T1059.004Unix Shell
T1059.004 — Unix Shell is a MITRE ATT&CK technique in the Execution tactic. Clankerusecase tracks 158 detection use cases covering it and 99 threat-intel articles citing it.
Execution
158Use cases
99Articles
0Sub-techniques
1Tactic
↑ Parent technique: T1059 · Command and Scripting Interpreter
Use cases covering this technique (158)
[WEEKLY] AI-Agent Server (PraisonAI/MCP) Spawns OS Shell or Recon LOLBin — Unauthenticated RCE Exploitation [WEEKLY] AI/LLM Agent Framework Runtime Spawning Shell, Recon, or Egress Child Process [WEEKLY] AI/LLM Framework Web Service Spawns Shell or Network Tool (Agent-Framework Unauthenticated RCE) [WEEKLY] Cross-Platform ClickFix Paste-to-Pipe Loader (UI-Parent Shell with Decode-and-Execute Payload) [WEEKLY] Developer/AI tooling runtime spawns shell or egress LOLBin (unauth RCE post-expl) [WEEKLY] Developer/Data-tooling Daemon Spawns Shell Child Seconds After POST to Runner/Exec Endpoint [WEEKLY] Gitea Service Account Post-Exploitation: git/gitea Spawning Interpreters or Egressing to Cloud Metadata [WEEKLY] Internet-Exposed AI Agent/LLM Service Spawns Shell or LOLBin After Inbound Connection [WEEKLY] Internet-Facing Service Daemon Spawns Shell or Ingress Tool Then Beacons Out [WEEKLY] Internet-Facing Service Process Spawning Unix Shell or Ingress-Tool LOLBin (Edge Zero-Day Post-Exploit) [WEEKLY] Internet-facing service process spawns shell/LOLBin within minutes of public inbound connection — post-RCE command execution [WEEKLY] Low-Code / AI Workflow Runtime Sandbox-Escape — Server Process Spawns Shell + Public Egress [WEEKLY] Package install lifecycle hook spawns interpreter that reads developer credential stores [WEEKLY] Package Manager / Dev-Tool Auto-Execution Triggers Non-Registry Egress or Credential-Store Access [WEEKLY] Package-Manager Install -> Interpreter Child -> Non-Registry Egress Within 5 Minutes [WEEKLY] Package manager lifecycle hook spawns network-fetching shell or runtime [WEEKLY] Package manager spawns network-fetching child to public code-hosting within minutes of install [WEEKLY] Public-facing app auth/authz bypass into server-side code execution (patch-bypass wave) [WEEKLY] Self-hosted application service spawns shell or SSH within seconds of inbound unauthenticated API write [WEEKLY] Server / AI-agent process spawns shell or LOLBIN with public egress — post-RCE behavioural chain [WEEKLY] Service-process parent spawns subprocess containing CLI-argument-injection tokens [WEEKLY] Web App Interpreter (Node/Python/Java/PHP) Spawns Shell or Net-Download LOLBin on Internet-Facing Host [WEEKLY] Web-Server Process Post-Exploit Anchor: Plugin/Extension RCE Leading to Shell Spawn or Webroot Script Drop [WEEKLY] Web-tier interpreter post-exploitation: shell/net-tool spawn, secret-file read, or cloud IMDS reach Linux Decode Base64 to Shell Linux Magic SysRq Key Abuse Linux MOTD Script Added Linux Netcat Outbound Connection Linux Possible System Binary Backdoor Linux Suspicious Privileged Container Execution Linux Suspicious React or Next.js Child Process Linux Suspicious XDG Autostart Linux Unix Shell Enable All SysRq Functions MacOS LOLbin Suspicious Linux Discovery Commands [LLM] Ray raylet/python spawning shell + ingress tooling (ShadowRay payload execution) [LLM] Credential exfil via shell command injection: base64-encoded secrets curled to OAST domain [LLM] Node.js runtime spawning a shell/command interpreter (vm2 sandbox breakout RCE) [LLM] Node.js runtime spawning shell/recon child process (vm2 CVE-2026-47686 escape RCE) [LLM] conflibot command injection: shell spawned by Node action with git + shell metacharacters (CVE-2026-55158) [LLM] Evooo1Bot wget.sh fetch-and-execute loader chain on Linux [LLM] AmnesiaStealer ClickFix loader: macOS shell fetching payload from fake-GitHub / Amnesia C2 host [LLM] Execution/write of known TeamPCP stealer binary by SHA256 [LLM] Evooo1Bot loader download cradle (wget.sh / wget||curl pipe-to-shell into /tmp) [LLM] SAP Commerce (Hybris) Java process spawning OS command shell — CVE-2026-58231 RCE payoff [LLM] macOS screensharingd spawning a shell or downloader as root (post-exploit RCE) [LLM] macOS ClickFix: Terminal spawns shell decoding Base64 / curl-pipe payload [LLM] macOS captured-password validation via dscl authonly + keychain unlock with cleartext password [LLM] Flowise (node) process spawning a shell — CVE-2026-70477 pyodide→child_process RCE landing [LLM] Reverse shell / egress from Flowise node-spawned interpreter (CVE-2026-70477 post-exploit) [LLM] Flowise Node process burst-spawning shell/recon children within seconds (post-RCE) [LLM] Flowise Node.js process spawning OS shell/recon (Pyodide js-interop RCE sink) [LLM] Flowise node runtime spawns shell interpreter (post-exploit command execution) [LLM] Flowise node.js spawns Unix shell/command binaries as root (CSVAgent Pyodide RCE) [LLM] Reverse shell / Meterpreter egress from Flowise node or its shell child [LLM] Flowise/node process spawning Unix shell or netcat reverse shell (CVE-2026-69254 vm2 escape) [LLM] Reverse-shell egress from Flowise node process tree (nc/shell child dialing out) [LLM] Flowise node process spawning shell/netcat (TypeORM DataSource RCE) [LLM] Reverse-shell egress from netcat/socat on Flowise host [LLM] PostgreSQL container process spawning shell — COPY TO PROGRAM RCE (CVE-2026-52887) [LLM] XCSSET v40 chrome_remote CDP backdoor binary execution [LLM] XCSSET v40 trojanized Xcode build spawning curl-to-shell downloader [LLM] Ruby/Puma Rails web process spawns a shell (post-file-read RCE via forged secret_key_base cookie) [LLM] Fluentd aggregator pod spawns shell/curl via injected out_exec (CVE-2026-54680 RCE) [LLM] Unexpected write to Fluentd fluent.conf introducing exec/block-close directives [LLM] OpenAM/Tomcat java process spawning shell or LOLBin — CVE-2026-62379 post-exploitation [LLM] OpenAM/Tomcat Java process spawning a shell — post-deserialization RCE (CVE-2026-62263) [LLM] Node.js host process spawning OS shell (Nunjucks SSTI child_process.execSync RCE) [LLM] Node.js process spawning shell / recon binary (velocityjs SSTI RCE execution) [LLM] SleeperGem loader: ruby install script spawns shell running deploy.sh [LLM] Ruby interpreter spawning PowerShell -ExecutionPolicy bypass or /bin/sh (SleeperGem dropper) [LLM] Web server daemon (php-fpm/apache/nginx/w3wp) spawning a shell or network tool — wp2shell post-exploit code execution [LLM] Pheditor terminal RCE: web-server/PHP process spawns shell (CVE-2026-55579) [LLM] Reverse shell via cron/webshell payload dropped through Anyquery AFW (/dev/tcp) [LLM] DIRAC FileCatalog checkDataset SQL injection carrying Python eval gadget (CVE-2026-61667) [LLM] DIRAC FileCatalog service Python process spawns shell or recon binary (eval RCE) [LLM] DIRAC ReqManager service (CVE-2026-45579) spawning a shell or recon/egress binary [LLM] File Browser hook-auth pre-auth RCE: filebrowser spawns shell/recon commands (CVE-2026-54088) [LLM] File Browser hook-auth RCE follow-on: reverse shell / egress tooling under filebrowser (CVE-2026-54088) [LLM] YesWiki Bazar CalcField eval() RCE — dangerous PHP functions in form-save request [LLM] YesWiki post-RCE — php-fpm/apache spawns Unix shell or recon binary (www-data) [LLM] YesWiki CalcField exploit attempts — PHP parse/fatal errors from CalcField.php in syslog [LLM] YesWiki web-server process spawning an OS shell (deserialization RCE outcome) [LLM] Git-spawned hook execution during recursive clone (CVE-2024-32002) [LLM] macOS.Gaslight self-staged standalone CPython 3.10.18 fetch (astral-sh python-build-standalone) [LLM] Atomic Arch payload execution: JS runtime spawning shell/network tooling under AUR build (or known payload hash) [LLM] Phantom Gyp: node-gyp install-time code execution via weaponized binding.gyp [LLM] PHP CLI drops hidden /tmp dropper artefacts (Laravel-Lang autoload payload) [LLM] Composer install of malicious helpers.php in laravel-lang vendor package [LLM] Megalodon harvester: curl POST to C2 /collect endpoint on Linux runner [LLM] Stage-3 exfil archive trin.tar.gz POST via curl --data-binary [LLM] Java/Tomcat process spawns OS command interpreter (post-Thymeleaf SSTI RCE) [LLM] Qinglong CVE-2026-4047 case-mismatch auth bypass via /aPi/system/command-run [LLM] Qinglong .fullgc cryptominer execution with nohup backgrounding [LLM] Stage-2 implant masquerading as node-health-check daemon (/tmp/.kh, /tmp/.ns) [LLM] node process spawning bash/curl chain to fetch Velora DEX install.sh dropper [LLM] hackerbot-claw second-stage download: curl -sSfL pipe-bash from hackmoltrepeat.com/molt [LLM] Python process spawning shell with TeamPCP recon chain (hostname; whoami; uname; ip addr fallback) [LLM] npm postinstall SSH-backdoor chain: node spawning sudo ufw allow 22/tcp + chown ~/.ssh [LLM] Bash-spawned curl to xygeni-action C2 nip.io endpoint with /b/in /b/q /b/r path on CI runner [LLM] Exfiltration to kubernetes-el attacker webhook.site UUIDs (Pwn Request payload) [LLM] Compromised kubernetes.el destructive payload — Emacs spawning `rm -rf / --no-preserve-root` [LLM] Local AI coding agents (claude/gemini/q) launched with permission-bypass flags during package install — s1ngularity [LLM] tj-actions/changed-files compromise: memdump.py secret-exfiltration shell pattern on runner (CVE-2025-30066) [LLM] Pastebin-piping stager retrieved from rentry.co/openclaw-core (macOS/Linux ClawHub skill) [LLM] SKILL.md file written referencing fabricated openclaw-core prerequisite (ClawHub skill social engineering hook) [LLM] Installation of credential-leaking ClawHub skills (moltyverse-email, buy-anything, prompt-log, youtube-data) [LLM] AI agent skill leaks Stripe key or card PAN/CVC verbatim in curl command line [LLM] AI coding agent spawns remote fetch-and-execute (curl | bash / curl | source) [LLM] Node.js process spawning interactive shell — suspected post-exploit RCE on Next.js / RSC server [LLM] AI coding agent CLI (claude/gemini/q) invoked with permission-bypass flags [LLM] Malicious tj-actions base64 payload prefix observed in process command line [LLM] Apache Spark CVE-2022-33891 doAs command injection — shell spawned by Spark JVM running 'id -Gn' with metacharacters [LLM] GitPython CVE-2022-24439 RCE — git 'ext::sh' transport command injection via crafted clone URL [LLM] GitHub Actions branch-name template injection — bash brace-expansion shell signature [LLM] Outbound fetch of file.sh via attacker-controlled commit d8daa0b... on raw.githubusercontent.com [LLM] ImageMagick 'convert -resize' command injection via sh -c in Go web app [LLM] cups-browsed spawning foomatic-rip or shell child (CVE-2024-47177 RCE) [LLM] Tomcat/Java process spawns OS shell or LOLBin (post-webshell RCE) [LLM] PHP web-server process initiating outbound TCP (fsockopen reverse shell to attacker) [LLM] PHP CLI dev server (php -S) spawning a shell or child interpreter (proc_open php -a) [LLM] macOS Text Replacements exfiltration via `defaults read NSUserDictionaryReplacementItems` [LLM] Node.js process spawning a command interpreter (deserialization RCE child_process exec) [LLM] Package-manager install hook spawning host-recon curl/wget exfil (pre.sh pattern) [LLM] Install of ypvpctpbamdhxtkzdu malicious package set (django-yauth + siblings) [LLM] Ruby/Rails app server spawning a Unix shell (post-deserialization RCE) [LLM] Git argument injection via --upload-pack option spawned by web-app runtime [LLM] Mercurial argument injection via --config alias/hooks or --debugger from app runtime [LLM] git/hg spawning a shell as child of a web-app runtime (argument-injection RCE evidence) [LLM] Bash reverse shell via /dev/tcp file-descriptor redirection [LLM] Server application runtime spawning shell with /dev/tcp redirection (RCE to reverse shell) [LLM] Reverse shell via ncat -e spawned by Node.js app (SonicJS GraphQL path-traversal RCE) [LLM] Tomcat/Java JVM spawning command shell (Spring4Shell webshell command execution) [LLM] Java/Tomcat spawns command shell or download tool (Spring4Shell RCE execution) [LLM] npm/yarn install spawning anomalous shell or working-dir binary (.npmrc/.yarnrc config override RCE) [LLM] Magento php-fpm/web-server spawning shell or download utility (CVE-2022-24086 RCE) [LLM] Magento web process (w3wp/php-fpm/php-cgi) spawning OS shell — CVE-2022-24086 RCE [LLM] Celery worker (Python) spawning a shell — CVE-2021-23727 stored command injection [LLM] Root shell spawned by pkexec with empty parent command line (PwnKit post-exploitation) [LLM] Log4Shell RCE execution: java/javaw spawning a shell or LOLBin [LLM] Java/Tomcat process spawning OS shell (Log4Shell Runtime.exec post-exploitation) [LLM] Java (java.exe/javaw.exe) spawning shell or LOLBin — Log4Shell post-exploitation [LLM] npm/node install lifecycle spawning interactive or reverse shell [LLM] ImageMagick convert spawning shell/LOLBin child (ImageTragick CVE-2016-3714 RCE) [LLM] systeminformation inetChecksite curl argument injection (CVE-2020-7752) [LLM] Arbitrary child process from systeminformation inetChecksite shell pipeline [LLM] Node.js (Express) process spawning a command shell — express-fileupload prototype-pollution RCE outcome [LLM] Apache Airflow Celery worker spawns non-airflow child (command-injection RCE, CVE-2020-11981) [LLM] World-writable executable run as a shell (-c) — minimist polluted shell privesc payload [LLM] Node.js process spawning OS command shell (child_process.exec backdoor) [LLM] Webmin password_change.cgi unauthenticated command injection exploit attempt (CVE-2019-15107) [LLM] Webmin RCE: miniserv/password_change.cgi spawning reverse shell (CVE-2019-15107) [LLM] Rails/Ruby app worker (puma/unicorn/passenger) spawning a shell — post-eval RCE [LLM] runc /proc/self/exe re-exec abuse (CVE-2019-5736 exploit primitive) [LLM] Zip Slip RCE: archive-extraction process spawns command interpreter [LLM] Apache Struts web app (java/Tomcat) spawning OS shell or recon — post-exploit RCE (CVE-2017-5638 / CVE-2017-9805) [LLM] Node.js process spawning shell/curl to read and exfiltrate /etc/passwd (Dust.js post-exploit) [LLM] ImageMagick binary spawning shell/recon process (ImageTragick CVE-2016-3714 delegate RCE)Articles citing this technique (99)
crit [GHSA / CRITICAL] CVE-2026-47698: vm2: Sandbox Breakout Using Dangerous Host Proto Mutators art-12
crit Team PCP Stole 78,330 Secrets From 2,186 Organizations. CloudSEK Just Published the List. art-35
crit Apple macOS Screen Sharing Flaw Exploited on Internet-Exposed Macs to Install Monero Miner art-38
crit AmnesiaStealer Hijacks Chromium Sessions to Give Attackers Live Browser Control on macOS art-55
crit 400+ AUR Packages Hijacked: What the “Atomic Arch” Campaign Means for Supply-Chain Security art-364
high Node-gyp Supply Chain Compromise: A Self-Propagating npm Worm That Hides in binding.gyp art-408
high Don't Panic: The Thymeleaf Template Injection That Only Hurts If You Let It (CVE-2026-40478) art-517
crit Malicious Polymarket Bot Hides in Hijacked dev-protocol GitHub Org and Steals Wallet Keys art-596
high Security Advisory: Critical RCE Vulnerabilities in React Server Components (CVE-2025-55182) art-782
crit Breaking out of message brokers art-3345