T1059 Command and Scripting Interpreter — Detection & Response
Adversaries may abuse command and script interpreters to execute commands, scripts, or binaries. These interfaces and languages provide ways of interacting with computer systems and are a common feature across many different platforms. Most systems come with some built-in command-line interface and scripting capabilities.
Coverage at a glance
- Detections shipped
- 4
- Avg. verdict time
- < 5 min
- Data sources
- 3+
Threat context
How adversaries use T1059 Command and Scripting Interpreter — Detection & Response
Adversaries may abuse command and script interpreters to execute commands, scripts, or binaries. These interfaces and languages provide ways of interacting with computer systems and are a common feature across many different platforms. Most systems come with some built-in command-line interface and scripting capabilities.
PowerShell (T1059.001) is the most abused scripting interpreter in Windows enterprise environments due to its deep OS integration and ability to operate in-memory. Attackers use PowerShell for downloading and executing payloads, reconnaissance, credential dumping, and lateral movement. Cloud API (T1059.009) abuse via AWS CLI, az CLI, and gcloud is the cloud-native equivalent — an attacker with stolen cloud credentials uses these tools to enumerate, escalate, and exfiltrate without touching the endpoint.
Detections ManySignal ships
Ready-to-deploy detection rules
| Rule name | Severity | Data source |
|---|---|---|
| Encoded PowerShell Execution — Base64 encoded command in PowerShell arguments PowerShell launched with -EncodedCommand argument, commonly used to obfuscate malicious commands. | High | Windows Event Log / CrowdStrike |
| PowerShell Download Cradle — Invoke-WebRequest or IEX in PowerShell command PowerShell script includes net.webclient.downloadstring or Invoke-Expression with a URL, indicating payload download. | Critical | CrowdStrike / SentinelOne |
| AWS CLI Mass Enumeration — High volume of describe/list API calls via CLI user agent Unusual volume of read API calls from the aws-cli user agent, consistent with post-compromise cloud enumeration. | High | AWS CloudTrail |
| New Process from Scripting Host — wscript.exe or cscript.exe spawning child process Windows Script Host spawns a new process, commonly seen in macro-based malware and phishing payload execution. | Medium | CrowdStrike / SentinelOne |
Related techniques and tactics
T1078 Valid Accounts — Detection & Response
ATT&CK Technique
T1110 Brute Force — Detection & Response
ATT&CK Technique
T1566 Phishing — Detection & Response
ATT&CK Technique
T1053 Scheduled Task/Job — Detection & Response
ATT&CK Technique
T1548 Abuse Elevation Control Mechanism — Detection & Response
ATT&CK Technique
T1068 Exploitation for Privilege Escalation — Detection & Response
ATT&CK Technique
T1134 Access Token Manipulation — Detection & Response
ATT&CK Technique
T1098 Account Manipulation — Detection & Response
ATT&CK Technique
T1136 Create Account — Detection & Response
ATT&CK Technique
T1556 Modify Authentication Process — Detection & Response
ATT&CK Technique
T1621 Multi-Factor Authentication Request Generation — Detection & Response
ATT&CK Technique
T1539 Steal Web Session Cookie — Detection & Response
ATT&CK Technique
T1059 Command and Scripting Interpreter — Detection & Response: frequently asked questions
Does ManySignal detect AMSI bypass techniques?
ManySignal receives CrowdStrike and SentinelOne detections that include AMSI bypass events. The EDR vendor detects the bypass at the kernel level; ManySignal enriches the alert with identity and network context to establish scope and blast radius.
See the agentic SOC in action
Watch AI agents work a real alert queue — verdicts, evidence, and confidence scores included. In-house SOC or MDR, your call.