T1059 Command and Scripting Interpreter — ATT&CK Technique
Adversaries may abuse command and script interpreters to execute commands, scripts, or binaries. These interfaces and languages provide ways of interacting with computer systems and are a common feature across many different platforms. Most systems come with some built-in command-line interface and scripting capabilities, for example, macOS and Linux distributions include some flavor of Unix Shell while Windows installations include the Windows Command Shell and PowerShell. There are also cross-platform interpreters such as Python, as well as those commonly associated with client applications such as JavaScript and Visual Basic. Adversaries may abuse these technologies in various ways as a means of executing arbitrary commands. Commands and scripts can be embedded in Initial Access payloads delivered to victims as lure documents or as secondary payloads downloaded from an existing C2. Adversaries may also execute commands through interactive terminals/shells, as well as utilize various Remote Services in order to achieve remote Execution.
Detection coverage (50)
- Turla Group Lateral Movement critical
- Lazarus Group Activity critical
- Potential CVE-2021-40444 Exploitation Attempt high
- Potential Atlassian Confluence CVE-2021-26084 Exploitation Attempt high
- Python Spawning Pretty TTY Via PTY Module medium
- Suspicious Execution via macOS Script Editor medium
- REvil Kaseya Incident Malware Patterns critical
- Atlassian Confluence CVE-2022-26134 high
- CVE-2023-22518 Exploitation Attempt - Suspicious Confluence Child Process (Windows) medium
- Potential MOVEit Transfer CVE-2023-34362 Exploitation - Dynamic Compilation Via Csc.EXE medium
- CVE-2023-22518 Exploitation Attempt - Suspicious Confluence Child Process (Linux) high
- DarkGate - Autoit3.EXE Execution Parameters high
- DarkGate - Autoit3.EXE File Creation By Uncommon Process medium
- Ursnif Redirection Of Discovery Commands high
- DarkGate - Drop DarkGate Loader In C:\Temp Directory medium
- Potential KamiKakaBot Activity - Lure Document Execution medium
- Shai-Hulud Malware Indicators - Linux high
- Shai-Hulud Malware Indicators - Windows high
- Linux Suspicious Child Process from Node.js - React2Shell high
- Windows Suspicious Child Process from Node.js - React2Shell high
- DNS Request From Windows Script Host low
- Elevated System Shell Spawned medium
- Manual Execution of Script Inside of a Compressed File medium
- Azure New CloudShell Created medium
- Payload Decoded and Decrypted via Built-in Utilities medium
- BPFDoor Abnormal Process ID or Lock File Accessed high
- Shell Execution via Git - Linux high
- Potential Netcat Reverse Shell Execution high
- Inline Python Execution - Spawn Shell Via OS System Library high
- Suspicious Java Children Processes high
- Shell Execution via Rsync - Linux high
- Suspicious Invocation of Shell via Rsync high
- Shell Invocation Via Ssh - Linux high
- Potential Xterm Reverse Shell medium
- Suspicious Browser Child Process - MacOS medium
- Python Inline Command Execution medium
- PUA - Wsudo Suspicious Execution high
- Suspicious Greedy Compression Using Rar.EXE high
- Python Spawning Pretty TTY on Windows high
- Suspicious RASdial Activity medium
- Suspicious Invocation of Shell via AWK - Linux high
- Capsh Shell Invocation - Linux high
- Suspicious Installer Package Child Process medium
- Hacktool Ruler high
- Windows Defender AMSI Trigger Detected high
- Windows Defender Threat Detected high
- PCRE.NET Package Temp Files high
- Suspicious File Created In PerfLogs medium
- Windows Shell/Scripting Application File Write to Suspicious Folder high
- PCRE.NET Package Image Load high
Malware using this technique
- DarkComet
- StarProxy
- CHOPSTICK
- Donut
- FIVEHANDS
- Matryoshka
- Imminent Monitor
- Kessel
- ZeroCleare
- gh0st RAT
- P.A.S. Webshell
- WINERACK
- SLIGHTPULSE
- Bandook
- VersaMem
- Zeus Panda
- NICECURL
- SpeakUp
- Get2
- MuddyViper
- Empire
- Raspberry Robin
- Bonadan