Windows Command Shell

T1059.003

Sub-technique of T1059 Command and Scripting Interpreter.View on attack.mitre.org

About this technique

Adversaries may abuse the Windows command shell for execution. The Windows command shell (cmd) is the primary command prompt on Windows systems. The Windows command prompt can be used to control almost any aspect of a system, with various permission levels required for different subsets of commands. The command prompt can be invoked remotely via Remote Services such as SSH.

Batch files (ex: .bat or .cmd) also provide the shell with a list of sequential commands to run, as well as normal scripting operations such as conditionals and loops. Common uses of batch files include long or repetitive tasks, or the need to run the same set of commands on multiple systems.

Adversaries may leverage cmd to execute various commands and payloads. Common uses include cmd to execute a single command, or abusing cmd interactively with input and output forwarded over a command and control channel.

Detection rules48

Rules on DetectionCode tagged with T1059.003.

Sigma28

RuleLevelLog source
AWS EC2 Startup Shell Script Changehighaws / NULL
Conhost.exe CommandLine Path Traversalhighwindows / process_creation
DNS Query by Finger Utilityhighwindows / dns_query
HackTool - CrackMapExec Executionhighwindows / process_creation
HackTool - CrackMapExec Execution Patternshighwindows / process_creation
HackTool - Koadic Executionhighwindows / process_creation
HackTool - RedMimicry Winnti Playbook Executionhighwindows / process_creation
HTML Help HH.EXE Suspicious Child Processhighwindows / process_creation
Network Connection Initiated via Finger.EXEhighwindows / network_connection
Operator Bloopers Cobalt Strike Commandshighwindows / process_creation
Operator Bloopers Cobalt Strike Moduleshighwindows / process_creation
Potential CommandLine Path Traversal Via Cmd.EXEhighwindows / process_creation
Suspicious HH.EXE Executionhighwindows / process_creation
Suspicious HWP Sub Processeshighwindows / process_creation
AppLocker Application Would Have Been Blockedmediumwindows / NULL

Splunk20

RuleTypeRiskData source
CMD Carry Out String Command ParameterHuntingNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
CMD Echo Pipe - EscalationTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
CrushFTP Authentication Bypass ExploitationTTPNULLCrushFTP
Detect Prohibited Applications Spawning cmd exeHuntingNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Detect Use of cmd exe to Launch Script InterpretersAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
First time seen command line argumentHuntingNULLSysmon EventID 1
Potentially malicious code on commandlineAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Ryuk Wake on LAN CommandTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Windows Command Shell DCRat ForkBomb PayloadTTPNULLSysmon EventID 1, CrowdStrike ProcessRollup2
Windows connhost exe started forcefullyTTPNULLSysmon EventID 1
Windows Content Copied from Browser was ExecutedTTPNULLSysmon EventID 13 AND Sysmon EventID 24
Windows File Association Modification via FtypeAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Windows For Loop Usage Within Cmd.exe To Execute CommandsAnomalyNULLSysmon EventID 1, CrowdStrike ProcessRollup2
Windows PowerShell FakeCAPTCHA Clipboard ExecutionTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2, Cisco Network Visibility Module Flow Data
Windows Powershell History File DeletionAnomalyNULLPowershell Script Block Logging 4104

Groups73

Show 49 more

Software295

Show 271 more
BlackCatBLACKCOFFEEBlackMouldBLINDINGCANBONDUPDATERBoxCaonBrute Ratel C4BumblebeeCALENDARCarbanakCardinal RATCARROTBATCaterpillar WebShellccf32ChaesCharmPowerChina ChopperClamblingClopcmdCobalt StrikeCobian RATCoinTickerComnieComRATContiCovenantCozyCarCrimsonCubaDanBotDarkCometDarkGateDarkTortillaDarkWatchmanDaserfDEADEYEDealersChoiceDenisDipsindDiskpartDnsSystemDownPaperDropBookDtrackDUSTTRAPECCENTRICBANDWAGONEgregorEmbargoEmissaryEmotetEmpireEnvyScoutEvilBunnyExaramel for WindowsFelismusFELIXROOTFlagproFlawedAmmyyFunnyDreamGelsemiumGold DragonGoldenSpyGoldMaxGoopyGravityRATGreyEnergyGrimAgentH1N1HannotogHARDRAINHavocHAWKBALLhcdLoaderHeartCryptHelminthHermeticWiperHermeticWizardHi-ZorHiddenWaspHikitHOMEFRYHOPLIGHTHotCroissantHTTPBrowserhttpclientHTTPTroyInnaputRATInvisiMoleIPsec HelperIronWindIxesheJCryJHUHUGITJPINjRATKapekaKasidetKazuarKevinKeyBoyKEYMARBLEKGH_SPYKoadicKOCTOPUSKOMPROGOKONNILAMEHUGLatrodectusLightNeuronLinfoLizarLockBit 2.0LokibotLookBackLoudMinerLuciferLunarWebMafaldaMagicRATManjusakaMarkiRATMazeMCMDMechaFlounderMedusa RansomwareMegaCortexMegazordMetamorfoMeteorMicropsiaMilanMirageFoxMis-TypeMisdatMivastMoleNetMoonWindMore_eggsMosquitoMuddyViperMultiLayer WiperMURKYTOPNanoCoreNavRATNebulaeNETEAGLENetwalkerNETWIRENightdoornjRATOceanSaltODAgentOilBoosterOkrumOopsIEOrzOut1OutSteelPcSharePeppyPHOREALPikabotPingPullPisloaderPLAINTEEPLEADPlugXPoetRATPoisonIvyPonyPowerDukePOWRUNERProxysvcPteranodonPUBLOADPyDCryptQakBotQilinQUADAGENTQuasarRATRagnar LockerRainyDayRansomHubRaspberry RobinRATANKBARCSessionRDATRedLeavesRedLine StealerRemcosRemexiRevenge RATREvilRGDoorRising SunROADSWEEPRobbinHoodRogueRobinRTMRunningRATRyukS-TypeSaint BotSakulaSampleCheck5000SamSamSamuraiSardonicSDBbotSeaDukeSeasaltSEASHARPEEServHelperSeth-LockerSharkSharpDiscoSharpStageShimRatSideTwistSILENTTRINITYSiloscapeSLOTHFULMEDIASmall SieveSNUGRIDESparkSQLRatSquirrelwaffleSTARWHALEStreamExStrelaStealerStrifeWaterSUGARUSHSYSCONSystemBCTaidoorTAINTEDSCRIBETAMECATTarraskTDTESSTEXTMATETinyTurlaTinyZBotTONESHELLTrickBotTrojan.KaraganyTroll StealerTSCookieTurianTURNEDUPTYPEFRAMEUBoatRATUmbreonUPPERCUTUroburosUSBferryVolgmerWarzoneRATWastedLockerWEBC2WellMessWhisperGateWiarpWoody RATxCaonXTunnelZebrocyZeus PandaZLibzwShellZxShell

Campaigns18

Procedure examples386

Groups73

Used byProcedure example
Groupadmin@338

Following exploitation with LOWBALL malware, admin@338 actors created a file containing a list of commands to be executed on the compromised computer.

GroupAgrius

Agrius uses ASPXSpy web shells to enable follow-on command execution via cmd.exe.

GroupAPT1

APT1 has used the Windows command shell to execute commands, and batch scripting to automate execution.

GroupAPT18

APT18 uses cmd.exe to execute commands on the victim’s machine.

GroupAPT28

An APT28 loader Trojan uses a cmd.exe and batch script to run its payload. The group has also used macros to execute payloads.

GroupAPT3

An APT3 downloader uses the Windows command "cmd.exe" /C whoami. The group also uses a tool to execute commands on remote computers.

GroupAPT32

APT32 has used cmd.exe for execution.

GroupAPT37

APT37 has used the command-line interface.

View all 73 groups examples

Software295

Used byProcedure example
Malware4H RAT

4H RAT has the capability to create a remote shell.

MalwareABK

ABK has the ability to use cmd to run a Portable Executable (PE) on the compromised host.

MalwareAction RAT

Action RAT can use `cmd.exe` to execute commands on an infected host.

Malwareadbupd

adbupd can run a copy of cmd.exe.

MalwareADVSTORESHELL

ADVSTORESHELL can create a remote shell and run a given command.

MalwareAkira

Akira executes from the Windows command line and can take various arguments for execution.

MalwareAnchor

Anchor has used cmd.exe to run its self deletion routine.

MalwareAstaroth

Astaroth spawns a CMD process to execute commands.

View all 295 software examples

Campaigns18

Used byProcedure example
Campaign2016 Ukraine Electric Power Attack

During the 2016 Ukraine Electric Power Attack, Sandworm Team used the `xp_cmdshell` command in MS-SQL.

Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries leveraged PsExec to run `cmd.exe` commands on multiple victim machines.

CampaignAPT28 Nearest Neighbor Campaign

During APT28 Nearest Neighbor Campaign, APT28 used cmd.exe for execution.

CampaignC0015

During C0015, the threat actors used `cmd.exe` to execute commands and run malicious binaries.

CampaignC0017

During C0017, APT41 used `cmd.exe` to execute reconnaissance commands.

CampaignFrankenstein

During Frankenstein, the threat actors ran a command script to set up persistence as a scheduled task named "WinUpdate", as well as other encoded commands from the command-line

CampaignFunnyDream

During FunnyDream, the threat actors used `cmd.exe` to execute the wmiexec.vbs script.

CampaignHomeLand Justice

During HomeLand Justice, threat actors used Windows batch files for persistence and execution.

View all 18 campaigns examples

References1

  1. SSH in Windows Open source
    Microsoft. (2020, May 19). Tutorial: SSH in Windows Terminal. Retrieved July 26, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.