T1059

Command and Scripting Interpreter

Adversaries may abuse command and script interpreters to execute commands, scripts, or binaries. These interfaces include PowerShell, Bash, Python, and more.

ATT&CK / Execution

PowerShell is commonly used by ransomware groups like Ryuk to execute encoded commands, disable security tools, and move laterally.

Defense strategies

  • Script block logging
  • Constrained Language Mode for PowerShell
  • Application whitelisting
  • Disable unnecessary scripting engines
  • Monitor script execution policies

Detection methods

  • Enable enhanced PowerShell logging
  • Monitor for encoded commands
  • Track process creation with command lines
  • Detect obfuscation patterns

T1059 on MITRE ATT&CK ↗