line Bespoke actions · alerting DSΣPDDCS [LLM] AI coding agent spawns remote fetch-and-execute (curl | bash / curl | source) Bespoke install · alerting DSΣPDDCS [LLM] Node.js process spawning interactive shell — suspected post-exploit RCE on Next.js / RSC server Bespoke exploit · alerting DSΣPDDCS [LLM] AI coding agent CLI (claude/gemini/q) invoked with permission-bypass flags Bespoke actions · alerting DSΣPDDCS [LLM] Malicious tj-actions base64 payload prefix observed in process command line Bespoke exploit · alerting DSΣPDDCS [LLM] Apache Spark CVE-2022-33891 doAs command injection — shell spawned by Spark JVM running 'id -Gn' with metacharacters Bespoke exploit · alerting DSΣPDDCS [LLM] GitPython CVE-2022-24439 RCE — git 'ext::sh' transport command injection via crafted clone URL Bespoke exploit · alerting DSΣPDDCS [LLM] GitHub Actions branch-name template injection — bash brace-expansion shell signature Bespoke exploit · alerting DSΣPDDCS [LLM] Outbound fetch of file.sh via attacker-controlled commit d8daa0b... on raw.githubusercontent.com Bespoke c2 · alerting DSΣPDDCS [LLM] ImageMagick 'convert -resize' command injection via sh -c in Go web app Bespoke exploit · hunting DSΣPDDCS [LLM] cups-browsed spawning foomatic-rip or shell child (CVE-2024-47177 RCE) Bespoke exploit · alerting DSΣPDDCS [LLM] Tomcat/Java process spawns OS shell or LOLBin (post-webshell RCE) Bespoke actions · alerting DSΣPDDCS [LLM] PHP web-server process initiating outbound TCP (fsockopen reverse shell to attacker) Bespoke c2 · alerting DSΣPCS [LLM] PHP CLI dev server (php -S) spawning a shell or child interpreter (proc_open php -a) Bespoke exploit · alerting DSΣPDDCS [LLM] macOS Text Replacements exfiltration via `defaults read NSUserDictionaryReplacementItems` Bespoke actions · alerting DSΣPCS [LLM] Node.js process spawning a command interpreter (deserialization RCE child_process exec) Bespoke exploit · alerting DSΣPDDCS [LLM] Package-manager install hook spawning host-recon curl/wget exfil (pre.sh pattern) Bespoke install · alerting DSΣPDDCS [LLM] Install of ypvpctpbamdhxtkzdu malicious package set (django-yauth + siblings) Bespoke delivery · hunting DSΣPDDCS [LLM] Ruby/Rails app server spawning a Unix shell (post-deserialization RCE) Bespoke exploit · alerting DSΣPCS [LLM] Git argument injection via --upload-pack option spawned by web-app runtime Bespoke exploit · alerting DSΣPDDCS [LLM] Mercurial argument injection via --config alias/hooks or --debugger from app runtime Bespoke exploit · alerting DSΣPDDCS [LLM] git/hg spawning a shell as child of a web-app runtime (argument-injection RCE evidence) Bespoke exploit · hunting DSPDDCS [LLM] Bash reverse shell via /dev/tcp file-descriptor redirection Bespoke install · alerting DSPDDCS [LLM] Server application runtime spawning shell with /dev/tcp redirection (RCE to reverse shell) Bespoke exploit · alerting DSΣPCS [LLM] Reverse shell via ncat -e spawned by Node.js app (SonicJS GraphQL path-traversal RCE) Bespoke c2 · alerting DSΣPDDCS [LLM] Tomcat/Java JVM spawning command shell (Spring4Shell webshell command execution) Bespoke actions · hunting DSΣPDDCS [LLM] Java/Tomcat spawns command shell or download tool (Spring4Shell RCE execution) Bespoke exploit · alerting DSΣPDDCS [LLM] npm/yarn install spawning anomalous shell or working-dir binary (.npmrc/.yarnrc config override RCE) Bespoke exploit · hunting DSΣPDDCS [LLM] Magento php-fpm/web-server spawning shell or download utility (CVE-2022-24086 RCE) Bespoke exploit · hunting DSΣPCS [LLM] Magento web process (w3wp/php-fpm/php-cgi) spawning OS shell — CVE-2022-24086 RCE Bespoke exploit · alerting DSΣPDDCS [LLM] Celery worker (Python) spawning a shell — CVE-2021-23727 stored command injection Bespoke exploit · hunting DSΣPCS [LLM] Root shell spawned by pkexec with empty parent command line (PwnKit post-exploitation) Bespoke install · alerting DSΣPCS [LLM] Log4Shell RCE execution: java/javaw spawning a shell or LOLBin Bespoke exploit · alerting DSΣPDDCS [LLM] Java/Tomcat process spawning OS shell (Log4Shell Runtime.exec post-exploitation) Bespoke install · alerting DSΣPDDCS [LLM] Java (java.exe/javaw.exe) spawning shell or LOLBin — Log4Shell post-exploitation Bespoke install · alerting DSΣPDDCS [LLM] npm/node install lifecycle spawning interactive or reverse shell Bespoke install · hunting DSΣPDDCS [LLM] ImageMagick convert spawning shell/LOLBin child (ImageTragick CVE-2016-3714 RCE) Bespoke exploit · alerting DSΣPCS [LLM] systeminformation inetChecksite curl argument injection (CVE-2020-7752) Bespoke exploit · alerting DSΣPDDCS [LLM] Arbitrary child process from systeminformation inetChecksite shell pipeline Bespoke actions · hunting DSΣP [LLM] Node.js (Express) process spawning a command shell — express-fileupload prototype-pollution RCE outcome Bespoke exploit · hunting DSΣPDDCS [LLM] Apache Airflow Celery worker spawns non-airflow child (command-injection RCE, CVE-2020-11981) Bespoke exploit · alerting DSΣPCS [LLM] World-writable executable run as a shell (-c) — minimist polluted shell privesc payload Bespoke install · hunting DSΣPDDCS [LLM] Node.js process spawning OS command shell (child_process.exec backdoor) Bespoke install · hunting DSΣPDDCS [LLM] Webmin password_change.cgi unauthenticated command injection exploit attempt (CVE-2019-15107) Bespoke exploit · hunting SΣP [LLM] Webmin RCE: miniserv/password_change.cgi spawning reverse shell (CVE-2019-15107) Bespoke exploit · alerting DSΣPDDCS [LLM] Rails/Ruby app worker (puma/unicorn/passenger) spawning a shell — post-eval RCE Bespoke actions · hunting DSΣPCS [LLM] runc /proc/self/exe re-exec abuse (CVE-2019-5736 exploit primitive) Bespoke exploit · hunting DSΣPDDCS [LLM] Zip Slip RCE: archive-extraction process spawns command interpreter Bespoke exploit · hunting DSΣPDDCS [LLM] Apache Struts web app (java/Tomcat) spawning OS shell or recon — post-exploit RCE (CVE-2017-5638 / CVE-2017-9805) Bespoke exploit · alerting DSΣPDDCS [LLM] Node.js process spawning shell/curl to read and exfiltrate /etc/passwd (Dust.js post-exploit) Bespoke actions · alerting DSΣPDDCS [LLM] ImageMagick binary spawning shell/recon process (ImageTragick CVE-2016-3714 delegate RCE) Bespoke exploit · hunting DSΣPCS

Articles citing this technique (99)