1200KM / simulation
T1059.006 Python — Attack Simulation
Adversaries may abuse Python commands and scripts for execution. Python is a very popular scripting/programming language, with capabilities to perform many functions. Python can be executed interactively from the command-line (via the python.exe interpreter) or via scripts (.py) that can be written and distributed to different systems. Python code can also be compiled into binary executables. Python comes with many built-in packages to interact…
Technique description
Adversaries may abuse Python commands and scripts for execution. Python is a very popular scripting/programming language, with capabilities to perform many functions. Python can be executed interactively from the command-line (via the python.exe interpreter) or via scripts (.py) that can be written and distributed to different systems. Python code can also be compiled into binary executables. Python comes with many built-in packages to interact…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- Execute Python via Python executables
Procedure 0b44d79b-570a-4b27-a31f-3bf2156e5eaa; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Python pty module and spawn function used to spawn sh or bash
Procedure 161d694c-b543-4434-85c3-c3a433e33792; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Execute shell script via python's command mode arguement
Procedure 3a95cdb2-c6ea-4761-b24e-02b71889b8bb; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Execute Python via scripts
Procedure 6c4d1dcb-33c7-4c36-a8df-c6cfd0408be8; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
- Turla · G0010
- APT29 · G0016
- Dragonfly · G0035
- BRONZE BUTLER · G0060
- APT37 · G0067
- MuddyWater · G0069
- APT39 · G0087
- Kimsuky · G0094
- Machete · G0095
- Rocke · G0106
- ZIRCONIUM · G0128
- Tonto Team · G0131
- Earth Lusca · G1006
- Cinnamon Tempest · G1021
- RedCurl · G1039
- UNC3886 · G1048
- Contagious Interview · G1052
- VOID MANTICORE · G1055
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.