1200KM / tool
cmd — Attack Tool
cmd is the Windows command-line interpreter that can be used to interact with systems and execute other processes and utilities. Cmd.exe contains native functionality to perform many operations to interact with the system, including listing files in a directory (e.g., dir ), deleting files (e.g., del ), and copying files (e.g., copy ).
Tool identity and evidence
Included because the active pinned ATT&CK object has type tool. This is an upstream classification, not an assurance of benignness or a recommendation to run it.
Aliases: cmd, cmd.exe
Existing author guides
No reviewed association in this snapshot.
Primary documentation
No reviewed association in this snapshot.
Connected ecosystem references
Linked tags
Documented actor use
Explicit actor-to-software uses relationships in the pinned ATT&CK source. These links are historical behavior context, not attribution of current events.
- APT18 · G0026 · Pinned relationship source (relationship--89c6bcd7-e330-4902-8296-0918923d6573)
- menuPass · G0045 · Pinned relationship source (relationship--99800503-d535-4fae-a318-dfa034dca663)
- BRONZE BUTLER · G0060 · Pinned relationship source (relationship--42897880-fe55-4f54-a42c-f85ba19fb39a)
- Orangeworm · G0071 · Pinned relationship source (relationship--a8f41a5a-b6bd-4446-8f9d-22d0e7b4af74)
- GALLIUM · G0093 · Pinned relationship source (relationship--0a20969e-c201-47cd-ac08-8e1a9c764512)
- Volt Typhoon · G1017 · Pinned relationship source (relationship--e8695cbf-80d1-4302-8b79-9667ba171735)
Technique-specific simulations and detections
Detection links describe the associated behavior, not independently verified tool-specific signatures.
- T1059.003 · Windows Command Shell · Detection rules & anomalies
- T1070.004 · File Deletion · Detection rules & anomalies
- T1082 · System Information Discovery · Detection rules & anomalies
- T1083 · File and Directory Discovery · Detection rules & anomalies
- T1105 · Ingress Tool Transfer · Detection rules & anomalies
- T1570 · Lateral Tool Transfer · Detection rules & anomalies
Telemetry context
Derived from the explicitly linked TTPs; not proof of sensor coverage for this tool.
- Command Execution · DC0064
- File Access · DC0055
- File Creation · DC0039
- File Deletion · DC0040
- File Metadata · DC0059
- File Modification · DC0061
- Instance Enumeration · DC0075
- Module Load · DC0016
- Network Connection Creation · DC0082
- Network Share Access · DC0102
- Network Traffic Flow · DC0078
- Process Creation · DC0032
- Script Execution · DC0029
- Windows Registry Key Modification · DC0063
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.