1200KM / simulation
T1059.003 Windows Command Shell — Attack Simulation
Adversaries may abuse the Windows command shell for execution. The Windows command shell (cmd) is the primary command prompt on Windows systems. The Windows command prompt can be used to control almost any aspect of a system, with various permission levels required for different subsets of commands. The command prompt can be invoked remotely via Remote Services such as SSH. Batch files (ex: .bat or .cmd) also provide the shell with a list of…
Technique description
Adversaries may abuse the Windows command shell for execution. The Windows command shell (cmd) is the primary command prompt on Windows systems. The Windows command prompt can be used to control almost any aspect of a system, with various permission levels required for different subsets of commands. The command prompt can be invoked remotely via Remote Services such as SSH. Batch files (ex: .bat or .cmd) also provide the shell with a list of…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- Command prompt writing script to file then executes it
Procedure 00682c9f-7df4-4df8-950b-6dcaaa3ad9af; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Writes text to a file and displays it.
Procedure 127b4afe-2346-4192-815c-69042bec570e; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Simulate BlackByte Ransomware Print Bombing
Procedure 6b2903ac-8f36-450d-9ad5-b220e8a2dcb9; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Create and Execute Batch Script
Procedure 9e8894c0-50bd-4525-a96c-d4ac78ece388; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Suspicious Execution via Windows Command Shell
Procedure d0eb3597-a1b3-4d65-b33b-2cda8d397f20; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Command Prompt read contents from CMD file and execute
Procedure df81db1b-066c-4802-9bc8-b6d030c3ba8e; elevation not declared required; cleanup not declared. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
- Ke3chang · G0004
- APT1 · G0006
- APT28 · G0007
- Turla · G0010
- Darkhotel · G0012
- admin@338 · G0018
- APT3 · G0022
- APT18 · G0026
- Threat Group-3390 · G0027
- Threat Group-1314 · G0028
- Lazarus Group · G0032
- Dragonfly · G0035
- FIN6 · G0037
- Suckfly · G0039
- Patchwork · G0040
- menuPass · G0045
- FIN7 · G0046
- Gamaredon Group · G0047
- OilRig · G0049
- APT32 · G0050
- FIN10 · G0051
- Sowbug · G0054
- Magic Hound · G0059
- BRONZE BUTLER · G0060
- FIN8 · G0061
- APT37 · G0067
- MuddyWater · G0069
- Dark Caracal · G0070
- Rancor · G0075
- Gorgon Group · G0078
- Cobalt Group · G0080
- Tropic Trooper · G0081
- APT38 · G0082
- WIRTE · G0090
- Silence · G0091
- TA505 · G0092
- GALLIUM · G0093
- Kimsuky · G0094
- Machete · G0095
- APT41 · G0096
- Wizard Spider · G0102
- Blue Mockingbird · G0108
- Chimera · G0114
- Fox Kitten · G0117
- Indrik Spider · G0119
- HAFNIUM · G0125
- Higaisa · G0126
- TA551 · G0127
- ZIRCONIUM · G0128
- Mustang Panda · G0129
- Nomadic Octopus · G0133
- TeamTNT · G0139
- LazyScripter · G0140
- Aquatic Panda · G0143
- Metador · G1013
- FIN13 · G1016
- Volt Typhoon · G1017
- Cinnamon Tempest · G1021
- ToddyCat · G1022
- APT5 · G1023
- Agrius · G1030
- Saint Bear · G1031
- INC Ransom · G1032
- Winter Vivern · G1035
- TA577 · G1037
- RedCurl · G1039
- Play · G1040
- BlackByte · G1043
- Storm-1811 · G1046
- UNC3886 · G1048
- Medusa Group · G1051
- Contagious Interview · G1052
- MirrorFace · G1054
Existing research
Connected anomaly research
Curated research views reached through an exact source technique, a catalog model, or a reviewed collection reference. These are navigation associations, not claims of detector effectiveness or sensor equivalence.
Telemetry contracts · Maintained query examples · Validation and blind spots
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.