T1059.006 Python
Subtécnica de T1059 Command and Scripting Interpreter
Adversaries may abuse Python commands and scripts for execution. Python is a very popular scripting/programming language, with capabilities to perform many functions. Python can be executed interactively from the command-line (via the python.exe interpreter) or via scripts (.py) that can be written and distributed to different systems. Python code can also be compiled into binary…
Quién la usa · con noticias en Jábega
Reglas Sigma para cazarla
- Emotet Loader Execution Via .LNK Filehightest · windows
- Serpent Backdoor Payload Execution Via Scheduled Taskhightest · windows
- Axios NPM Compromise Indicators - Linuxhighexperimental · linux
- Python One-Liners with Base64 Decodinghighexperimental · windows
- Python One-Liners with Base64 Decoding - Linuxhighexperimental · linux
- TanStack Supply-Chain Attack Execution Indicators - Linuxhighexperimental · linux
- AppLocker Prevented Application or Script from Runningmediumtest · windows
- Potential CVE-2022-22954 Exploitation Attempt - VMware Workspace ONE Access Remote Code Executionmediumtest · windows
- Suspicious File Characteristics Due to Missing Fieldsmediumtest · windows
- AppLocker Application Would Have Been Blockedmediumexperimental · windows
Reglas de SigmaHQ · Detection Rule License 1.1. Técnica de MITRE ATT&CK®.