T1059Command and Scripting Interpreter
T1059 — Command and Scripting Interpreter is a MITRE ATT&CK technique in the Execution tactic. Clankerusecase tracks 114 detection use cases covering it and 50 threat-intel articles citing it.
Execution
114Use cases
50Articles
13Sub-techniques
1Tactic
Sub-techniques (13)
T1059.002 · AppleScriptT1059.010 · AutoHotKey & AutoITT1059.009 · Cloud APIT1059.013 · Container CLI/APIT1059.012 · Hypervisor CLIT1059.007 · JavaScriptT1059.011 · LuaT1059.008 · Network Device CLIT1059.001 · PowerShellT1059.006 · PythonT1059.004 · Unix ShellT1059.005 · Visual BasicT1059.003 · Windows Command Shell
Use cases covering this technique (114)
Spring4Shell RCE attempts (CVE-2022-22963) Command injection exploited (WAF detection) Falco runtime-security alert Log4Shell RCE attempts (CVE-2021-44228) [WEEKLY] AI/LLM Agent Framework Runtime Spawning Shell, Recon, or Egress Child Process [WEEKLY] Auth-Bypass on Public-Facing Service → Post-Exploit Action on Same Host (≤10 min) [WEEKLY] Edge-service post-exploitation chain: internet-facing daemon → child shell or token redemption within 10 min of external request [WEEKLY] Internet-Exposed AI Agent/LLM Service Spawns Shell or LOLBin After Inbound Connection [WEEKLY] Internet-facing server process spawns interpreter then beacons to first-seen external host within 5 minutes [WEEKLY] Internet-facing service process spawns shell/LOLBin within minutes of public inbound connection — post-RCE command execution [WEEKLY] Language-runtime server (node/python/java) spawns OS shell shortly after inbound request — eval / sandbox-escape exploitation chain [WEEKLY] Public-Facing App Runtime Spawns Shell, LOLBin, or Container-Control Tool [WEEKLY] Server / AI-agent process spawns shell or LOLBIN with public egress — post-RCE behavioural chain [WEEKLY] Service-process parent spawns subprocess containing CLI-argument-injection tokens [WEEKLY] Web App Interpreter (Node/Python/Java/PHP) Spawns Shell or Net-Download LOLBin on Internet-Facing Host [WEEKLY] Web-Server Process Post-Exploit Anchor: Plugin/Extension RCE Leading to Shell Spawn or Webroot Script Drop Cisco IOS XE Guestshell Activation and Destroy Cisco IOS XE Request Platform Package Describe Shell Pattern ESXi Reverse Shell Patterns MCP Filesystem Server Suspicious Extension Write MCP Prompt Injection Ollama Suspicious Prompt Injection Jailbreak PTC Windchill Gateway Command Execution PTC Windchill GW READY OK Probe Cisco NVM - Installation of Typosquatted Python Package Cisco NVM - Suspicious File Download via Headless Browser Excessive distinct processes from Windows Temp Excessive number of taskhost processes Living Off The Land Detection Log4Shell CVE-2021-44228 Exploitation Process Writing DynamicWrapperX Wermgr Process Spawned CMD Or Powershell Process Windows Apache Benchmark Binary Windows AutoIt3 Execution Windows Command and Scripting Interpreter Hunting Path Traversal Windows Command and Scripting Interpreter Path Traversal Exec Windows Common Abused Cmd Shell Risk Behavior Windows Defender ASR Audit Events Windows Defender ASR Block Events Windows Defender ASR Rules Stacking Windows Identify Protocol Handlers Windows PaperCut NG Spawn Shell Windows Process Accessing Windows Recall Directory Windows Process Execution From RDP Share Windows Remote Image Load Windows Scheduled Task Service Spawned Shell Windows Suspicious VMWare Tools Child Process Windows TeamCity Payload Execution from Temp Directory Windows TeamCity Plugin Installed Windows WinDBG Spawning AutoIt3 Windows XLL File Creation Outside of Typical Location Cisco Secure Firewall - Binary File Type Download Cisco Secure Firewall - Citrix NetScaler Memory Overread Attempt Cisco Secure Firewall - High Volume of Intrusion Events Per Host Cisco Secure Firewall - Possibly Compromised Host Cisco Secure Firewall - Privileged Command Execution via HTTP Cisco Secure Firewall - Wget or Curl Download Detect Outbound LDAP Traffic Juniper Networks Remote Code Execution Exploit Detection CHCP Command Execution Detect Risky SPL using Pretrained ML Model Detect suspicious processnames using pretrained model in DSDL Splunk Command and Scripting Interpreter Delete Usage Splunk Command and Scripting Interpreter Risky Commands Splunk Command and Scripting Interpreter Risky SPL MLTK [LLM] AppVShNotify.exe spawning child processes (NightLedger command dispatcher execution) [LLM] Inbound connections from Arista-attributed VeloCloud Orchestrator attacker IPs (CVE-2026-16812) [LLM] vBulletin web-server process (php-fpm/httpd/w3wp) spawning OS shell — CVE-2026-61511 post-exploitation [LLM] Spring Boot Java process spawning shell/LOLBin child (Fastjson RCE execution) [LLM] `kiota info` run against a remote/untrusted OpenAPI description (CVE-2026-59865) [LLM] Hermes AI agent launched in unattended YOLO mode (--yolo / HERMES_YOLO_MODE) [LLM] CI runner process POSTing secrets to GhostAction exfil host via curl/wget/node [LLM] fast16 sabotage implant carrier (svcmgmt.exe) by hash / Lua-carrier behaviour [LLM] WordPress web-server/PHP process spawning a shell (wp2shell RCE) [LLM] EnvoyExtensionPolicy Lua invoking os/io/debug file primitives [LLM] OkoBot HDUtil launcher execution (target/nouac) with HWID guardrail [LLM] TidGi Desktop wiki worker spawning a command interpreter (TiddlyWiki startup-module RCE) [LLM] plain-crypto-js postinstall RAT dropper spawns downloader (axios/Sapphire Sleet) [LLM] SiYuan Electron client spawns command interpreter (XSS-to-RCE via child_process) [LLM] Base64 PHP-serialized-object payload in importfiche POST body [LLM] Cypher injection primitives in Langroid LLM prompt / inbound HTTP input [LLM] Neo4j executes attacker-primitive Cypher (apoc.*, dbms.*, LOAD CSV) via query.log [LLM] Active Twig RCE gadget strings in Craft/Formie HTTP request inputs [LLM] 9router unauthenticated MCP / cli-tools route RCE via process spawn — CVE-2026-46339 [LLM] Compromised simonecorsi/mawesome GitHub Action payload by known hash [LLM] Maven/Gradle build log file containing jqwik prompt-injection directive [LLM] Laravel-Lang stealer file drop in .laravel_locale temp directory [LLM] Thymeleaf SpEL tab-character sandbox bypass payload in HTTP request (CVE-2026-40478) [LLM] npm/node postinstall hook spawning interpreter and reaching new C2 host (Axios-style dropper) [LLM] Compromised trivy binary (v0.69.4-v0.69.6) execution by SHA1 hash [LLM] npm install referencing GitHub commit SHA (github:owner/repo#sha) — dangling-commit supply chain hunt [LLM] Nx s1ngularity: npm postinstall weaponizes AI CLI tools (claude/gemini/q) for credential recon [LLM] Process crash with faulting module WindowsCodecs.dll (CVE-2025-50165 exploit attempt) [LLM] WinRAR CVE-2025-8088 path traversal — payload dropped to user Startup folder [LLM] Go typosquat module reference: github.com/boltdb-go/bolt in process or build telemetry [LLM] npm/yarn/pnpm install of compromised @lottiefiles/lottie-player versions 2.0.5-2.0.7 [LLM] JVM (java/javaw) spawning OS command interpreter — SnakeYAML gadget RCE outcome [LLM] npm/yarn install-script (postinstall) spawning download LOLBins for secret theft / payload fetch [LLM] Java/JVM spawning OS shell after Text4Shell (CVE-2022-42889) script-engine RCE [LLM] Vulnerable Snyk CLI (< v1.996.0) present — CVE-2022-40764 command injection exposure [LLM] Snyk CLI spawning a shell — CVE-2022-40764 command injection via go-plugin vendor.json [LLM] Java (ProcessBuilder) spawning shell/LOLBin child — Commons Config interpolation RCE [LLM] Magento CVE-2022-24086/24087 TrojanOrders checkout exploitation from known attacker IP [LLM] Magento CVE-2022-24086 template-directive injection in web requests (getTemplateFilter RCE) [LLM] Java/Tomcat application server spawning command shell or netcat (Log4Shell RCE) [LLM] Log4Shell JNDI lookup injection string in HTTP requests / process cmdline (${jndi:ldap}) [LLM] Java/Tomcat process spawning shell, curl or wget (Log4Shell RCE follow-on) [LLM] Tomcat/Java server process spawning an OS command shell (CVE-2020-9484 RCE outcome) [LLM] Celery task injected into Apache Airflow message broker (unacked queue / execute_command) [LLM] Ghostcat RCE: Tomcat/java process spawning a command shell (JSP webshell execution) [LLM] npm/yarn install lifecycle (postinstall) spawning download or LOLBin tooling [LLM] Java/Spring Boot process spawning a shell — possible jackson-databind deserialization RCE [LLM] strong_password 0.0.7 backdoor: RCE via attacker-controlled ___id cookie eval middleware [LLM] Apache Struts OGNL / XStream exploit payload in WAF & web logs (CVE-2017-5638 + CVE-2017-9805)Articles citing this technique (50)
high Find Unused, Stale, and OIDC-Replaceable GitHub Actions Secrets Across Your GitHub Organization art-114
high SQL injection isn't dead art-118
high Don't Panic: The Thymeleaf Template Injection That Only Hurts If You Let It (CVE-2026-40478) art-472
crit Reviewing CVE-2022-42889: The arbitrary code execution vulnerability in Apache Commons Text art-1966
crit Breaking out of message brokers art-3322