1200KM / simulation
T1059.004 Unix Shell — Attack Simulation
Adversaries may abuse Unix shell commands and scripts for execution. Unix shells are the primary command prompt on Linux, macOS, and ESXi systems, though many variations of the Unix shell exist (e.g. sh, ash, bash, zsh, etc.) depending on the specific OS or distribution. Unix shells can control every aspect of a system, with certain commands requiring elevated privileges. Unix shells also support scripts that enable sequential execution of…
Technique description
Adversaries may abuse Unix shell commands and scripts for execution. Unix shells are the primary command prompt on Linux, macOS, and ESXi systems, though many variations of the Unix shell exist (e.g. sh, ash, bash, zsh, etc.) depending on the specific OS or distribution. Unix shells can control every aspect of a system, with certain commands requiring elevated privileges. Unix shells also support scripts that enable sequential execution of…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- Current kernel information enumeration
Procedure 3a53734a-9e26-4f4b-ad15-059e767f5f14; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Harvest SUID executable files
Procedure 46274fc6-08a7-4956-861b-24cbbaa0503c; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Obfuscated command line scripts
Procedure 5bec4cc8-f41e-437b-b417-33ff60acf9af; elevation not declared required; cleanup not declared. Not executed or individually validated.
- What shell is running
Procedure 7b38e5cc-47be-44f0-a425-390305c76c17; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Create and Execute Bash Shell Script
Procedure 7e7ac3ed-f795-4fa5-b711-09d6fbe9b873; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- New script file in the tmp directory
Procedure 8cd1947b-4a54-41fb-b5ea-07d0ace04f81; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- LinEnum tool execution
Procedure a2b35a63-9df1-4806-9a4d-5fe0500845f2; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Shell Creation using busybox command
Procedure ab4d04af-68dc-4fee-9c16-6545265b3276; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Command line scripts
Procedure b04ed73c-7d43-4dc8-b563-a2fc595cba1a; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Creating shell using cpan command
Procedure bcd4c2bc-490b-4f91-bd31-3709fe75bbdf; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Environment variable scripts
Procedure bdaebd56-368b-4970-a523-f905ff4a8a51; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- What shells are available
Procedure bf23c7dc-1004-4949-8262-4c1d1ef87702; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Change login shell
Procedure c7ac59cb-13cc-4622-81dc-6d2fee9bfac7; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Command-Line Interface
Procedure d0c88567-803d-4dca-99b4-7ce65e7b257c; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- emacs spawning an interactive system shell
Procedure e0742e38-6efe-4dd4-ba5c-2078095b6156; elevation required; cleanup not declared. Not executed or individually validated.
- Shell Creation using awk command
Procedure ee72b37d-b8f5-46a5-a9e7-0ff50035ffd5; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Detecting pipe-to-shell
Procedure fca246a8-a585-4f28-a2df-6495973976a1; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
No reviewed association in this snapshot.
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.