T1059Command and Scripting Interpreter
T1059 — Command and Scripting Interpreter is a MITRE ATT&CK technique in the Execution tactic. Clankerusecase tracks 112 detection use cases covering it and 41 threat-intel articles citing it.
Execution
112Use cases
41Articles
13Sub-techniques
1Tactic
Sub-techniques (13)
T1059.002 · AppleScriptT1059.010 · AutoHotKey & AutoITT1059.009 · Cloud APIT1059.013 · Container CLI/APIT1059.012 · Hypervisor CLIT1059.007 · JavaScriptT1059.011 · LuaT1059.008 · Network Device CLIT1059.001 · PowerShellT1059.006 · PythonT1059.004 · Unix ShellT1059.005 · Visual BasicT1059.003 · Windows Command Shell
Use cases covering this technique (112)
Spring4Shell RCE attempts (CVE-2022-22963) Command injection exploited (WAF detection) Falco runtime-security alert Log4Shell RCE attempts (CVE-2021-44228) [WEEKLY] AI/LLM Agent Framework Runtime Spawning Shell, Recon, or Egress Child Process [WEEKLY] Auth-Bypass on Public-Facing Service → Post-Exploit Action on Same Host (≤10 min) [WEEKLY] Edge-service post-exploitation chain: internet-facing daemon → child shell or token redemption within 10 min of external request [WEEKLY] Gitea Service Account Post-Exploitation: git/gitea Spawning Interpreters or Egressing to Cloud Metadata [WEEKLY] Internet-Exposed AI Agent/LLM Service Spawns Shell or LOLBin After Inbound Connection [WEEKLY] Internet-facing server process spawns interpreter then beacons to first-seen external host within 5 minutes [WEEKLY] Internet-facing service process spawns shell/LOLBin within minutes of public inbound connection — post-RCE command execution [WEEKLY] Language-runtime server (node/python/java) spawns OS shell shortly after inbound request — eval / sandbox-escape exploitation chain [WEEKLY] Public-Facing App Auth-Bypass to Server-Side Code Execution (web-server process spawning a shell/interpreter) [WEEKLY] Public-Facing App Runtime Spawns Shell, LOLBin, or Container-Control Tool [WEEKLY] Server / AI-agent process spawns shell or LOLBIN with public egress — post-RCE behavioural chain [WEEKLY] Service-process parent spawns subprocess containing CLI-argument-injection tokens [WEEKLY] Web App Interpreter (Node/Python/Java/PHP) Spawns Shell or Net-Download LOLBin on Internet-Facing Host [WEEKLY] Web-Server Process Post-Exploit Anchor: Plugin/Extension RCE Leading to Shell Spawn or Webroot Script Drop Cisco IOS XE Guestshell Activation and Destroy Cisco IOS XE Request Platform Package Describe Shell Pattern ESXi Reverse Shell Patterns MCP Filesystem Server Suspicious Extension Write MCP Prompt Injection Ollama Suspicious Prompt Injection Jailbreak PTC Windchill Gateway Command Execution PTC Windchill GW READY OK Probe Cisco NVM - Installation of Typosquatted Python Package Cisco NVM - Suspicious File Download via Headless Browser Excessive distinct processes from Windows Temp Excessive number of taskhost processes Linux Binary Executed from Shared Memory Directory Linux Ghostscript Exploitation Linux Shell Pseudo Device Reverse Shell Living Off The Land Detection Log4Shell CVE-2021-44228 Exploitation Process Writing DynamicWrapperX Wermgr Process Spawned CMD Or Powershell Process Windows Apache Benchmark Binary Windows AutoIt3 Execution Windows Command and Scripting Interpreter Hunting Path Traversal Windows Command and Scripting Interpreter Path Traversal Exec Windows Common Abused Cmd Shell Risk Behavior Windows Defender ASR Audit Events Windows Defender ASR Block Events Windows Defender ASR Rules Stacking Windows Identify Protocol Handlers Windows PaperCut NG Spawn Shell Windows Process Accessing Windows Recall Directory Windows Process Execution From RDP Share Windows Remote Image Load Windows Scheduled Task Service Spawned Shell Windows Suspicious Child Process of Consent.EXE Windows Suspicious VMWare Tools Child Process Windows TeamCity Payload Execution from Temp Directory Windows TeamCity Plugin Installed Windows WinDBG Spawning AutoIt3 Windows XLL File Creation Outside of Typical Location Cisco Secure Firewall - Binary File Type Download Cisco Secure Firewall - Citrix NetScaler Memory Overread Attempt Cisco Secure Firewall - High Volume of Intrusion Events Per Host Cisco Secure Firewall - Possibly Compromised Host Cisco Secure Firewall - Privileged Command Execution via HTTP Cisco Secure Firewall - Wget or Curl Download Detect Outbound LDAP Traffic Juniper Networks Remote Code Execution Exploit Detection CHCP Command Execution Detect Risky SPL using Pretrained ML Model Detect suspicious processnames using pretrained model in DSDL Splunk Command and Scripting Interpreter Delete Usage Splunk Command and Scripting Interpreter Risky Commands Splunk Command and Scripting Interpreter Risky SPL MLTK [LLM] Node.js runtime spawning shell/recon child process (vm2 CVE-2026-47686 escape RCE) [LLM] Vulnerable vm2 package present on host (CVE-2026-47686, vm2 <= 3.11.5) [LLM] mshta.exe spawning command interpreter or secondary LOLBin [LLM] Node.js spawning a shell or detached node -e child (Joyfill RAT execution) [LLM] `kiota info` run against a remote/untrusted OpenAPI description (CVE-2026-59865) [LLM] CI runner process POSTing secrets to GhostAction exfil host via curl/wget/node [LLM] fast16 sabotage implant carrier (svcmgmt.exe) by hash / Lua-carrier behaviour [LLM] WordPress web-server/PHP process spawning a shell (wp2shell RCE) [LLM] EnvoyExtensionPolicy Lua invoking os/io/debug file primitives [LLM] TidGi Desktop wiki worker spawning a command interpreter (TiddlyWiki startup-module RCE) [LLM] plain-crypto-js postinstall RAT dropper spawns downloader (axios/Sapphire Sleet) [LLM] SiYuan Electron client spawns command interpreter (XSS-to-RCE via child_process) [LLM] Base64 PHP-serialized-object payload in importfiche POST body [LLM] Compromised simonecorsi/mawesome GitHub Action payload by known hash [LLM] Maven/Gradle build log file containing jqwik prompt-injection directive [LLM] Laravel-Lang stealer file drop in .laravel_locale temp directory [LLM] Thymeleaf SpEL tab-character sandbox bypass payload in HTTP request (CVE-2026-40478) [LLM] npm/node postinstall hook spawning interpreter and reaching new C2 host (Axios-style dropper) [LLM] Compromised trivy binary (v0.69.4-v0.69.6) execution by SHA1 hash [LLM] npm install referencing GitHub commit SHA (github:owner/repo#sha) — dangling-commit supply chain hunt [LLM] Process crash with faulting module WindowsCodecs.dll (CVE-2025-50165 exploit attempt) [LLM] Go typosquat module reference: github.com/boltdb-go/bolt in process or build telemetry [LLM] npm/yarn/pnpm install of compromised @lottiefiles/lottie-player versions 2.0.5-2.0.7 [LLM] JVM (java/javaw) spawning OS command interpreter — SnakeYAML gadget RCE outcome [LLM] npm/yarn install-script (postinstall) spawning download LOLBins for secret theft / payload fetch [LLM] Java/JVM spawning OS shell after Text4Shell (CVE-2022-42889) script-engine RCE [LLM] Vulnerable Snyk CLI (< v1.996.0) present — CVE-2022-40764 command injection exposure [LLM] Snyk CLI spawning a shell — CVE-2022-40764 command injection via go-plugin vendor.json [LLM] Java (ProcessBuilder) spawning shell/LOLBin child — Commons Config interpolation RCE [LLM] Magento CVE-2022-24086/24087 TrojanOrders checkout exploitation from known attacker IP [LLM] Magento CVE-2022-24086 template-directive injection in web requests (getTemplateFilter RCE) [LLM] Java/Tomcat application server spawning command shell or netcat (Log4Shell RCE) [LLM] Log4Shell JNDI lookup injection string in HTTP requests / process cmdline (${jndi:ldap}) [LLM] Java/Tomcat process spawning shell, curl or wget (Log4Shell RCE follow-on) [LLM] Tomcat/Java server process spawning an OS command shell (CVE-2020-9484 RCE outcome) [LLM] Celery task injected into Apache Airflow message broker (unacked queue / execute_command) [LLM] Ghostcat RCE: Tomcat/java process spawning a command shell (JSP webshell execution) [LLM] npm/yarn install lifecycle (postinstall) spawning download or LOLBin tooling [LLM] Java/Spring Boot process spawning a shell — possible jackson-databind deserialization RCE [LLM] strong_password 0.0.7 backdoor: RCE via attacker-controlled ___id cookie eval middleware [LLM] Apache Struts OGNL / XStream exploit payload in WAF & web logs (CVE-2017-5638 + CVE-2017-9805)Articles citing this technique (41)
high Find Unused, Stale, and OIDC-Replaceable GitHub Actions Secrets Across Your GitHub Organization art-221
high SQL injection isn't dead art-224
high Don't Panic: The Thymeleaf Template Injection That Only Hurts If You Let It (CVE-2026-40478) art-517
crit Reviewing CVE-2022-42889: The arbitrary code execution vulnerability in Apache Commons Text art-1989
crit Breaking out of message brokers art-3345