1200KM / detection
T1059.003 Windows Command Shell — Detection Rules
Detection workspace for T1059.003 Windows Command Shell: 27 Sigma sources, 1 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- AWS EC2 Startup Shell Script Change · test · high · {"product":"aws","service":"cloudtrail"}
- Remote Access Tool - ScreenConnect Command Execution · test · low · {"service":"application","product":"windows"}
- Remote Access Tool - ScreenConnect File Transfer · test · low · {"service":"application","product":"windows"}
- AppLocker Prevented Application or Script from Running · test · medium · {"product":"windows","service":"applocker"}
- DNS Query by Finger Utility · experimental · high · {"product":"windows","category":"dns_query"}
- Remote Access Tool - ScreenConnect Temporary File · test · low · {"category":"file_event","product":"windows"}
- Network Connection Initiated via Finger.EXE · experimental · high · {"category":"network_connection","product":"windows"}
- Powershell Execute Batch Script · test · medium · {"product":"windows","category":"ps_script","definition":"Requirements: Script Block Logging must be enabled"}
- Command Line Execution with Suspicious URL and AppData Strings · test · medium · {"category":"process_creation","product":"windows"}
- Potential CommandLine Path Traversal Via Cmd.EXE · test · high · {"category":"process_creation","product":"windows"}
- Read Contents From Stdin Via Cmd.EXE · test · medium · {"category":"process_creation","product":"windows"}
- OpenEDR Spawning Command Shell · experimental · medium · {"product":"windows","category":"process_creation"}
- Powershell Executed From Headless ConHost Process · test · medium · {"category":"process_creation","product":"windows"}
- Conhost.exe CommandLine Path Traversal · test · high · {"category":"process_creation","product":"windows"}
- HTML Help HH.EXE Suspicious Child Process · test · high · {"category":"process_creation","product":"windows"}
- Suspicious HH.EXE Execution · test · high · {"category":"process_creation","product":"windows"}
- Operator Bloopers Cobalt Strike Commands · test · high · {"category":"process_creation","product":"windows"}
- Operator Bloopers Cobalt Strike Modules · test · high · {"category":"process_creation","product":"windows"}
- HackTool - CrackMapExec Execution · test · high · {"category":"process_creation","product":"windows"}
- HackTool - CrackMapExec Execution Patterns · stable · high · {"category":"process_creation","product":"windows"}
- HackTool - Jlaive In-Memory Assembly Execution · test · medium · {"product":"windows","category":"process_creation"}
- HackTool - Koadic Execution · test · high · {"category":"process_creation","product":"windows"}
- HackTool - RedMimicry Winnti Playbook Execution · test · high · {"product":"windows","category":"process_creation"}
- Suspicious HWP Sub Processes · test · high · {"category":"process_creation","product":"windows"}
- PUA - AdvancedRun Execution · test · medium · {"product":"windows","category":"process_creation"}
- Remote Access Tool - ScreenConnect Remote Command Execution · test · low · {"category":"process_creation","product":"windows"}
- Suspicious Usage of For Loop with Recursive Directory Search in CMD · experimental · medium · {"category":"process_creation","product":"windows"}
Atlas deterministic concepts
T1059.003 Windows Command Shell
MATCH(process_name IN [cmd.exe, command.com]) AND command_line MATCHES suspicious_command_patterns -> ALERTAnomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0202 Behavioral Detection of Windows Command Shell Execution
AN0578 Analytic 0578
Detects interactive or scripted abuse of cmd.exe, batch files, or shell invocation chains. Focuses on parent-child relationships (e.g., cmd.exe launched from unusual parents), anomalous command-line parameters, and chaining with discovery, credential access, or lateral movement behaviors.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
- Ke3chang · G0004
- APT1 · G0006
- APT28 · G0007
- Turla · G0010
- Darkhotel · G0012
- admin@338 · G0018
- APT3 · G0022
- APT18 · G0026
- Threat Group-3390 · G0027
- Threat Group-1314 · G0028
- Lazarus Group · G0032
- Dragonfly · G0035
- FIN6 · G0037
- Suckfly · G0039
- Patchwork · G0040
- menuPass · G0045
- FIN7 · G0046
- Gamaredon Group · G0047
- OilRig · G0049
- APT32 · G0050
- FIN10 · G0051
- Sowbug · G0054
- Magic Hound · G0059
- BRONZE BUTLER · G0060
- FIN8 · G0061
- APT37 · G0067
- MuddyWater · G0069
- Dark Caracal · G0070
- Rancor · G0075
- Gorgon Group · G0078
- Cobalt Group · G0080
- Tropic Trooper · G0081
- APT38 · G0082
- WIRTE · G0090
- Silence · G0091
- TA505 · G0092
- GALLIUM · G0093
- Kimsuky · G0094
- Machete · G0095
- APT41 · G0096
- Wizard Spider · G0102
- Blue Mockingbird · G0108
- Chimera · G0114
- Fox Kitten · G0117
- Indrik Spider · G0119
- HAFNIUM · G0125
- Higaisa · G0126
- TA551 · G0127
- ZIRCONIUM · G0128
- Mustang Panda · G0129
- Nomadic Octopus · G0133
- TeamTNT · G0139
- LazyScripter · G0140
- Aquatic Panda · G0143
- Metador · G1013
- FIN13 · G1016
- Volt Typhoon · G1017
- Cinnamon Tempest · G1021
- ToddyCat · G1022
- APT5 · G1023
- Agrius · G1030
- Saint Bear · G1031
- INC Ransom · G1032
- Winter Vivern · G1035
- TA577 · G1037
- RedCurl · G1039
- Play · G1040
- BlackByte · G1043
- Storm-1811 · G1046
- UNC3886 · G1048
- Medusa Group · G1051
- Contagious Interview · G1052
- MirrorFace · G1054
Existing anomaly research
Connected anomaly research
Curated research views reached through an exact source technique, a catalog model, or a reviewed collection reference. These are navigation associations, not claims of detector effectiveness or sensor equivalence.
Telemetry contracts · Maintained query examples · Validation and blind spots
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.