Cross-source coverage

T1059 / ATT&CK

Command and Scripting Interpreter

1442 rules · 1422 families across 13 sources.

91 deprecated hidden · include

From MITRE ATT&CK 19.2

Adversaries may abuse command and script interpreters to execute commands, scripts, or binaries. These interfaces and languages provide ways of interacting with computer systems and are a common feature across many different platforms. Most systems come with some built-in command-line interface and scripting capabilities, for example, macOS and Linux distributions include some flavor of Unix Shell while Windows installations include the Windows Command Shell and PowerShell.

There are also cross-platform interpreters such as Python, as well as those commonly associated with client applications such as JavaScript and Visual Basic.

Adversaries may abuse these technologies in various ways as a means of executing arbitrary commands. Commands and scripts can be embedded in Initial Access payloads delivered to victims as lure documents or as secondary payloads downloaded from an existing C2. Adversaries may also execute commands through interactive terminals/shells, as well as utilize various Remote Services in order to achieve remote Execution.

Tactics
Execution
Platforms
Containers · ESXi · IaaS · Identity Provider · Linux · macOS · Network Devices · Office Suite · SaaS · Windows
Telemetry
WinEventLog:Sysmonauditd:SYSCALLmacos:unifiedlogesxi:vobdnetworkdevice:clinetworkdevice:syslog

How MITRE says to detect it DET0516

Behavioral Detection of Command and Scripting Interpreter Abuse

Windows Analytic 1428

Detects the execution of scripting or command interpreters (e.g., powershell.exe, cmd.exe, wscript.exe) outside expected administrative time windows or from abnormal user contexts, often followed by encoded/obfuscated arguments or secondary execution events.

  • WinEventLog:Sysmon EventCode=1

Linux Analytic 1429

Detects use of shell interpreters (e.g., bash, sh, python, perl) initiated by users or processes not normally executing them, especially when chaining suspicious utilities like netcat, curl, or ssh.

  • auditd:SYSCALL execve

macOS Analytic 1430

Detects launch of command-line interpreters via Terminal, Automator, or hidden `osascript`, especially when parent process lineage deviates from user-initiated applications.

  • macos:unifiedlog log stream --info --predicate 'eventMessage CONTAINS "exec"'

ESXi Analytic 1431

Detects use of 'esxcli system' or direct interpreter commands (e.g., busybox shell) invoked from SSH or host terminal unexpectedly.

  • esxi:vobd shell session start

Network Devices Analytic 1432

Identifies CLI interpreter access (e.g., Cisco IOS, Juniper JUNOS) via `enable` mode or scripting-capable sessions used by uncommon accounts or from unknown IPs.

  • networkdevice:cli shell command
  • networkdevice:syslog authentication & authorization

Sub-techniques with coverage

Counted in the 1442 above — a rule tagged a sub-technique covers this technique too.


SigmaHQ/sigma

424 rules
Detection Severity Format
Bad Opsec Powershell Code Artifacts Critical Sigma
Elise Backdoor Activity Critical Sigma
Greenbug Espionage Group Indicators Critical Sigma
HackTool - Sliver C2 Implant Activity Pattern Critical Sigma
Lazarus Group Activity Critical Sigma
Linux Reverse Shell Indicator Critical Sigma
Potential QBot Activity Critical Sigma
REvil Kaseya Incident Malware Patterns Critical Sigma
Rorschach Ransomware Execution Activity Critical Sigma
Silence.EDA Detection Critical Sigma

+ 414 more from SigmaHQ/sigma → showing the 10 highest-severity

elastic/protections-artifacts

372 rules · 370 families
Detection Severity Format
Abnormal Auval Child Process Execution Undefined Elastic TOML
Abnormally Large Javascript Evaluation via Nodejs Undefined Elastic TOML
Abnormally Large Shell Script Execution via Perl Undefined Elastic TOML
Access to Windows Passwords Vault via Powershell Undefined Elastic TOML
AMSI Bypass via PowerShell Undefined Elastic TOML
AppleScript Decoded via Base64 Undefined Elastic TOML
Arbitrary Python Code Execution via Nodejs Undefined Elastic TOML
Attempt to establish VScode Remote Tunnel Undefined Elastic TOML
At Utility Launched through Udevadm Undefined Elastic TOML
Background Process Execution via Shell Undefined Elastic TOML

+ 362 more from elastic/protections-artifacts → showing the 10 highest-severity

elastic/detection-rules

305 rules
Detection Severity Format
Potential Redis Lua Use-After-Free RCE Attempt (CVE-2025-49844 / RediShell) Critical Elastic TOML
Attempt to Install or Run Kali Linux via WSL High Elastic TOML
AWS Bedrock High Risk Filesystem or Execution Tool Invocation High Elastic TOML
AWS CloudShell Environment Created High Elastic TOML
AWS EC2 Stop, Start, and User Data Modification Correlation High Elastic TOML
AWS SageMaker Notebook Lifecycle Configuration With Suspicious Script Content High Elastic TOML
Base64 Decoded Payload Piped to Interpreter High Elastic TOML
Binary Executed from Shared Memory Directory High Elastic TOML
BPF filter applied using TC High Elastic TOML
Cassandra JavaScript UDF Creation High Elastic TOML

+ 295 more from elastic/detection-rules → showing the 10 highest-severity

splunk/security_content

151 rules
Detection Severity Format
Cisco IOS XE Guestshell Activation and Destroy Undefined SPL
Cisco IOS XE Request Platform Package Describe Shell Pattern Undefined SPL
Cisco NVM - Installation of Typosquatted Python Package Undefined SPL
Cisco NVM - MSHTML or MSHTA Network Execution Without URL in CLI Undefined SPL
Cisco NVM - Suspicious File Download via Headless Browser Undefined SPL
Cisco NVM - Susp Script From Archive Triggering Network Activity Undefined SPL
Cisco Secure Firewall - Binary File Type Download Undefined SPL
Cisco Secure Firewall - Citrix NetScaler Memory Overread Attempt Undefined SPL
Cisco Secure Firewall - Communication Over Suspicious Ports Undefined SPL
Cisco Secure Firewall - High Volume of Intrusion Events Per Host Undefined SPL

+ 141 more from splunk/security_content → showing the 10 highest-severity

socfortress/Wazuh-Rules

84 rules · 76 families
Detection Severity Format
Change of login shell to /bin/sh (T1059.004) High Wazuh XML
Detects BPFDoor .lock and .pid files access in temporary file storage facility. 2 variants High Wazuh XML
Detects BPFDoor .lock and .pid files access in temporary file storage facility. 2 variants High Wazuh XML
Detects relevant commands often related to malware or hacking activity. 2 variants High Wazuh XML
Detects relevant commands often related to malware or hacking activity. 2 variants High Wazuh XML
Execution of privilege escalation scripts (AutoSUID, LinEnum) - T1059.004 High Wazuh XML
Execution of remote script via pipe-to-shell method (T1059.004) High Wazuh XML
Obfuscated base64-encoded payload piped to shell (T1059.004) High Wazuh XML
Powershell script: C2/exploitation keyword detected High Wazuh XML
Powershell script: $doit variable detected (exploit scripts) High Wazuh XML

+ 74 more from socfortress/Wazuh-Rules → showing the 10 highest-severity

Wazuh Core Ruleset

41 rules
Detection Severity Format
Office application started mshta.exe and executed scripting command Critical Wazuh XML
Possible Shimming. Application Compatibility Database launched from an encoded powershell command Critical Wazuh XML
Powershell script used "Invoke-command" cmdlet to execute code on remote computer Critical Wazuh XML
Powershell used to copy SAM hive from VSS Critical Wazuh XML
Suspicious execution of .js file by · win.eventdata.parentCommandLine = (?i)svchost.exe -k netsvcs -p, win.eventdata.commandLine = (?i)appdata\\\\.+\.exe.+\.js Critical Wazuh XML
A powershell process created by WMI executed a base64 encoded command High Wazuh XML
Binary loaded PowerShell automation library - Possible unmanaged Powershell execution by suspicious process High Wazuh XML
Detected a suspicious process launched with a jscript engine signature High Wazuh XML
Executed a renamed copy of wscript.exe High Wazuh XML
from same source ip. High Wazuh XML

+ 31 more from Wazuh Core Ruleset → showing the 10 highest-severity

falcosecurity/rules

15 rules
Detection Severity Format
Reverse Shell from Web Server Critical Falco YAML
Container Drift Detected (chmod) High Falco YAML
Container Drift Detected (open+create) High Falco YAML
Execution from /dev/shm Medium Falco YAML
Netcat Remote Code Execution in Container Medium Falco YAML
Netcat/Socat Remote Code Execution on Host Medium Falco YAML
Web Server Spawned Suspicious Child Process Medium Falco YAML
Disallowed SSH Connection Non Standard Port Low Falco YAML
Launch Suspicious Network Tool in Container Low Falco YAML
Launch Suspicious Network Tool on Host Low Falco YAML

+ 5 more from falcosecurity/rules → showing the 10 highest-severity

Azure/Azure-Sentinel

14 rules
Detection Severity Format
Application Gateway WAF - SQLi Detection High KQL
SUNBURST and SUPERNOVA backdoor hashes (Normalized File Events) High KQL
A host is potentially running a hacking tool (ASIM Web Session schema) Medium KQL
A host is potentially running PowerShell to send HTTP(S) requests (ASIM Web Session schema) Medium KQL
Azure VM Run Command operations executing a unique PowerShell script Medium KQL
Base64 encoded Windows process command-lines (Normalized Process Events) Medium KQL
Exchange Worker Process Making Remote Call Medium KQL
Midnight Blizzard - Script payload stored in Registry Medium KQL
SUNBURST suspicious SolarWinds child processes (Normalized Process Events) Medium KQL
AI Agents - MCP Tool Configured Undefined KQL

+ 4 more from Azure/Azure-Sentinel → showing the 10 highest-severity

panther-labs/panther-analysis

11 rules
Detection Severity Format
AWS EC2 Startup Script Change High Panther Python
AWS WAF Managed Known Bad Inputs Passthrough Rule High Panther Python
AWS WAF ReactJS RCE Attempt via Body High Panther Python
Crowdstrike Reverse Shell Tool Executed High Panther Python
StopInstance WITH ModifyInstanceAttributes High Panther Python
Teleport Suspicious Commands Executed Medium Panther Python
Upwind Runtime Detection Passthrough Medium Panther Python
User Logged in as root Medium Panther Python
Azure Automation Runbook Created or Modified Informational Panther Python
Azure Serverless Script Execution Informational Panther Python

+ 1 more from panther-labs/panther-analysis → showing the 10 highest-severity

Emerging Threats Open

8 rules
Detection Severity Format
ET HUNTING Dotted Quad Host Base64-Encoded PHP payload High Suricata
ET HUNTING Dotted Quad Host Base64-Encoded Powershell Payload High Suricata
ET HUNTING Dotted Quad Host Suspected IoT Botnet Loader Shell Script High Suricata
ET HUNTING HTTP Response Containing Base64-Encoded and Compressed Powershell Payload Keywords High Suricata
ET HUNTING HTTP Response Containing Base64-Encoded Powershell Payload Keywords High Suricata
ET HUNTING schtasks create Command in HTTP Body Response High Suricata
ET MALWARE Commvault Pre-Auth RCE (CVE-2025-34028) Post-Exploitation Activity (jsp webshell) High Suricata
ET HUNTING Telegram API Request (POST) Informational Suricata

Bert-JanP/Hunting-Queries-Detection-Rules

7 rules
Detection Severity Format
AMSI Script Detection Undefined KQL
MITRE ATT&CK Mapping Undefined KQL
PowerShell Invoke-Webrequest Undefined KQL
Smoke Sandstorm - SnailResin and SlugResin Infection Detection Undefined KQL
Suspicious Browser Child Process Undefined KQL
Suspicious Explorer Child Process Undefined KQL
TTP Detection Rule: PowerShell Launching Scripts From WindowsApps Directory (FIN7) Undefined KQL

chronicle/detection-rules

7 rules
Detection Severity Format
base64_encoded_powershell_command_detected High YARA-L
powershell_downloadfile High YARA-L
sap_execution_of_sensitive_abap_program High YARA-L
convertto_securestring_cmdlet_usage_via_commandline Medium YARA-L
hacktool_ironsharp_pack_execution Medium YARA-L
powershell_web_download Medium YARA-L
ttp_windows_w3wp_launching_encoded_powershell Medium YARA-L

chainguard-dev/osquery-defense-kit

3 rules
Detection Severity Format
Uncover reverse-shell processes Undefined osquery SQL
Unexpected process that spawns shell processes (event based) Undefined osquery SQL
Unexpected process that spawns shell processes (event-based) Undefined osquery SQL

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.