Cross-source coverage
T1059 / ATT&CK
Command and Scripting Interpreter
1533 rules · 1510 families across 13 sources.
Showing deprecated rules · back to the default
From MITRE ATT&CK 19.2
Adversaries may abuse command and script interpreters to execute commands, scripts, or binaries. These interfaces and languages provide ways of interacting with computer systems and are a common feature across many different platforms. Most systems come with some built-in command-line interface and scripting capabilities, for example, macOS and Linux distributions include some flavor of Unix Shell while Windows installations include the Windows Command Shell and PowerShell.
There are also cross-platform interpreters such as Python, as well as those commonly associated with client applications such as JavaScript and Visual Basic.
Adversaries may abuse these technologies in various ways as a means of executing arbitrary commands. Commands and scripts can be embedded in Initial Access payloads delivered to victims as lure documents or as secondary payloads downloaded from an existing C2. Adversaries may also execute commands through interactive terminals/shells, as well as utilize various Remote Services in order to achieve remote Execution.
- Tactics
- Execution
- Platforms
- Containers · ESXi · IaaS · Identity Provider · Linux · macOS · Network Devices · Office Suite · SaaS · Windows
- Telemetry
-
WinEventLog:Sysmonauditd:SYSCALLmacos:unifiedlogesxi:vobdnetworkdevice:clinetworkdevice:syslog
How MITRE says to detect it DET0516
Behavioral Detection of Command and Scripting Interpreter Abuse
Windows Analytic 1428
Detects the execution of scripting or command interpreters (e.g., powershell.exe, cmd.exe, wscript.exe) outside expected administrative time windows or from abnormal user contexts, often followed by encoded/obfuscated arguments or secondary execution events.
WinEventLog:SysmonEventCode=1
Linux Analytic 1429
Detects use of shell interpreters (e.g., bash, sh, python, perl) initiated by users or processes not normally executing them, especially when chaining suspicious utilities like netcat, curl, or ssh.
auditd:SYSCALLexecve
macOS Analytic 1430
Detects launch of command-line interpreters via Terminal, Automator, or hidden `osascript`, especially when parent process lineage deviates from user-initiated applications.
macos:unifiedloglog stream --info --predicate 'eventMessage CONTAINS "exec"'
ESXi Analytic 1431
Detects use of 'esxcli system' or direct interpreter commands (e.g., busybox shell) invoked from SSH or host terminal unexpectedly.
esxi:vobdshell session start
Network Devices Analytic 1432
Identifies CLI interpreter access (e.g., Cisco IOS, Juniper JUNOS) via `enable` mode or scripting-capable sessions used by uncommon accounts or from unknown IPs.
networkdevice:clishell commandnetworkdevice:syslogauthentication & authorization
Sub-techniques with coverage
Counted in the 1533 above — a rule tagged a sub-technique covers this technique too.
- T1059.001 PowerShell 521
- T1059.004 Unix Shell 369
- T1059.007 JavaScript 153
- T1059.003 Windows Command Shell 143
- T1059.005 Visual Basic 109
- T1059.006 Python 97
- T1059.002 AppleScript 49
- T1059.011 Lua 15
- T1059.012 Hypervisor CLI 9
- T1059.009 Cloud API 6
- T1059.010 AutoHotKey & AutoIT 1
- T1059.013 Container CLI/API 1
SigmaHQ/sigma
424 rules| Detection | Severity | Format |
|---|---|---|
| Bad Opsec Powershell Code Artifacts | Critical | Sigma |
| Elise Backdoor Activity | Critical | Sigma |
| Greenbug Espionage Group Indicators | Critical | Sigma |
| HackTool - Sliver C2 Implant Activity Pattern | Critical | Sigma |
| Lazarus Group Activity | Critical | Sigma |
| Linux Reverse Shell Indicator | Critical | Sigma |
| Potential QBot Activity | Critical | Sigma |
| REvil Kaseya Incident Malware Patterns | Critical | Sigma |
| Rorschach Ransomware Execution Activity | Critical | Sigma |
| Silence.EDA Detection | Critical | Sigma |
+ 414 more from SigmaHQ/sigma → showing the 10 highest-severity
elastic/protections-artifacts
372 rules · 370 families| Detection | Severity | Format |
|---|---|---|
| Abnormal Auval Child Process Execution | Undefined | Elastic TOML |
| Abnormally Large Javascript Evaluation via Nodejs | Undefined | Elastic TOML |
| Abnormally Large Shell Script Execution via Perl | Undefined | Elastic TOML |
| Access to Windows Passwords Vault via Powershell | Undefined | Elastic TOML |
| AMSI Bypass via PowerShell | Undefined | Elastic TOML |
| AppleScript Decoded via Base64 | Undefined | Elastic TOML |
| Arbitrary Python Code Execution via Nodejs | Undefined | Elastic TOML |
| Attempt to establish VScode Remote Tunnel | Undefined | Elastic TOML |
| At Utility Launched through Udevadm | Undefined | Elastic TOML |
| Background Process Execution via Shell | Undefined | Elastic TOML |
+ 362 more from elastic/protections-artifacts → showing the 10 highest-severity
elastic/detection-rules
329 rules| Detection | Severity | Format |
|---|---|---|
| Potential Redis Lua Use-After-Free RCE Attempt (CVE-2025-49844 / RediShell) | Critical | Elastic TOML |
| Attempt to Install or Run Kali Linux via WSL | High | Elastic TOML |
| AWS Bedrock High Risk Filesystem or Execution Tool Invocation | High | Elastic TOML |
| AWS CloudShell Environment Created | High | Elastic TOML |
| AWS EC2 Stop, Start, and User Data Modification Correlation | High | Elastic TOML |
| AWS SageMaker Notebook Lifecycle Configuration With Suspicious Script Content | High | Elastic TOML |
| Base64 Decoded Payload Piped to Interpreter | High | Elastic TOML |
| Binary Executed from Shared Memory Directory | High | Elastic TOML |
| BPF filter applied using TC | High | Elastic TOML |
| Cassandra JavaScript UDF Creation | High | Elastic TOML |
+ 319 more from elastic/detection-rules → showing the 10 highest-severity
splunk/security_content
151 rules| Detection | Severity | Format |
|---|---|---|
| Cisco IOS XE Guestshell Activation and Destroy | Undefined | SPL |
| Cisco IOS XE Request Platform Package Describe Shell Pattern | Undefined | SPL |
| Cisco NVM - Installation of Typosquatted Python Package | Undefined | SPL |
| Cisco NVM - MSHTML or MSHTA Network Execution Without URL in CLI | Undefined | SPL |
| Cisco NVM - Suspicious File Download via Headless Browser | Undefined | SPL |
| Cisco NVM - Susp Script From Archive Triggering Network Activity | Undefined | SPL |
| Cisco Secure Firewall - Binary File Type Download | Undefined | SPL |
| Cisco Secure Firewall - Citrix NetScaler Memory Overread Attempt | Undefined | SPL |
| Cisco Secure Firewall - Communication Over Suspicious Ports | Undefined | SPL |
| Cisco Secure Firewall - High Volume of Intrusion Events Per Host | Undefined | SPL |
+ 141 more from splunk/security_content → showing the 10 highest-severity
socfortress/Wazuh-Rules
84 rules · 76 families| Detection | Severity | Format |
|---|---|---|
| Change of login shell to /bin/sh (T1059.004) | High | Wazuh XML |
| Detects BPFDoor .lock and .pid files access in temporary file storage facility. 2 variants | High | Wazuh XML |
| Detects BPFDoor .lock and .pid files access in temporary file storage facility. 2 variants | High | Wazuh XML |
| Detects relevant commands often related to malware or hacking activity. 2 variants | High | Wazuh XML |
| Detects relevant commands often related to malware or hacking activity. 2 variants | High | Wazuh XML |
| Execution of privilege escalation scripts (AutoSUID, LinEnum) - T1059.004 | High | Wazuh XML |
| Execution of remote script via pipe-to-shell method (T1059.004) | High | Wazuh XML |
| Obfuscated base64-encoded payload piped to shell (T1059.004) | High | Wazuh XML |
| Powershell script: C2/exploitation keyword detected | High | Wazuh XML |
| Powershell script: $doit variable detected (exploit scripts) | High | Wazuh XML |
+ 74 more from socfortress/Wazuh-Rules → showing the 10 highest-severity
chronicle/detection-rules
69 rules| Detection | Severity | Format |
|---|---|---|
| base64_encoded_powershell_command_detected | High | YARA-L |
| powershell_downloadfile | High | YARA-L |
| sap_execution_of_sensitive_abap_program | High | YARA-L |
| convertto_securestring_cmdlet_usage_via_commandline | Medium | YARA-L |
| hacktool_ironsharp_pack_execution | Medium | YARA-L |
| powershell_web_download | Medium | YARA-L |
| ttp_windows_w3wp_launching_encoded_powershell | Medium | YARA-L |
| abusing_managebdewsf | Undefined | YARA-L |
| abusing_security_support_provider_and_authentication_packages | Undefined | YARA-L |
| add_programs_to_firewall_exclusion_from_temp_directory_sysmon | Undefined | YARA-L |
+ 59 more from chronicle/detection-rules → showing the 10 highest-severity
Wazuh Core Ruleset
41 rules| Detection | Severity | Format |
|---|---|---|
| Office application started mshta.exe and executed scripting command | Critical | Wazuh XML |
| Possible Shimming. Application Compatibility Database launched from an encoded powershell command | Critical | Wazuh XML |
| Powershell script used "Invoke-command" cmdlet to execute code on remote computer | Critical | Wazuh XML |
| Powershell used to copy SAM hive from VSS | Critical | Wazuh XML |
| Suspicious execution of .js file by · win.eventdata.parentCommandLine = (?i)svchost.exe -k netsvcs -p, win.eventdata.commandLine = (?i)appdata\\\\.+\.exe.+\.js | Critical | Wazuh XML |
| A powershell process created by WMI executed a base64 encoded command | High | Wazuh XML |
| Binary loaded PowerShell automation library - Possible unmanaged Powershell execution by suspicious process | High | Wazuh XML |
| Detected a suspicious process launched with a jscript engine signature | High | Wazuh XML |
| Executed a renamed copy of wscript.exe | High | Wazuh XML |
| from same source ip. | High | Wazuh XML |
+ 31 more from Wazuh Core Ruleset → showing the 10 highest-severity
falcosecurity/rules
15 rules| Detection | Severity | Format |
|---|---|---|
| Reverse Shell from Web Server | Critical | Falco YAML |
| Container Drift Detected (chmod) | High | Falco YAML |
| Container Drift Detected (open+create) | High | Falco YAML |
| Execution from /dev/shm | Medium | Falco YAML |
| Netcat Remote Code Execution in Container | Medium | Falco YAML |
| Netcat/Socat Remote Code Execution on Host | Medium | Falco YAML |
| Web Server Spawned Suspicious Child Process | Medium | Falco YAML |
| Disallowed SSH Connection Non Standard Port | Low | Falco YAML |
| Launch Suspicious Network Tool in Container | Low | Falco YAML |
| Launch Suspicious Network Tool on Host | Low | Falco YAML |
+ 5 more from falcosecurity/rules → showing the 10 highest-severity
Azure/Azure-Sentinel
14 rules+ 4 more from Azure/Azure-Sentinel → showing the 10 highest-severity
Emerging Threats Open
13 rules · 10 families| Detection | Severity | Format |
|---|---|---|
| ET HUNTING Dotted Quad Host Base64-Encoded PHP payload | High | Suricata |
| ET HUNTING Dotted Quad Host Base64-Encoded Powershell Payload | High | Suricata |
| ET HUNTING Dotted Quad Host Suspected IoT Botnet Loader Shell Script | High | Suricata |
| ET HUNTING HTTP Response Containing Base64-Encoded and Compressed Powershell Payload Keywords | High | Suricata |
| ET HUNTING HTTP Response Containing Base64-Encoded Powershell Payload Keywords | High | Suricata |
| ET HUNTING schtasks create Command in HTTP Body Response | High | Suricata |
| ET MALWARE Commvault Pre-Auth RCE (CVE-2025-34028) Post-Exploitation Activity (jsp webshell) | High | Suricata |
| ET HUNTING Obfuscated PowerShell Script Download - Excessive CHAR | Informational | Suricata |
| ET HUNTING Obfuscated PowerShell Script Download - Excessive Split String M1 4 variants | Informational | Suricata |
| ET HUNTING Obfuscated PowerShell Script Download - Excessive Split String M2 4 variants | Informational | Suricata |
+ 3 more from Emerging Threats Open → showing the 10 highest-severity
panther-labs/panther-analysis
11 rules| Detection | Severity | Format |
|---|---|---|
| AWS EC2 Startup Script Change | High | Panther Python |
| AWS WAF Managed Known Bad Inputs Passthrough Rule | High | Panther Python |
| AWS WAF ReactJS RCE Attempt via Body | High | Panther Python |
| Crowdstrike Reverse Shell Tool Executed | High | Panther Python |
| StopInstance WITH ModifyInstanceAttributes | High | Panther Python |
| Teleport Suspicious Commands Executed | Medium | Panther Python |
| Upwind Runtime Detection Passthrough | Medium | Panther Python |
| User Logged in as root | Medium | Panther Python |
| Azure Automation Runbook Created or Modified | Informational | Panther Python |
| Azure Serverless Script Execution | Informational | Panther Python |
+ 1 more from panther-labs/panther-analysis → showing the 10 highest-severity
Bert-JanP/Hunting-Queries-Detection-Rules
7 rules| Detection | Severity | Format |
|---|---|---|
| AMSI Script Detection | Undefined | KQL |
| MITRE ATT&CK Mapping | Undefined | KQL |
| PowerShell Invoke-Webrequest | Undefined | KQL |
| Smoke Sandstorm - SnailResin and SlugResin Infection Detection | Undefined | KQL |
| Suspicious Browser Child Process | Undefined | KQL |
| Suspicious Explorer Child Process | Undefined | KQL |
| TTP Detection Rule: PowerShell Launching Scripts From WindowsApps Directory (FIN7) | Undefined | KQL |
chainguard-dev/osquery-defense-kit
3 rules| Detection | Severity | Format |
|---|---|---|
| Uncover reverse-shell processes | Undefined | osquery SQL |
| Unexpected process that spawns shell processes (event based) | Undefined | osquery SQL |
| Unexpected process that spawns shell processes (event-based) | Undefined | osquery SQL |