T1059.006 Python Mappings

Adversaries may abuse Python commands and scripts for execution. Python is a very popular scripting/programming language, with capabilities to perform many functions. Python can be executed interactively from the command-line (via the <code>python.exe</code> interpreter) or via scripts (.py) that can be written and distributed to different systems. Python code can also be compiled into binary executables.

Python comes with many built-in packages to interact with the underlying system, such as file operations and device I/O. Adversaries can use these libraries to download and execute commands or other scripts as well as perform various malicious behaviors.

View in MITRE ATT&CK®

Mappings

Capability ID Capability Description Mapping Type ATT&CK ID ATT&CK Name
AC-17 Remote Access Protects T1059.006 Python
AC-02 Account Management Protects T1059.006 Python
AC-03 Access Enforcement Protects T1059.006 Python
AC-06 Least Privilege Protects T1059.006 Python
CM-11 User-installed Software Protects T1059.006 Python
CM-02 Baseline Configuration Protects T1059.006 Python
CM-03 Configuration Change Control Protects T1059.006 Python
CM-05 Access Restrictions for Change Protects T1059.006 Python
CM-06 Configuration Settings Protects T1059.006 Python
SI-10 Information Input Validation Protects T1059.006 Python
SI-16 Memory Protection Protects T1059.006 Python
SI-02 Flaw Remediation Protects T1059.006 Python
SI-03 Malicious Code Protection Protects T1059.006 Python
SI-04 System Monitoring Protects T1059.006 Python
SI-07 Software, Firmware, and Information Integrity Protects T1059.006 Python
EOP-Antimalware-E3 Antimalware Technique Scores T1059.006 Python
M365-DEF-ZAP-E3 Zero Hour Auto Purge Technique Scores T1059.006 Python