Command and Scripting Interpreter

T1059

Technique with 13 sub-techniques.View on attack.mitre.org

About this technique

Adversaries may abuse command and script interpreters to execute commands, scripts, or binaries. These interfaces and languages provide ways of interacting with computer systems and are a common feature across many different platforms. Most systems come with some built-in command-line interface and scripting capabilities, for example, macOS and Linux distributions include some flavor of Unix Shell while Windows installations include the Windows Command Shell and PowerShell.

There are also cross-platform interpreters such as Python, as well as those commonly associated with client applications such as JavaScript and Visual Basic.

Adversaries may abuse these technologies in various ways as a means of executing arbitrary commands. Commands and scripts can be embedded in Initial Access payloads delivered to victims as lure documents or as secondary payloads downloaded from an existing C2. Adversaries may also execute commands through interactive terminals/shells, as well as utilize various Remote Services in order to achieve remote Execution.

Detection rules512

Rules on DetectionCode tagged with T1059 or one of its sub-techniques.

Sigma339

RuleLevelLog sourceTechnique
Bad Opsec Powershell Code Artifactscriticalwindows / ps_moduleT1059.001
HackTool - Sliver C2 Implant Activity Patterncriticalwindows / process_creationT1059
Linux Reverse Shell Indicatorcriticallinux / network_connectionT1059.004
Silence.EDA Detectioncriticalwindows / ps_scriptT1059.001
Abusable DLL Potential Sideloading From Suspicious Locationhighwindows / image_loadT1059
Add Insecure Download Source To Wingethighwindows / process_creationT1059
Adwind RAT / JRAT File Artifacthighwindows / file_eventT1059.005 T1059.007
Atlassian Confluence CVE-2022-26134highlinux / process_creationT1059
AWS EC2 Startup Shell Script Changehighaws / NULLT1059.001 T1059.003 T1059.004
AWS IAM S3Browser LoginProfile Creationhighaws / NULLT1059.009
AWS IAM S3Browser Templated S3 Bucket Policy Creationhighaws / NULLT1059.009
AWS IAM S3Browser User or AccessKey Creationhighaws / NULLT1059.009
Base64 Encoded PowerShell Command Detectedhighwindows / process_creationT1059.001
BloodHound Collection Fileshighwindows / file_eventT1059.001
BPFDoor Abnormal Process ID or Lock File Accessedhighlinux / NULLT1059

Splunk173

RuleTypeRiskData sourceTechnique
Any Powershell DownloadFileTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1059.001
Any Powershell DownloadStringTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1059.001
CHCP Command ExecutionAnomalyNULLSysmon EventID 1, CrowdStrike ProcessRollup2T1059
Cisco IOS XE Guestshell Activation and DestroyAnomalyNULLCisco IOS LogsT1059
Cisco IOS XE Request Platform Package Describe Shell PatternTTPNULLCisco IOS LogsT1059
Cisco NVM - Browser Spawned Unix Shell with External ConnectionAnomalyNULLCisco Network Visibility Module Flow DataT1059
Cisco NVM - Installation of Typosquatted Python PackageTTPNULLCisco Network Visibility Module Flow DataT1059
Cisco NVM - MSHTML or MSHTA Network Execution Without URL in CLIAnomalyNULLCisco Network Visibility Module Flow DataT1059.005
Cisco NVM - Osascript Network Connection for a Long DurationAnomalyNULLCisco Network Visibility Module Flow DataT1059.002
Cisco NVM - Susp Script From Archive Triggering Network ActivityAnomalyNULLCisco Network Visibility Module Flow DataT1059.005
Cisco NVM - Suspicious File Download via Headless BrowserTTPNULLCisco Network Visibility Module Flow DataT1059
Cisco Secure Firewall - Binary File Type DownloadAnomalyNULLCisco Secure Firewall Threat Defense File EventT1059
Cisco Secure Firewall - Citrix NetScaler Memory Overread AttemptTTPNULLCisco Secure Firewall Threat Defense Intrusion EventT1059
Cisco Secure Firewall - Communication Over Suspicious PortsAnomalyNULLCisco Secure Firewall Threat Defense Connection EventT1059.001
Cisco Secure Firewall - High Volume of Intrusion Events Per HostAnomalyNULLCisco Secure Firewall Threat Defense Intrusion EventT1059

Sub-techniques13

IDNameExamples
T1059.001PowerShell233
T1059.002AppleScript6
T1059.003Windows Command Shell386
T1059.004Unix Shell66
T1059.005Visual Basic131
T1059.006Python63
T1059.007JavaScript75
T1059.008Network Device CLI5
T1059.009Cloud API6
T1059.010AutoHotKey & AutoIT6
T1059.011Lua5
T1059.012Hypervisor CLI4
T1059.013Container CLI/API3

Groups17

Software23

Campaigns4

Procedure examples44

Groups17

Used byProcedure example
GroupAPT19

APT19 downloaded and launched code within a SCT file.

GroupAPT32

APT32 has used COM scriptlets to download Cobalt Strike beacons.

GroupAPT37

APT37 has used Ruby scripts to execute payloads.

GroupAPT39

APT39 has utilized custom scripts to perform internal reconnaissance.

GroupDragonfly

Dragonfly has used the command line for execution.

GroupFIN5

FIN5 scans processes on all victim systems in the environment and uses automated scripts to pull back the results.

GroupFIN6

FIN6 has used scripting to iterate through a list of compromised PoS systems, copy data to a log file, and remove the original data files.

GroupFIN7

FIN7 used SQL scripts to help perform tasks on the victim's machine.

View all 17 groups examples

Software23

Used byProcedure example
MalwareBandook

Bandook can support commands to execute Java-based payloads.

MalwareBonadan

Bonadan can create bind and reverse shells on the infected system.

MalwareCHOPSTICK

CHOPSTICK is capable of performing remote command execution.

MalwareDarkComet

DarkComet can execute various types of scripts on the victim’s machine.

ToolDonut

Donut can generate shellcode outputs that execute via Ruby.

ToolEmpire

Empire uses a command-line interface to interact with systems.

MalwareFIVEHANDS

FIVEHANDS can receive a command line argument to limit file encryption to specified directories.

MalwareGet2

Get2 has the ability to run executables with command-line arguments.

View all 23 software examples

Campaigns4

Used byProcedure example
CampaignArcaneDoor

ArcaneDoor included the adversary executing command line interface (CLI) commands.

CampaignCutting Edge

During Cutting Edge, threat actors used Perl scripts to enable the deployment of the THINSPOOL shell script dropper and for enumerating host data.

CampaignFLORAHOX Activity

FLORAHOX Activity has executed PHP and Shell scripts to identify and infect subsequent routers for the ORB network.

CampaignOperation Spalax

For Operation Spalax, the threat actors used Nullsoft Scriptable Install System (NSIS) scripts to install malware.

References3

  1. Cisco IOS Software Integrity Assurance - Command History Open source
    Cisco. (n.d.). Cisco IOS Software Integrity Assurance - Command History. Retrieved October 21, 2020.
  2. Powershell Remote Commands Open source
    Microsoft. (2020, August 21). Running Remote Commands. Retrieved July 26, 2021.
  3. Remote Shell Execution in Python Open source
    Abdou Rockikz. (2020, July). How to Execute Shell Commands in a Remote Machine in Python. Retrieved July 26, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.