T1059.003 Windows Command Shell
Subtécnica de T1059 Command and Scripting Interpreter
Adversaries may abuse the Windows command shell for execution. The Windows command shell ([cmd](https://attack.mitre.org/software/S0106)) is the primary command prompt on Windows systems. The Windows command prompt can be used to control almost any aspect of a system, with various permission levels required for different subsets of commands. The command prompt can be invoked remotely via [Remote…
Quién la usa · con noticias en Jábega
Reglas Sigma para cazarla
- Elise Backdoor Activitycriticaltest · windows
- Rorschach Ransomware Execution Activitycriticaltest · windows
- ZxShell Malwarecriticaltest · windows
- HackTool - CrackMapExec Execution Patternshighstable · windows
- AWS EC2 Startup Shell Script Changehightest · aws
- Conhost.exe CommandLine Path Traversalhightest · windows
- Exploited CVE-2020-10189 Zoho ManageEnginehightest · windows
- Exploiting SetupComplete.cmd CVE-2019-1378hightest · windows
- HTML Help HH.EXE Suspicious Child Processhightest · windows
- HackTool - CrackMapExec Executionhightest · windows
- HackTool - Koadic Executionhightest · windows
- HackTool - RedMimicry Winnti Playbook Executionhightest · windows
- Operator Bloopers Cobalt Strike Commandshightest · windows
- Operator Bloopers Cobalt Strike Moduleshightest · windows
- Potential Baby Shark Malware Activityhightest · windows
- Potential CommandLine Path Traversal Via Cmd.EXEhightest · windows
- Sofacy Trojan Loader Activityhightest · windows
- Suspicious HH.EXE Executionhightest · windows
- Suspicious HWP Sub Processeshightest · windows
- Axios NPM Compromise Indicators - Windowshighexperimental · windows
- DNS Query by Finger Utilityhighexperimental · windows
- Network Connection Initiated via Finger.EXEhighexperimental · windows
- Potential Exploitation of CrushFTP RCE Vulnerability (CVE-2025-54309)highexperimental · windows
- Suspicious Process Spawned by CentreStack Portal AppPoolhighexperimental · windows
- AppLocker Prevented Application or Script from Runningmediumtest · windows
Mostrando 25 de 40.
Reglas de SigmaHQ · Detection Rule License 1.1. Técnica de MITRE ATT&CK®.