Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Execution/ T1059.006

T1059.006Python

T1059.006 — Python is a MITRE ATT&CK technique in the Execution tactic. Clankerusecase tracks 74 detection use cases covering it and 40 threat-intel articles citing it.

Execution
View on the matrix → Filter Detection Library MITRE official spec ↗
74Use cases
40Articles
0Sub-techniques
1Tactic

Use cases covering this technique (74)

[WEEKLY] AI-Agent Server (PraisonAI/MCP) Spawns OS Shell or Recon LOLBin — Unauthenticated RCE Exploitation Internal exploit · alerting DSΣPDDCS [WEEKLY] AI/LLM Agent Framework Runtime Spawning Shell, Recon, or Egress Child Process Internal exploit · alerting DSΣPDDCS [WEEKLY] AI/LLM Framework Web Service Spawns Shell or Network Tool (Agent-Framework Unauthenticated RCE) Internal exploit · alerting DSΣPDDCS [WEEKLY] Developer/AI tooling runtime spawns shell or egress LOLBin (unauth RCE post-expl) Internal exploit · alerting DSPDDCS [WEEKLY] Developer/Data-tooling Daemon Spawns Shell Child Seconds After POST to Runner/Exec Endpoint Internal exploit · alerting DSPDD [WEEKLY] Developer interpreter / package-manager process exfiltrating tokens to public code-hosting / worker domains Internal install · alerting DSPDDCSCW [WEEKLY] Developer package install spawning script-host with non-registry C2 within 5 minutes Internal install · alerting DSPDD [WEEKLY] Language-runtime server (node/python/java) spawns OS shell shortly after inbound request — eval / sandbox-escape exploitation chain Internal exploit · alerting DSPDD [WEEKLY] Linux LPE chain — anomalous algif_aead/esp4/esp6/rxrpc kernel-module load followed by same-user root transition Internal exploit · alerting DSPDD [WEEKLY] Low-Code / AI Workflow Runtime Sandbox-Escape — Server Process Spawns Shell + Public Egress Internal exploit · alerting DSΣPDD [WEEKLY] Package install lifecycle hook spawns interpreter that reads developer credential stores Internal install · alerting DSPCS [WEEKLY] Package-manager install hook spawns interpreter that beacons to non-registry host within 120s Internal install · alerting DSPDD [WEEKLY] Package Manager Install Hook Spawns Scripting Interpreter Then Touches Credential Files or Egresses Off-Registry Internal install · alerting DSPDD [WEEKLY] Package-Manager Install -> Interpreter Child -> Non-Registry Egress Within 5 Minutes Internal install · alerting DSPDD [WEEKLY] Package Manager Install Spawning Outbound Egress to Non-Registry Infrastructure Within 5 Minutes Internal install · alerting DSPDD [WEEKLY] Package-manager install-time interpreter spawn with credential-file read and outbound egress within 120s Internal install · alerting DSPDD [WEEKLY] Package manager lifecycle hook spawns runtime with outbound egress to non-registry host within 5 minutes Internal install · alerting DSPDD [WEEKLY] Package manager spawns network-fetching child to public code-hosting within minutes of install Internal install · alerting DSPDD [WEEKLY] Server / AI-agent process spawns shell or LOLBIN with public egress — post-RCE behavioural chain Internal exploit · alerting DSΣPDD [WEEKLY] Service-process parent spawns subprocess containing CLI-argument-injection tokens Internal exploit · alerting DSΣPDD [WEEKLY] Web App Interpreter (Node/Python/Java/PHP) Spawns Shell or Net-Download LOLBin on Internet-Facing Host Internal exploit · alerting DSPDD [LLM] Node.js spawning Python credential-stealer child Bespoke actions · alerting DSΣPDDCS [LLM] Web/interpreter process connecting to internal HiveServer2 (10000) or Hadoop NameNode (50070) Bespoke exploit · alerting DSΣPCS [LLM] Hermes AI agent launched in unattended YOLO mode (--yolo / HERMES_YOLO_MODE) Bespoke install · alerting DSΣPDDCS [LLM] pythonw.exe loader executing from deceptive %LocalAppData%\Temp dir (ACR Stealer) Bespoke install · hunting DSΣPDDCS [LLM] Trojanized WebEx/Zoom/MobaXterm installer spawns Python or script host (UAT-11795 Starland RAT) Bespoke delivery · alerting DSΣPDDCS [LLM] Trojanized software installer spawning embedded Python payload (Starland loader) Bespoke install · alerting DSΣPDDCS [LLM] pip install redirected to non-PyPI index / find-links (dependency confusion) Bespoke delivery · hunting DSΣPDDCS [LLM] Python setup.py install-time code execution spawning shell/LOLBin Bespoke exploit · alerting DSΣPDDCS [LLM] Malicious .pth file dropped into site-packages by pip/python Bespoke install · hunting DSΣPDDCS [LLM] Langroid Python agent spawning shell/downloader child (os.system RCE) Bespoke exploit · hunting DSΣPCS [LLM] Langroid eval() exploit signature: __import__('os') / full_eval=True in cmdline or app logs Bespoke exploit · alerting DSΣPDDCS [LLM] BusySnake Python stealer executed from %APPDATA%\WindowsHelper (module.pyw) Bespoke install · alerting DSΣPDDCS [LLM] BusySnake reverse SSH tunnel: ssh.exe -R launched by bundled Python payload Bespoke c2 · hunting DSΣPDDCS [LLM] GitHub Actions runner spawns network tool / interpreter under compromised trivy-action or KICS Bespoke exploit · hunting DSΣPDDCS [LLM] macOS.Gaslight self-staged standalone CPython 3.10.18 fetch (astral-sh python-build-standalone) Bespoke install · alerting DSΣPCS [LLM] Hades on-import payload: Python process spawning Bun JavaScript runtime Bespoke c2 · alerting DSΣPDDCS [LLM] Hades PyPI startup hook: malicious -setup.pth dropped in site-packages Bespoke install · hunting DSΣPDDCS [LLM] Vertex AI model deployment following default-staged upload (poisoned-model deploy) Bespoke exploit · hunting PDD [LLM] Bun runtime executed from temp dir running _index.js payload (Hades Campaign) Bespoke install · alerting DSΣPDDCS [LLM] Scripting interpreter downloads Bun v1.3.14 runtime from oven-sh GitHub releases Bespoke delivery · hunting DSPCS [LLM] Hades import-hook payload artifacts dropped (_index.js, _hooks.py, _runtime.bin, .bun_ran, b.zip) Bespoke install · alerting DSΣPDDCS [LLM] CI runner secret theft via /proc/<pid>/mem read of Runner.Worker (Miasma memory scraper) Bespoke actions · hunting SΣPCS [LLM] Miasma Phantom Gyp: python.exe (gyp parser) spawning node index.js during npm install Bespoke install · alerting DSΣPDDCS [LLM] Kitty cat.py Python Backdoor File Drop / Execution (Nx Console Compromise) Bespoke install · alerting DSΣPDDCS [LLM] Known Shai-Hulud / Nx Console implant hash match (SHA256/SHA1) Bespoke install · hunting DSΣPDDCS [LLM] Python backdoor self-daemonisation via __DAEMONIZED=1 spawned by VS Code helper or node Bespoke install · hunting DSΣPDDCS [LLM] TeamPCP Nx Console payload SHA256 hash match on developer endpoints Bespoke install · hunting DSΣPDDCS [LLM] Compromised Microsoft durabletask PyPI Package Install (TeamPCP 1.4.1-1.4.3) Bespoke delivery · alerting DSΣPDDCS [LLM] durabletask PyPI dropper launches second-stage zipapp (python3 /tmp/managed.pyz) Bespoke install · alerting DSΣPDDCS [LLM] python3 reading /proc/<PID>/mem to scrape Runner.Worker secrets Bespoke actions · alerting DSΣPDDCS [LLM] Mini Shai-Hulud: Python subprocess spawns `_runtime/start.py` from lightning site-packages Bespoke install · alerting DSΣPDD [LLM] Python child process executing lightning _runtime/start.py bootstrapper Bespoke install · alerting DSΣPDD [LLM] Compromised elementary-data==0.23.3 PyPI install on developer / CI host Bespoke delivery · alerting DSΣPDDCS [LLM] Trinny marker file creation (.trinny-security-update) Bespoke install · alerting DSΣPDDCS [LLM] TeamPCP telnyx FetchAudio() — python subprocess running inline base64 exec Bespoke install · alerting DSΣPDD [LLM] pip install of malicious telnyx versions 4.87.1 / 4.87.2 Bespoke delivery · alerting DSΣPDDCS [LLM] Compromised litellm 1.82.7 / 1.82.8 PyPI install (TeamPCP supply-chain) Bespoke install · alerting DSΣPDDCS [LLM] Linux user-systemd sysmon persistence drop (~/.config/sysmon/sysmon.py + sysmon.service) Bespoke install · alerting DSΣPDDCS [LLM] Linux Python RAT orphaned via nohup python3 /tmp/ld.py (Axios npm payload) Bespoke install · alerting DSΣPDDCS [LLM] Python spawning python -c with base64.b64decode exec (litellm .pth stage-1 launcher) Bespoke install · alerting DSΣP [LLM] TeamPCP Linux/Mac stdin-piped Python second stage (sys.executable -) Bespoke exploit · hunting DSPDDCS [LLM] TeamPCP systemd backdoor — sysmon.py / sysmon.service persistence on CI runner Bespoke install · alerting DSΣPDD [LLM] Compromised bittensor-wallet 4.0.2 source-tarball SHA256 on disk Bespoke delivery · hunting DSΣPDD [LLM] ForceMemo: Node.js v22.9.0 spawned by Python from user home directory Bespoke install · alerting DSΣPDD [LLM] Python .pth startup hook executes subprocess to curl C2 (litellm fork-bomb pattern) Bespoke install · alerting DSΣPDDCS [LLM] Cacheract memdump.py download/execution on CI runner or developer host Bespoke install · alerting DSΣPDD [LLM] Ultralytics PyPI supply-chain XMRig coinminer execution from /tmp/ultralytics_runner Bespoke actions · alerting DSΣPDDCS [LLM] tj-actions/changed-files: CI runner pipes gist memdump.py to python to scrape secrets Bespoke actions · alerting DSΣPDDCS [LLM] Installation of poisoned Ultralytics PyPI package (v8.3.41 / 8.3.42 / 8.3.45 / 8.3.46) Bespoke install · alerting DSΣPDDCS [LLM] Python interpreter relaunching itself to execute a NamedTemporaryFile stager Bespoke install · alerting DSΣPDDCS [LLM] Python interpreter drops EXE sourced from Discord CDN (cyphers/stealthpy PyPI malware) Bespoke delivery · alerting DSΣPDDCS [LLM] Process execution from masquerade directory C:\$Windows.~SXK (Discord/Roblox stealer) Bespoke install · alerting DSΣPDDCS [LLM] Apache Airflow task run with --pickle flag (pickle deserialization, CVE-2020-11982) Bespoke exploit · hunting DSΣPDDCS

Articles citing this technique (40)