MITRE ATT&CK sub-technique
T1059.003 — Windows Command Shell
Last fetched
T1059.003 (Windows Command Shell) is a MITRE ATT&CK sub-technique tracked in WhisperGraph, serving the Execution tactic.
Description
Adversaries may abuse the Windows command shell for execution. The Windows command shell ([cmd](https://attack.mitre.org/software/S0106)) is the primary command prompt on Windows systems. The Windows command prompt can be used to control almost any aspect of a system, with various permission levels required for different subsets of commands. The command prompt can be invoked remotely via [Remote Services](https://attack.mitre.org/techniques/T1021) such as [SSH](https://attack.mitre.org/techniques/T1021/004).(Citation: SSH in Windows) Batch files (ex: .bat or .cmd) also provide the shell with a list of sequential commands to run, as well as normal scripting operations such as conditionals and loops. Common uses of batch files include long or repetitive tasks, or the need to run the same set of commands on multiple systems. Adversaries may leverage [cmd](https://attack.mitre.org/software/S0106) to execute various commands and payloads. Common uses include [cmd](https://attack.mitre.org/software/S0106) to execute a single command, or abusing [cmd](https://attack.mitre.org/software/S0106) interactively with input and output forwarded over a command and control channel.
Tactics
Related techniques
Parent technique: T1059 · Command and Scripting Interpreter
Threat actors observed using this technique
- Blue Mockingbird
- Dragonfly
- Agrius
- INC Ransom
- Volt Typhoon
- Mustang Panda
- ToddyCat
- Play
- Indrik Spider
- TA505
- Contagious Interview
- Higaisa
- Threat Group-1314
- Sowbug
- Cobalt Group
- APT5
- APT3
- UNC3886
- APT1
- Threat Group-3390
- Nomadic Octopus
- Suckfly
- Gamaredon Group
- BRONZE BUTLER
- MirrorFace
- Ke3chang
- Fox Kitten
- Medusa Group
- menuPass
- FIN13
- FIN10
- BlackByte
- Metador
- ZIRCONIUM
- Wizard Spider
- Storm-1811
- LazyScripter
- Rancor
- APT41
- Silence
- Turla
- MuddyWater
- WIRTE
- APT38
- APT37
- TA577
- APT32
- Magic Hound
- Aquatic Panda
- APT28
- GALLIUM
- Cinnamon Tempest
- Kimsuky
- OilRig
- TeamTNT
- Gorgon Group
- Tropic Trooper
- FIN6
- FIN7
- FIN8
- APT18
- admin@338
- TA551
- Darkhotel
- Winter Vivern
- Patchwork
- Dark Caracal
- Saint Bear
- Chimera
- HAFNIUM
- Machete
- RedCurl
- Lazarus Group
- WIZARD SPIDER
- MUSTANG PANDA
© The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.
Related pages
Pivot from T1059.003 into its tactic, related techniques and the actors that use it.
Queries
Resolves the segment to this technique or tactic.
MATCH (t:ATTACK_PATTERN {name: $id})
RETURN t.id AS id, t.name AS name, t.kind AS kind, t.description AS descriptionRun yourself →The tactic(s) this technique serves.
MATCH (t:ATTACK_PATTERN {name: $id})-[:USES_TACTIC]->(tac:ATTACK_PATTERN)
RETURN tac.id AS id, tac.name AS name
LIMIT 10Run yourself →This id's parent technique, if it is a sub-technique.
MATCH (p:ATTACK_PATTERN {name: $parentId})
RETURN p.id AS id, p.name AS name
LIMIT 1Run yourself →Sub-techniques of this technique, if any.
MATCH (c:ATTACK_PATTERN) WHERE c.id STARTS WITH $subPrefix
RETURN c.id AS id, c.name AS name
ORDER BY c.id
LIMIT 25Run yourself →Threat actors observed using this technique.
MATCH (a:ACTOR)-[:USES_TECHNIQUE]->(t:ATTACK_PATTERN {name: $id})
RETURN a.name AS name
LIMIT 100Run yourself →Or query Whisper from your own LLM workflow via the Whisper MCP server.