Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Execution/ T1059

T1059Command and Scripting Interpreter

T1059 — Command and Scripting Interpreter is a MITRE ATT&CK technique in the Execution tactic. Clankerusecase tracks 114 detection use cases covering it and 50 threat-intel articles citing it.

Execution
View on the matrix → Filter Detection Library MITRE official spec ↗
114Use cases
50Articles
13Sub-techniques
1Tactic

Sub-techniques (13)

Use cases covering this technique (114)

Spring4Shell RCE attempts (CVE-2022-22963) Internal delivery · alerting DD Command injection exploited (WAF detection) Internal delivery · alerting DD Falco runtime-security alert Internal actions · alerting DD Log4Shell RCE attempts (CVE-2021-44228) Internal delivery · alerting DD [WEEKLY] AI/LLM Agent Framework Runtime Spawning Shell, Recon, or Egress Child Process Internal exploit · alerting DSΣPDDCS [WEEKLY] Auth-Bypass on Public-Facing Service → Post-Exploit Action on Same Host (≤10 min) Internal exploit · alerting DSPDD [WEEKLY] Edge-service post-exploitation chain: internet-facing daemon → child shell or token redemption within 10 min of external request Internal actions · alerting DSPDD [WEEKLY] Internet-Exposed AI Agent/LLM Service Spawns Shell or LOLBin After Inbound Connection Internal exploit · alerting DSΣPDDCS [WEEKLY] Internet-facing server process spawns interpreter then beacons to first-seen external host within 5 minutes Internal install · alerting DSPDD [WEEKLY] Internet-facing service process spawns shell/LOLBin within minutes of public inbound connection — post-RCE command execution Internal exploit · alerting DSΣPDD [WEEKLY] Language-runtime server (node/python/java) spawns OS shell shortly after inbound request — eval / sandbox-escape exploitation chain Internal exploit · alerting DSPDD [WEEKLY] Public-Facing App Runtime Spawns Shell, LOLBin, or Container-Control Tool Internal exploit · alerting DSΣPDD [WEEKLY] Server / AI-agent process spawns shell or LOLBIN with public egress — post-RCE behavioural chain Internal exploit · alerting DSΣPDD [WEEKLY] Service-process parent spawns subprocess containing CLI-argument-injection tokens Internal exploit · alerting DSΣPDD [WEEKLY] Web App Interpreter (Node/Python/Java/PHP) Spawns Shell or Net-Download LOLBin on Internet-Facing Host Internal exploit · alerting DSPDD [WEEKLY] Web-Server Process Post-Exploit Anchor: Plugin/Extension RCE Leading to Shell Spawn or Webroot Script Drop Internal install · alerting DSΣPDD Cisco IOS XE Guestshell Activation and Destroy ESCU actions · hunting P Cisco IOS XE Request Platform Package Describe Shell Pattern ESCU actions · alerting P ESXi Reverse Shell Patterns ESCU actions · alerting P MCP Filesystem Server Suspicious Extension Write ESCU actions · hunting P MCP Prompt Injection ESCU actions · alerting P Ollama Suspicious Prompt Injection Jailbreak ESCU actions · hunting P PTC Windchill Gateway Command Execution ESCU actions · hunting P PTC Windchill GW READY OK Probe ESCU actions · hunting P Cisco NVM - Installation of Typosquatted Python Package ESCU actions · alerting P Cisco NVM - Suspicious File Download via Headless Browser ESCU actions · alerting P Excessive distinct processes from Windows Temp ESCU actions · hunting P Excessive number of taskhost processes ESCU actions · hunting P Living Off The Land Detection ESCU actions · alerting P Log4Shell CVE-2021-44228 Exploitation ESCU actions · alerting P Process Writing DynamicWrapperX ESCU actions · hunting P Wermgr Process Spawned CMD Or Powershell Process ESCU actions · alerting P Windows Apache Benchmark Binary ESCU actions · hunting P Windows AutoIt3 Execution ESCU actions · alerting P Windows Command and Scripting Interpreter Hunting Path Traversal ESCU actions · hunting P Windows Command and Scripting Interpreter Path Traversal Exec ESCU actions · alerting P Windows Common Abused Cmd Shell Risk Behavior ESCU actions · alerting P Windows Defender ASR Audit Events ESCU actions · hunting P Windows Defender ASR Block Events ESCU actions · hunting P Windows Defender ASR Rules Stacking ESCU actions · hunting P Windows Identify Protocol Handlers ESCU actions · hunting P Windows PaperCut NG Spawn Shell ESCU actions · alerting P Windows Process Accessing Windows Recall Directory ESCU actions · hunting P Windows Process Execution From RDP Share ESCU actions · hunting P Windows Remote Image Load ESCU actions · hunting P Windows Scheduled Task Service Spawned Shell ESCU actions · alerting P Windows Suspicious VMWare Tools Child Process ESCU actions · alerting P Windows TeamCity Payload Execution from Temp Directory ESCU actions · alerting P Windows TeamCity Plugin Installed ESCU actions · hunting P Windows WinDBG Spawning AutoIt3 ESCU actions · alerting P Windows XLL File Creation Outside of Typical Location ESCU actions · hunting P Cisco Secure Firewall - Binary File Type Download ESCU actions · hunting P Cisco Secure Firewall - Citrix NetScaler Memory Overread Attempt ESCU actions · alerting P Cisco Secure Firewall - High Volume of Intrusion Events Per Host ESCU actions · hunting P Cisco Secure Firewall - Possibly Compromised Host ESCU actions · hunting P Cisco Secure Firewall - Privileged Command Execution via HTTP ESCU actions · hunting P Cisco Secure Firewall - Wget or Curl Download ESCU actions · hunting P Detect Outbound LDAP Traffic ESCU actions · hunting P Juniper Networks Remote Code Execution Exploit Detection ESCU actions · alerting P CHCP Command Execution ESCU actions · hunting P Detect Risky SPL using Pretrained ML Model ESCU actions · hunting P Detect suspicious processnames using pretrained model in DSDL ESCU actions · hunting P Splunk Command and Scripting Interpreter Delete Usage ESCU actions · hunting P Splunk Command and Scripting Interpreter Risky Commands ESCU actions · hunting P Splunk Command and Scripting Interpreter Risky SPL MLTK ESCU actions · hunting P [LLM] AppVShNotify.exe spawning child processes (NightLedger command dispatcher execution) Bespoke exploit · alerting DSΣPDDCS [LLM] Inbound connections from Arista-attributed VeloCloud Orchestrator attacker IPs (CVE-2026-16812) Bespoke delivery · hunting DSΣPCS [LLM] vBulletin web-server process (php-fpm/httpd/w3wp) spawning OS shell — CVE-2026-61511 post-exploitation Bespoke actions · alerting DSΣPDDCS [LLM] Spring Boot Java process spawning shell/LOLBin child (Fastjson RCE execution) Bespoke install · hunting DSΣPDDCS [LLM] `kiota info` run against a remote/untrusted OpenAPI description (CVE-2026-59865) Bespoke exploit · hunting DSΣPDDCS [LLM] Hermes AI agent launched in unattended YOLO mode (--yolo / HERMES_YOLO_MODE) Bespoke install · alerting DSΣPDDCS [LLM] CI runner process POSTing secrets to GhostAction exfil host via curl/wget/node Bespoke actions · alerting DSΣPDDCS [LLM] fast16 sabotage implant carrier (svcmgmt.exe) by hash / Lua-carrier behaviour Bespoke install · alerting DSΣPDDCS [LLM] WordPress web-server/PHP process spawning a shell (wp2shell RCE) Bespoke exploit · alerting DSΣPDDCS [LLM] EnvoyExtensionPolicy Lua invoking os/io/debug file primitives Bespoke exploit · hunting SΣPDD [LLM] OkoBot HDUtil launcher execution (target/nouac) with HWID guardrail Bespoke install · alerting DSΣPDDCS [LLM] TidGi Desktop wiki worker spawning a command interpreter (TiddlyWiki startup-module RCE) Bespoke exploit · alerting DSΣPDDCS [LLM] plain-crypto-js postinstall RAT dropper spawns downloader (axios/Sapphire Sleet) Bespoke install · alerting DSΣPDDCS [LLM] SiYuan Electron client spawns command interpreter (XSS-to-RCE via child_process) Bespoke exploit · alerting DSΣPDDCS [LLM] Base64 PHP-serialized-object payload in importfiche POST body Bespoke exploit · alerting SP [LLM] Cypher injection primitives in Langroid LLM prompt / inbound HTTP input Bespoke exploit · hunting SPDD [LLM] Neo4j executes attacker-primitive Cypher (apoc.*, dbms.*, LOAD CSV) via query.log Bespoke exploit · alerting SΣPDD [LLM] Active Twig RCE gadget strings in Craft/Formie HTTP request inputs Bespoke exploit · alerting SΣP [LLM] 9router unauthenticated MCP / cli-tools route RCE via process spawn — CVE-2026-46339 Bespoke exploit · alerting DSΣPCS [LLM] Compromised simonecorsi/mawesome GitHub Action payload by known hash Bespoke install · hunting DSΣPDDCS [LLM] Maven/Gradle build log file containing jqwik prompt-injection directive Bespoke install · hunting DSPDDCS [LLM] Laravel-Lang stealer file drop in .laravel_locale temp directory Bespoke install · alerting DSΣPDDCS [LLM] Thymeleaf SpEL tab-character sandbox bypass payload in HTTP request (CVE-2026-40478) Bespoke exploit · alerting SΣPDD [LLM] npm/node postinstall hook spawning interpreter and reaching new C2 host (Axios-style dropper) Bespoke delivery · hunting DSPDDCS [LLM] Compromised trivy binary (v0.69.4-v0.69.6) execution by SHA1 hash Bespoke install · alerting DSΣPDD [LLM] npm install referencing GitHub commit SHA (github:owner/repo#sha) — dangling-commit supply chain hunt Bespoke weapon · hunting DSΣPDDCS [LLM] Nx s1ngularity: npm postinstall weaponizes AI CLI tools (claude/gemini/q) for credential recon Bespoke actions · alerting DSΣPDDCS [LLM] Process crash with faulting module WindowsCodecs.dll (CVE-2025-50165 exploit attempt) Bespoke exploit · hunting DSPDDCS [LLM] WinRAR CVE-2025-8088 path traversal — payload dropped to user Startup folder Bespoke install · alerting DSΣPDDCS [LLM] Go typosquat module reference: github.com/boltdb-go/bolt in process or build telemetry Bespoke delivery · alerting DSΣPDDCS [LLM] npm/yarn/pnpm install of compromised @lottiefiles/lottie-player versions 2.0.5-2.0.7 Bespoke install · alerting DSΣPDDCS [LLM] JVM (java/javaw) spawning OS command interpreter — SnakeYAML gadget RCE outcome Bespoke exploit · hunting DSΣPDDCS [LLM] npm/yarn install-script (postinstall) spawning download LOLBins for secret theft / payload fetch Bespoke exploit · hunting DSΣPDDCS [LLM] Java/JVM spawning OS shell after Text4Shell (CVE-2022-42889) script-engine RCE Bespoke install · alerting DSΣPDDCS [LLM] Vulnerable Snyk CLI (< v1.996.0) present — CVE-2022-40764 command injection exposure Bespoke weapon · alerting DSP [LLM] Snyk CLI spawning a shell — CVE-2022-40764 command injection via go-plugin vendor.json Bespoke exploit · alerting DSΣPDDCS [LLM] Java (ProcessBuilder) spawning shell/LOLBin child — Commons Config interpolation RCE Bespoke install · alerting DSΣPDDCS [LLM] Magento CVE-2022-24086/24087 TrojanOrders checkout exploitation from known attacker IP Bespoke exploit · alerting SΣP [LLM] Magento CVE-2022-24086 template-directive injection in web requests (getTemplateFilter RCE) Bespoke exploit · hunting SΣP [LLM] Java/Tomcat application server spawning command shell or netcat (Log4Shell RCE) Bespoke exploit · alerting DSΣPDDCS [LLM] Log4Shell JNDI lookup injection string in HTTP requests / process cmdline (${jndi:ldap}) Bespoke exploit · alerting DSΣPDDCS [LLM] Java/Tomcat process spawning shell, curl or wget (Log4Shell RCE follow-on) Bespoke install · alerting DSΣPDDCS [LLM] Tomcat/Java server process spawning an OS command shell (CVE-2020-9484 RCE outcome) Bespoke exploit · alerting DSΣPDDCS [LLM] Celery task injected into Apache Airflow message broker (unacked queue / execute_command) Bespoke delivery · alerting DSΣPDDCS [LLM] Ghostcat RCE: Tomcat/java process spawning a command shell (JSP webshell execution) Bespoke exploit · hunting DSΣPDDCS [LLM] npm/yarn install lifecycle (postinstall) spawning download or LOLBin tooling Bespoke install · hunting DSΣPDDCS [LLM] Java/Spring Boot process spawning a shell — possible jackson-databind deserialization RCE Bespoke exploit · hunting DSΣPDDCS [LLM] strong_password 0.0.7 backdoor: RCE via attacker-controlled ___id cookie eval middleware Bespoke exploit · alerting SΣP [LLM] Apache Struts OGNL / XStream exploit payload in WAF & web logs (CVE-2017-5638 + CVE-2017-9805) Bespoke exploit · alerting SP

Articles citing this technique (50)