Skip to content
← LibraryTechnique entry
T1059Execution

Command and Scripting Interpreter

Abuse shells/interpreters (PowerShell, bash, Python).

§ Where this technique fits

T1059 is catalogued under the Execution tactic of the offensive-security kill-chain. It appears in 42 approved dossiers in the registry, typically at step 4.1 on average.

Authoritative reference: attack.mitre.org/techniques/T1059/.

§ Dossiers chaining this technique

§ What commonly comes next

  1. 01
    LSASS via procdump / comsvcs.dll
    W-LSASS-PROCDUMP · Credential Access
    seen 4×
  2. 02
    Unsecured Credentials
    T1552 · Credential Access
    seen 3×
  3. 03
    Valid Accounts
    T1078 · Initial Access
    seen 3×
  4. 04
    LSASS Memory
    T1003.001 · Credential Access
    seen 2×
  5. 05
    Scheduled Task Hijack
    W-SCHEDTASK-HIJACK · Persistence
    seen 2×
  6. 06
    AlwaysInstallElevated
    W-ALWAYS-ELEVATE · Privilege Escalation
    seen 1×
  7. 07
    Application Layer Protocol
    T1071 · Command and Control
    seen 1×
  8. 08
    Brute Force
    T1110 · Credential Access
    seen 1×