Applied Cybernetics Group
T1059 — Command and Scripting Interpreter
- Technique
T1059- Tactics
- Execution
- MISP citations
- 0
- KEV CVEs mapped
- 170
- Community rules
- 93
- thrunt rules
- 0
- Upstream
- https://attack.mitre.org/techniques/T1059
MITRE description
Adversaries may abuse command and script interpreters to execute commands, scripts, or binaries. These interfaces and languages provide ways of interacting with computer systems and are a common feature across many different platforms. Most systems come with some built-in command-line interface and scripting capabilities, for example, macOS and Linux distributions include some flavor of [Unix Shell](https://attack.mitre.org/techniques/T1059/004) while Windows installations include the [Windows Command Shell](https://attack.mitre.org/techniques/T1059/003) and [PowerShell](https://attack.mitre.org/techniques/T1059/001). There are also cross-platform interpreters such as [Python](https://attack.mitre.org/techniques/T1059/006), as well as those commonly associated with client applications such as [JavaScript](https://attack.mitre.org/techniques/T1059/007) and [Visual Basic](https://attack.mitre.org/techniques/T1059/005). Adversaries may abuse these technologies in various ways as a means of executing arbitrary commands. Commands and scripts can be embedded in [Initial Access](https://attack.mitre.org/tactics/TA0001) payloads delivered to victims as lure documents or as secondary payloads downloaded from an existing C2. Adversaries may also execute commands through interactive terminals/shells, as well as utilize various [Remote Services](https://attack.mitre.org/techniques/T1021) in order to achieve remote Execution.(Citation: Powershell Remote Commands)(Citation: Cisco IOS Software Integrity Assurance - Command History)(Citation: Remote Shell Execution in Python)
KEV CVEs mapped to this technique
Per MITRE CTID's hand-curated KEV→ATT&CK mappings — these are the actively-exploited vulnerabilities behind this technique's KEV signal.
CVE-2025-6554CVE-2025-6543CVE-2025-53770CVE-2025-47812CVE-2025-4632CVE-2025-4428CVE-2025-4427CVE-2025-42999CVE-2025-42599CVE-2025-3935CVE-2025-3928CVE-2025-35939CVE-2025-33053CVE-2025-32756CVE-2025-32709CVE-2025-32706CVE-2025-32701CVE-2025-3248CVE-2025-32433CVE-2025-31324CVE-2025-31201CVE-2025-31200CVE-2025-31161CVE-2025-30406CVE-2025-30397CVE-2025-27038CVE-2025-24985CVE-2025-24201CVE-2025-24085CVE-2025-24016CVE-2025-23006CVE-2025-22457CVE-2025-21590CVE-2025-20337CVE-2025-20281CVE-2025-1976CVE-2025-0994CVE-2024-6047CVE-2024-58136CVE-2024-57968CVE-2024-57727CVE-2024-56145CVE-2024-53197CVE-2024-53104CVE-2024-5217CVE-2024-50603CVE-2024-4947CVE-2024-4885CVE-2024-4879CVE-2024-4761CVE-2024-4671CVE-2024-4577CVE-2024-45195CVE-2024-41710CVE-2024-38475CVE-2024-34102CVE-2024-29059CVE-2024-27198CVE-2024-26169CVE-2024-21887CVE-2024-21413CVE-2024-20953CVE-2024-20399CVE-2024-20359CVE-2024-12987CVE-2024-12686CVE-2024-11182CVE-2023-7101CVE-2023-48788CVE-2023-48365CVE-2023-43770CVE-2023-41179CVE-2023-40044CVE-2023-38035CVE-2023-36851CVE-2023-36847CVE-2023-36846CVE-2023-36845CVE-2023-35081CVE-2023-34362CVE-2023-34192CVE-2023-33538CVE-2023-33246CVE-2023-2868CVE-2023-28252CVE-2023-27350CVE-2023-26359CVE-2023-2533CVE-2023-22952CVE-2023-22515CVE-2023-20887CVE-2023-20867CVE-2023-20273CVE-2023-20118CVE-2023-20109CVE-2022-43939CVE-2022-43769CVE-2022-42948CVE-2022-41125CVE-2022-39197CVE-2022-37969CVE-2022-36804CVE-2022-35914CVE-2022-35405CVE-2022-34713CVE-2022-29303CVE-2022-26501CVE-2022-26500CVE-2022-26258CVE-2022-24521CVE-2022-23748CVE-2022-23131CVE-2022-22965CVE-2022-22947CVE-2022-22047CVE-2022-21999CVE-2022-21971CVE-2022-1040CVE-2021-45382CVE-2021-45046CVE-2021-42321CVE-2021-42258CVE-2021-42237CVE-2021-42013CVE-2021-41773CVE-2021-35464CVE-2021-35394CVE-2021-3129CVE-2021-31166CVE-2021-27104CVE-2021-27102CVE-2021-27101CVE-2021-26084CVE-2021-22986CVE-2021-22900CVE-2021-22894CVE-2021-22893CVE-2021-22205CVE-2021-22204CVE-2021-22005CVE-2021-21972CVE-2021-20035CVE-2021-1498CVE-2021-1497CVE-2020-8515CVE-2020-5902CVE-2020-3580CVE-2020-29574CVE-2020-29557CVE-2020-25506CVE-2020-17530CVE-2020-15505CVE-2020-0787CVE-2019-3398CVE-2019-19781CVE-2019-17558CVE-2019-13608CVE-2019-11634CVE-2019-11580CVE-2019-11510CVE-2018-7600CVE-2018-6789CVE-2018-11776CVE-2017-9822CVE-2017-9805CVE-2017-6742CVE-2017-5638CVE-2017-11882CVE-2016-4437CVE-2010-2883
Detection coverage
SigmaHQ community rules
- Turla Group Lateral Movement (emerging-threats)
- Lazarus Group Activity (emerging-threats)
- Potential Atlassian Confluence CVE-2021-26084 Exploitation Attempt (emerging-threats)
- Potential CVE-2021-40444 Exploitation Attempt (emerging-threats)
- REvil Kaseya Incident Malware Patterns (emerging-threats)
- Atlassian Confluence CVE-2022-26134 (emerging-threats)
- CVE-2023-22518 Exploitation Attempt - Suspicious Confluence Child Process (Linux) (emerging-threats)
- CVE-2023-22518 Exploitation Attempt - Suspicious Confluence Child Process (Windows) (emerging-threats)
- Potential MOVEit Transfer CVE-2023-34362 Exploitation - Dynamic Compilation Via Csc.EXE (emerging-threats)
- DarkGate - Autoit3.EXE File Creation By Uncommon Process (emerging-threats)
- DarkGate - Autoit3.EXE Execution Parameters (emerging-threats)
- Ursnif Redirection Of Discovery Commands (emerging-threats)
- DarkGate - Drop DarkGate Loader In C:\Temp Directory (emerging-threats)
- Potential KamiKakaBot Activity - Lure Document Execution (emerging-threats)
- Linux Suspicious Child Process from Node.js - React2Shell (emerging-threats)
- Windows Suspicious Child Process from Node.js - React2Shell (emerging-threats)
- Shai-Hulud Malware Indicators - Linux (emerging-threats)
- Shai-Hulud Malware Indicators - Windows (emerging-threats)
- Elevated System Shell Spawned (threat-hunting)
- Manual Execution of Script Inside of a Compressed File (threat-hunting)
- Azure New CloudShell Created (core)
- BPFDoor Abnormal Process ID or Lock File Accessed (core)
- Suspicious Invocation of Shell via AWK - Linux (core)
- Capsh Shell Invocation - Linux (core)
- Shell Execution via Git - Linux (core)
Showing 25 of 93 community rules —
the full set is tagged attack.t1059 in
SigmaHQ.