Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Execution/ T1059

T1059Command and Scripting Interpreter

T1059 — Command and Scripting Interpreter is a MITRE ATT&CK technique in the Execution tactic. Clankerusecase tracks 99 detection use cases covering it and 40 threat-intel articles citing it.

Execution
View on the matrix → Filter Detection Library MITRE official spec ↗
99Use cases
40Articles
13Sub-techniques
1Tactic

Sub-techniques (13)

Use cases covering this technique (99)

Spring4Shell RCE attempts (CVE-2022-22963) Internal delivery · alerting DD Command injection exploited (WAF detection) Internal delivery · alerting DD Falco runtime-security alert Internal actions · alerting DD Log4Shell RCE attempts (CVE-2021-44228) Internal delivery · alerting DD [WEEKLY] Auth-Bypass on Public-Facing Service → Post-Exploit Action on Same Host (≤10 min) Internal exploit · alerting DSPDD [WEEKLY] Edge-service post-exploitation chain: internet-facing daemon → child shell or token redemption within 10 min of external request Internal actions · alerting DSPDD [WEEKLY] Internet-facing server process spawns interpreter then beacons to first-seen external host within 5 minutes Internal install · alerting DSPDD [WEEKLY] Internet-facing service process spawns shell/LOLBin within minutes of public inbound connection — post-RCE command execution Internal exploit · alerting DSΣPDD [WEEKLY] Language-runtime server (node/python/java) spawns OS shell shortly after inbound request — eval / sandbox-escape exploitation chain Internal exploit · alerting DSPDD [WEEKLY] Public-Facing App Runtime Spawns Shell, LOLBin, or Container-Control Tool Internal exploit · alerting DSΣPDD [WEEKLY] Server / AI-agent process spawns shell or LOLBIN with public egress — post-RCE behavioural chain Internal exploit · alerting DSΣPDD [WEEKLY] Service-process parent spawns subprocess containing CLI-argument-injection tokens Internal exploit · alerting DSΣPDD [WEEKLY] Web App Interpreter (Node/Python/Java/PHP) Spawns Shell or Net-Download LOLBin on Internet-Facing Host Internal exploit · alerting DSPDD [WEEKLY] Web-Server Process Post-Exploit Anchor: Plugin/Extension RCE Leading to Shell Spawn or Webroot Script Drop Internal install · alerting DSΣPDD Cisco IOS XE Guestshell Activation and Destroy ESCU actions · hunting P Cisco IOS XE Request Platform Package Describe Shell Pattern ESCU actions · alerting P ESXi Reverse Shell Patterns ESCU actions · alerting P MCP Filesystem Server Suspicious Extension Write ESCU actions · hunting P MCP Prompt Injection ESCU actions · alerting P Ollama Suspicious Prompt Injection Jailbreak ESCU actions · hunting P Cisco NVM - Installation of Typosquatted Python Package ESCU actions · alerting P Cisco NVM - Suspicious File Download via Headless Browser ESCU actions · alerting P Excessive distinct processes from Windows Temp ESCU actions · hunting P Excessive number of taskhost processes ESCU actions · hunting P Living Off The Land Detection ESCU actions · alerting P Log4Shell CVE-2021-44228 Exploitation ESCU actions · alerting P Process Writing DynamicWrapperX ESCU actions · hunting P Wermgr Process Spawned CMD Or Powershell Process ESCU actions · alerting P Windows Apache Benchmark Binary ESCU actions · hunting P Windows AutoIt3 Execution ESCU actions · alerting P Windows Command and Scripting Interpreter Hunting Path Traversal ESCU actions · hunting P Windows Command and Scripting Interpreter Path Traversal Exec ESCU actions · alerting P Windows Common Abused Cmd Shell Risk Behavior ESCU actions · alerting P Windows Defender ASR Audit Events ESCU actions · hunting P Windows Defender ASR Block Events ESCU actions · hunting P Windows Defender ASR Rules Stacking ESCU actions · hunting P Windows Identify Protocol Handlers ESCU actions · hunting P Windows PaperCut NG Spawn Shell ESCU actions · alerting P Windows Process Accessing Windows Recall Directory ESCU actions · hunting P Windows Process Execution From RDP Share ESCU actions · hunting P Windows Remote Image Load ESCU actions · hunting P Windows Scheduled Task Service Spawned Shell ESCU actions · alerting P Windows Suspicious VMWare Tools Child Process ESCU actions · alerting P Windows TeamCity Payload Execution from Temp Directory ESCU actions · alerting P Windows TeamCity Plugin Installed ESCU actions · hunting P Windows WinDBG Spawning AutoIt3 ESCU actions · alerting P Windows XLL File Creation Outside of Typical Location ESCU actions · hunting P Cisco Secure Firewall - Binary File Type Download ESCU actions · hunting P Cisco Secure Firewall - Citrix NetScaler Memory Overread Attempt ESCU actions · alerting P Cisco Secure Firewall - High Volume of Intrusion Events Per Host ESCU actions · hunting P Cisco Secure Firewall - Possibly Compromised Host ESCU actions · hunting P Cisco Secure Firewall - Privileged Command Execution via HTTP ESCU actions · hunting P Cisco Secure Firewall - Wget or Curl Download ESCU actions · hunting P Detect Outbound LDAP Traffic ESCU actions · hunting P Juniper Networks Remote Code Execution Exploit Detection ESCU actions · alerting P CHCP Command Execution ESCU actions · hunting P Detect suspicious processnames using pretrained model in DSDL ESCU actions · hunting P [LLM] Implicit node-gyp rebuild from binding.gyp spawns suspicious build child Bespoke install · hunting DSΣPDDCS [LLM] Machine-cadence post-auth FortiGate CLI/API calls in single session (MCP-orchestrated) Bespoke install · hunting DSPDD [LLM] FireAnt Metakit.exe spawns unsigned setup.exe from update path (SPECTRALVIPER supply-chain delivery) Bespoke delivery · alerting DSΣPDDCS [LLM] SPECTRALVIPER known SHA1 sample sighting (ESET 2024-2026 IOC bundle) Bespoke install · hunting DSΣPDDCS [LLM] Ivanti Sentry command injection via /mics/api/v2/sentry/mics-config/handleMessage (CVE-2026-10520) Bespoke exploit · alerting DSΣPDDCS [LLM] Cargo build script spawning git with onering's exfil --pretty=format JSON Bespoke actions · alerting DSΣPDDCS [LLM] DHCP Client svchost anomalous child process (CVE-2026-44815 post-exploit) Bespoke exploit · alerting DSΣPDDCS [LLM] HEEx / Elixir Kernel injection markers in BEAM-spawned process command line (CVE-2026-8467) Bespoke exploit · alerting DSΣPDDCS [LLM] LiteLLM CVE-2026-42271 MCP test endpoint POST (preview command injection) Bespoke exploit · alerting SPDD [LLM] PHPSpreadsheet phar:/// three-slash wrapper in HTTP request (CVE-2026-45034) Bespoke exploit · alerting SΣPDD [LLM] Stata binary spawning OS shell (CVE-2026-47708 stata-mcp log_file_name injection) Bespoke exploit · alerting DSΣPDDCS [LLM] Stata-authored log file written with shell metacharacters or path traversal in filename (CVE-2026-47708) Bespoke exploit · alerting DSΣPDDCS [LLM] Jupyter Enterprise Gateway /api/kernels POST with KERNEL_* YAML-injection payload Bespoke exploit · hunting DSPDD [LLM] Maven/Gradle build log file containing jqwik prompt-injection directive Bespoke install · hunting DSPDDCS [LLM] Node.js process spawns shell or LOLBin — vm2 sandbox escape post-exploitation (CVE-2026-47210) Bespoke exploit · alerting DSΣPDDCS [LLM] Node.exe spawning OS shell after vm2 sandbox exploitation Bespoke install · alerting DSΣPDDCS [LLM] Node.js web process spawning shell (LiquidJS RCE post-exploit) Bespoke exploit · alerting DSΣPDDCS [LLM] Yamcs MDB algorithm override PATCH with Java Runtime payload Bespoke delivery · hunting SΣPDD [LLM] Laravel-Lang stealer file drop in .laravel_locale temp directory Bespoke install · alerting DSΣPDDCS [LLM] TamperedChef trojanized-app activation via --cm / --enableupdate / --fullupdate flags Bespoke install · alerting DSΣPDDCS [LLM] GlassFish java process spawning command shell (CVE-2026-2587 RCE) Bespoke exploit · alerting DSΣPDDCS [LLM] Inbound HTTP request with Camel-internal header or query param to CXF/Knative endpoint (CVE-2026-47323) Bespoke exploit · alerting DSΣPDDCS [LLM] Node.js process spawning shell or system utility — likely vm2 sandbox escape Bespoke exploit · alerting DSΣPDDCS [LLM] Marten CVE-2026-45288 regConfig SQL injection attempt in web traffic Bespoke exploit · alerting SΣPDD [LLM] Marten CVE-2026-45288 injection observed executing in PostgreSQL audit log Bespoke exploit · alerting SΣPDD [LLM] MCPHub tool execution via spoofed identity — POST to /<user>/messages with JSON-RPC body Bespoke actions · alerting SΣPDD [LLM] Post-exploit RCE: node.js (n8n) spawning shell or scripting interpreter Bespoke install · alerting DSΣPDDCS [LLM] Flowise node.exe Spawning OS Shell or Command-Line Utility - Post-Exploit RCE (CVE-2026-46442) Bespoke exploit · alerting DSΣPDDCS [LLM] Thymeleaf SpEL tab-character sandbox bypass payload in HTTP request (CVE-2026-40478) Bespoke exploit · alerting SΣPDD [LLM] npm/node postinstall hook spawning interpreter and reaching new C2 host (Axios-style dropper) Bespoke delivery · hunting DSPDDCS [LLM] Compromised trivy binary (v0.69.4-v0.69.6) execution by SHA1 hash Bespoke install · alerting DSΣPDD [LLM] Storybook portable-stories RCE — vitest/node spawning shell, recon or secret-grep child (CVE-2026-27148) Bespoke exploit · alerting DSΣPDDCS [LLM] npm install referencing GitHub commit SHA (github:owner/repo#sha) — dangling-commit supply chain hunt Bespoke weapon · hunting DSΣPDDCS [LLM] AI CLI weaponized for recon — claude/gemini/q invoked under npm install lineage Bespoke actions · alerting DSΣPDDCS [LLM] SKILL.md written to ~/.claude/skills/ or ~/.openclaw/skills/ (agent-skill install) Bespoke install · hunting DSΣPDDCS [LLM] Prompt-injection markers (base64, Unicode tags, 'ignore previous instructions') in SKILL.md content Bespoke weapon · hunting DSPDDCS [LLM] AI CLI tool (claude/gemini/q) spawned non-interactively by node/npm/npx for recon Bespoke actions · alerting DSΣPDDCS [LLM] Process crash with faulting module WindowsCodecs.dll (CVE-2025-50165 exploit attempt) Bespoke exploit · hunting DSPDDCS [LLM] Node.js process downloads payload via curl/wget (React2Shell SNOWLIGHT/VShell deployment) Bespoke install · alerting DSΣPDDCS [LLM] WinRAR CVE-2025-8088 path traversal — payload dropped to user Startup folder Bespoke install · alerting DSΣPDDCS [LLM] Go typosquat module reference: github.com/boltdb-go/bolt in process or build telemetry Bespoke delivery · alerting DSΣPDDCS [LLM] npm/yarn/pnpm install of compromised @lottiefiles/lottie-player versions 2.0.5-2.0.7 Bespoke install · alerting DSΣPDDCS

Articles citing this technique (40)