Command and Scripting Interpreter T1059

Tactic: Execution

Adversaries may abuse command and script interpreters to execute commands, scripts, or binaries. These interfaces and languages provide ways of interacting with computer systems and are a common feature across many different platforms. Most systems come with some built-in command-line interface and scripting capabilities, for example, macOS and Linux distributions include some flavor of Unix Shell while Windows installations include the Windows Command Shell and PowerShell.

Events covered

102 catalog events are tagged with this technique by at least one rule.

ProviderEventTitle
SysmonEvent ID 1Process creation
SysmonEvent ID 3Network connection
SysmonEvent ID 5Process terminated
SysmonEvent ID 7Image loaded
SysmonEvent ID 8CreateRemoteThread
SysmonEvent ID 10ProcessAccess
SysmonEvent ID 11FileCreate
SysmonEvent ID 12RegistryEvent (Object create and delete)
SysmonEvent ID 13RegistryEvent (Value Set)
SysmonEvent ID 14RegistryEvent (Key and Value Rename)
SysmonEvent ID 17PipeEvent (Pipe Created)
SysmonEvent ID 18PipeEvent (Pipe Connected)
SysmonEvent ID 19WmiEvent (WmiEventFilter activity detected)
SysmonEvent ID 20WmiEvent (WmiEventConsumer activity detected)
SysmonEvent ID 21WmiEvent (WmiEventConsumerToFilter activity detected)
SysmonEvent ID 22DNSEvent (DNS query)
SysmonEvent ID 23FileDelete (File Delete archived)
SysmonEvent ID 26FileDeleteDetected (File Delete logged)
Security-AuditingEvent ID 4624An account was successfully logged on.
Security-AuditingEvent ID 4625An account failed to log on.
Security-AuditingEvent ID 4656A handle to an object was requested.
Security-AuditingEvent ID 4657A registry value was modified.
Security-AuditingEvent ID 4663An attempt was made to access an object.
Security-AuditingEvent ID 4688A new process has been created.
Security-AuditingEvent ID 4689A process has exited.
Security-AuditingEvent ID 4697A service was installed in the system.
Security-AuditingEvent ID 4698A scheduled task was created.
Security-AuditingEvent ID 4776The domain controller attempted to validate the credentials for an account.
Security-AuditingEvent ID 4799A security-enabled local group membership was enumerated.
Security-AuditingEvent ID 5140A network share object was accessed.
Security-AuditingEvent ID 5145A network share object was checked to see whether client can be granted desired access.
Security-AuditingEvent ID 5152The Windows Filtering Platform blocked a packet.
Security-AuditingEvent ID 5154The Windows Filtering Platform has permitted an application or service to listen on a port for incoming connections.
Security-AuditingEvent ID 5155The Windows Filtering Platform has blocked an application or service from listening on a port for incoming connections.
Security-AuditingEvent ID 5156The Windows Filtering Platform has permitted a connection.
Security-AuditingEvent ID 5157The Windows Filtering Platform has blocked a connection.
Security-AuditingEvent ID 5158The Windows Filtering Platform has permitted a bind to a local port.
Security-AuditingEvent ID 5159The Windows Filtering Platform has blocked a bind to a local port.
Defender-AlertEvidenceanyAlert evidence
Defender-AlertInfoanyAlert information
Defender-DeviceEventsanyDefender event
Defender-DeviceEventsPowerShellCommandPowerShell command executed
Defender-DeviceEventsAmsiScriptContentAMSI script content captured
Defender-DeviceEventsClrUnbackedModuleLoadedCLR unbacked module loaded
Defender-DeviceEventsExploitGuardNonMicrosoftSignedBlockedExploit Guard non-Microsoft signed image (blocked)
Defender-DeviceFileEventsanyFile activity
Defender-DeviceImageLoadEventsanyImage load
Defender-DeviceImageLoadEventsImageLoadedImage loaded
Defender-DeviceLogonEventsanyLogon activity
Defender-DeviceNetworkEventsConnectionSuccessConnection succeeded
Defender-DeviceProcessEventsanyProcess activity
ESFexecProcess Execution
ESFforkProcess Fork
ESFsignalSignal Delivery
ESFopenFile Open
ESFcreateFile or Directory Create
ESFrenameFile Rename
ESFunlinkFile Unlink
ESFwriteFile Write
Linux-AuditdEvent ID 1101USER_ACCT
Linux-AuditdEvent ID 1103CRED_ACQ
Linux-AuditdEvent ID 1105USER_START
Linux-AuditdEvent ID 1106USER_END
Linux-AuditdEvent ID 1123USER_CMD
Linux-AuditdEvent ID 1300SYSCALL
Linux-AuditdEvent ID 1302PATH
Linux-AuditdEvent ID 1307CWD
Linux-AuditdEvent ID 1309EXECVE
Linux-AuditdEvent ID 1327PROCTITLE
MSSQLSERVEREvent ID 8128Event ID 8128
AppLockerEvent ID 8003RuleAndFileData.FilePath was allowed to run but would have been prevented from running if the AppLocker policy were enforced.
AppLockerEvent ID 8004FilePathBuffer was prevented from running.
AppLockerEvent ID 8006FilePathBuffer was allowed to run but would have been prevented from running if the AppLocker policy were enforced.
AppLockerEvent ID 8007FilePathBuffer was prevented from running.
AppLockerEvent ID 8021PackageBuffer was allowed to run but would have been prevented from running if the AppLocker policy were enforced.
AppLockerEvent ID 8022PackageBuffer was prevented from running.
AppLockerEvent ID 8024PackageBuffer was allowed to run but would have been prevented from running if the AppLocker policy were enforced.
AppLockerEvent ID 8025PackageBuffer was prevented from running.
PowerShellEvent ID 4103Payload Context: ContextInfo User Data: UserData.
PowerShellEvent ID 4104Creating Scriptblock text (MessageNumber of MessageTotal).
Windows-DefenderEvent ID 1006ProductName has detected malware or other potentially unwanted software.
Windows-DefenderEvent ID 1015ProductName has detected a suspicious behavior.
Windows-DefenderEvent ID 1116Product Name has detected malware or other potentially unwanted software.
Windows-DefenderEvent ID 1117Product Name has taken action to protect this machine from malware or other potentially unwanted software.
Windows-DefenderEvent ID 1121Microsoft Defender Exploit Guard has blocked an operation that is not allowed by your IT administrator.
Windows-DefenderEvent ID 1122Microsoft Defender Exploit Guard audited an operation that is not allowed by your IT administrator.
Windows-DefenderEvent ID 1125Your IT administrator would have caused Microsoft Defender Exploit Guard to block a potentially dangerous network connection.
Windows-DefenderEvent ID 1126Your IT administrator has caused Microsoft Defender Exploit Guard to block a potentially dangerous network connection.
Windows-DefenderEvent ID 1129A user has allowed a blocked Microsoft Defender Exploit Guard operation.
Windows-DefenderEvent ID 1131ProductName has blocked an operation that your administrator doesn't allow.
Windows-DefenderEvent ID 1132ProductName has audited an operation.
Windows-DefenderEvent ID 1133ProductName has blocked an operation that your administrator doesn't allow.
Windows-DefenderEvent ID 1134ProductName has audited an operation.
Windows-DefenderEvent ID 5007Product Name Configuration has changed.
PowerShellEvent ID 400Event ID 400
PowerShellEvent ID 800Event ID 800
ScreenConnectEvent ID 200Executed command of length.
ScreenConnectEvent ID 201Transferred files with action 'Transfer'.
Service-Control-ManagerEvent ID 7045A service was installed in the system.
Sysmon-for-LinuxEvent ID 1Process Create
Sysmon-for-LinuxEvent ID 3Network connection
Sysmon-for-LinuxEvent ID 11File created

Authoring guide

These 1506 rules share fields, values, and exclusions.

Fields filtered most (418 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
process_name579eq 331, in 210, starts_with 78, wildcard 58, regex_match 27, ends_with 5, contains 3, cross_field_compare 2, is_not_null 2, ne 1bash, csh, powershell.exe, dash, cmd.exe
CommandLine522contains 337, regex_match 102, wildcard 82, match 28, is_not_null 17, ends_with 16, in 16, eq 10, is_null 8, length_compare 8, starts_with 5 -e , event0.file.name, .js, list, /bin/bash
EventType502eq 417, in 93, ne 17, starts_with 4exec, start, connection_attempted, exec_event, ProcessRollup2
event.type446eq 431, in 15, ne 1start, creation, change, process_started, deletion
Image330ends_with 201, starts_with 58, wildcard 36, contains 24, eq 17, is_not_null 12, in 5, regex_match 5, is_null 2, ne 1\powershell.exe, \cmd.exe, \pwsh.exe, /dev/shm/, \cscript.exe
parent_process_name296eq 181, in 67, starts_with 35, regex_match 27, wildcard 23, ends_with 5, contains 3, is_not_null 2bash, explorer.exe, csh, node, powershell.exe
process.args295eq 178, in 78, wildcard 77, starts_with 64, contains 36, ends_with 13, regex_match 4, is_not_null 1, match 1-c, -e, -cl, -i, -base64
host.os.type222eq 215, in 8
EventID202eq 198, in 44104, 4688, 1, 4103, 7
OriginalFileName166eq 150, in 16, wildcard 3, contains 2powershell.exe, pwsh.dll, cmd.exe, powershell_ise.exe, cscript.exe
ParentImage160ends_with 72, is_not_null 29, starts_with 24, eq 19, contains 14, wildcard 13, in 2, is_null 1, regex_match 1/dev/shm/, /boot/, \powershell.exe, ./, \cmd.exe
ScriptBlockText132contains 76, in 45, eq 24, regex_match 10, match 6, ends_with 3adjusttokenprivileges, frombase64string, new-object, &&, (new-object...
process.args_count98eq 56, ge 26, le 17, gt 42, 3, 1, 4, 5
TargetFilename82starts_with 31, contains 18, wildcard 18, ends_with 17, eq 7, regex_match 4, in 3/tmp/, /private/tmp/, /dev/shm/, /private/var/tmp/, ?:\users\
ParentCommandLine77contains 53, wildcard 10, regex_match 7, eq 6, ends_with 5, is_not_null 5, in 2, length_compare 2, starts_with 1app.py, asgi.py, django, *--port*, */app/*.js*

Top indicator values (12798 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
event.typeeq
start
4161078
EventTypeeq
exec
271576
EventTypeeq
start
96391
EventTypeeq
connection_attempted
4273
process_namein
bash
126202
process_namein
sh
125197
process_namein
zsh
124196
process_namein
dash
108170
process_namein
csh
103159
process_namein
ksh
103163
process_namein
fish
102163
process_namein
tcsh
102156
process_nameeq
powershell.exe
103184
process_nameeq
cmd.exe
67121
process_nameeq
pwsh.exe
5177
process_nameeq
wscript.exe
4783
EventIDeq
4104
76269
EventIDeq
4688
59317
EventIDeq
1
43241
process.argseq
-c
74107
event.categoryeq
process
68142
EventTypein
exec
67201
EventTypein
start
51163
Imageends_with
\powershell.exe
62179
Imageends_with
\pwsh.exe
55165
Imageends_with
\cmd.exe
40130
OriginalFileNameeq
powershell.exe
57138
OriginalFileNameeq
pwsh.dll
43112
process_namestarts_with
python
4771
process_namewildcard
python*
4569

Exclusions (6183 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
dest_ipcidr_match
127.0.0.0/8
57
dest_ipcidr_match
169.254.0.0/16
56
dest_ipcidr_match
224.0.0.0/4
55
dest_ipcidr_match
::1
55
dest_ipcidr_match
10.0.0.0/8
49
dest_ipcidr_match
172.16.0.0/12
49
dest_ipcidr_match
192.0.0.0/24
48
dest_ipcidr_match
192.0.2.0/24
48
dest_ipcidr_match
192.88.99.0/24
48
dest_ipcidr_match
240.0.0.0/4
48
dest_ipcidr_match
FE80::/10
48
dest_ipcidr_match
FF00::/8
48
dest_ipcidr_match
100.64.0.0/10
47
dest_ipcidr_match
192.175.48.0/24
47
dest_ipcidr_match
192.31.196.0/24
47

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Sigma 432 rules

Elastic 689 rules

Splunk 298 rules

Kusto 68 rules

YARA-L 7 rules

Panther 12 rules