T1059.003 Windows Command Shell — ATT&CK Technique
Adversaries may abuse the Windows command shell for execution. The Windows command shell (cmd) is the primary command prompt on Windows systems. The Windows command prompt can be used to control almost any aspect of a system, with various permission levels required for different subsets of commands. The command prompt can be invoked remotely via Remote Services such as SSH. Batch files (ex: .bat or .cmd) also provide the shell with a list of sequential commands to run, as well as normal scripting operations such as conditionals and loops. Common uses of batch files include long or repetitive tasks, or the need to run the same set of commands on multiple systems. Adversaries may leverage cmd to execute various commands and payloads. Common uses include cmd to execute a single command, or abusing cmd interactively with input and output forwarded over a command and control channel.
Detection coverage (50)
- Rorschach Ransomware Execution Activity critical
- Potential APT FIN7 Exploitation Activity medium
- Potential SAP NetWeaver Webshell Creation - Linux medium
- Potential SAP NetWeaver Webshell Creation medium
- Suspicious Child Process of SAP NetWeaver - Linux medium
- Suspicious CrushFTP Child Process medium
- Suspicious Process Spawned by CentreStack Portal AppPool high
- Suspicious Child Process of SAP NetWeaver medium
- Potential Exploitation of CrushFTP RCE Vulnerability (CVE-2025-54309) high
- Axios NPM Compromise Indicators - Windows high
- Headless Process Launched Via Conhost.EXE medium
- AWS EC2 Startup Shell Script Change high
- PUA - AdvancedRun Execution medium
- AppLocker Prevented Application or Script from Running medium
- Remote Access Tool - ScreenConnect File Transfer low
- Remote Access Tool - ScreenConnect Command Execution low
- DNS Query by Finger Utility high
- Remote Access Tool - ScreenConnect Temporary File low
- Network Connection Initiated via Finger.EXE high
- Powershell Execute Batch Script medium
- Potential CommandLine Path Traversal Via Cmd.EXE high
- Command Line Execution with Suspicious URL and AppData Strings medium
- Powershell Executed From Headless ConHost Process medium
- Conhost.exe CommandLine Path Traversal high
- Read Contents From Stdin Via Cmd.EXE medium
- OpenEDR Spawning Command Shell medium
- HTML Help HH.EXE Suspicious Child Process high
- Operator Bloopers Cobalt Strike Commands high
- HackTool - CrackMapExec Execution Patterns high
- Suspicious HH.EXE Execution high
- Operator Bloopers Cobalt Strike Modules high
- HackTool - CrackMapExec Execution high
- HackTool - Jlaive In-Memory Assembly Execution medium
- HackTool - Koadic Execution high
- HackTool - RedMimicry Winnti Playbook Execution high
- Suspicious HWP Sub Processes high
- Remote Access Tool - ScreenConnect Remote Command Execution low
- Suspicious Usage of For Loop with Recursive Directory Search in CMD medium
- CMD Carry Out String Command Parameter
- CMD Echo Pipe - Escalation
- Detect Prohibited Applications Spawning cmd exe
- Detect Use of cmd exe to Launch Script Interpreters
- Ryuk Wake on LAN Command
- ZxShell Malware critical
- Windows Command Shell DCRat ForkBomb Payload
- Windows File Association Modification via Ftype
- Windows Powershell History File Deletion
- Windows PowerShell FakeCAPTCHA Clipboard Execution
- Windows PowerShell Invoke-Sqlcmd Execution
- Windows Shell Process from CrushFTP
Malware using this technique
- TrickBot
- PowerDuke
- BLINDINGCAN
- Pikabot
- Wiarp
- RCSession
- Spark
- Bumblebee
- MURKYTOP
- Exaramel for Windows
- Orz
- IronWind
- Bandook
- MagicRAT
- SEASHARPEE
- POWRUNER
- RobbinHood
- TDTESS
- SharpStage
- Sardonic
- Misdat
- adbupd
- Emissary
- KEYMARBLE
- HAWKBALL
- TAMECAT
- HeartCrypt
- RansomHub
- ZLib
- RedLeaves
- Felismus
- Zeus Panda
- Havoc
- ShimRat
- CARROTBAT
- GravityRAT
- WEBC2
- Bankshot
- xCaon
- PLAINTEE
- Pony
- Nebulae
- AuditCred
- Kasidet
- Hannotog
- OceanSalt
- Medusa Ransomware
- RainyDay
- NETWIRE
- TinyTurla
Threat actors using this technique
- RansomExx
- APT38
- BlackByte
- Evil Corp
- APT37
- FIN7
- DragonForce
- Play Ransomware
- Storm-2603
- Rancor
- WIRTE
- APT35
- GALLIUM
- APT3
- Kimsuky
- TA577
- admin@338
- Volt Typhoon
- Patchwork
- APT41
- Dragonfly
- Gorgon Group
- APT10
- APT32
- HAFNIUM
- MuddyWater
- FIN6
- Lazarus Group
- Gamaredon Group
- Storm-1811
- TeamTNT
- Machete
- APT18
- Mustang Panda
- ZIRCONIUM
- UNC3886
- Contagious Interview
- OilRig
- Higaisa
- APT27
- Tropic Trooper
- Suckfly
- Aquatic Panda
- APT15
- Saint Bear
- APT1
- Blue Mockingbird
- Winter Vivern
- Turla
- TA505