T1059
Command and Scripting Interpreter
Adversaries may abuse command and script interpreters to execute commands, scripts, or binaries. These interfaces include PowerShell, Bash, Python, and more.
ATT&CK / Execution
PowerShell is commonly used by ransomware groups like Ryuk to execute encoded commands, disable security tools, and move laterally.
Defense strategies
- Script block logging
- Constrained Language Mode for PowerShell
- Application whitelisting
- Disable unnecessary scripting engines
- Monitor script execution policies
Detection methods
- Enable enhanced PowerShell logging
- Monitor for encoded commands
- Track process creation with command lines
- Detect obfuscation patterns
D3FEND mappings
4