Adversaries may abuse the Windows command shell for execution. The Windows command shell (cmd) is the primary command prompt on Windows systems. The Windows command prompt can be used to control almost any aspect of a system, with various permission levels required for different subsets of commands.
Batch files (ex: .bat or .cmd) also provide the shell with a list of sequential commands to run, as well as normal scripting operations such as conditionals and loops. Common uses of batch files include long or repetitive tasks, or the need to run the same set of commands on multiple systems.
Adversaries may leverage cmd to execute various commands and payloads. Common uses include cmd to execute a single command, or abusing cmd interactively with input and output forwarded over a command and control channel.
View in MITRE ATT&CK®Capability ID | Capability Description | Mapping Type | ATT&CK ID | ATT&CK Name | Notes |
---|---|---|---|---|---|
CM-7 | Least Functionality | Protects | T1059.003 | Windows Command Shell | |
SI-10 | Information Input Validation | Protects | T1059.003 | Windows Command Shell | |
SI-4 | System Monitoring | Protects | T1059.003 | Windows Command Shell | |
SI-7 | Software, Firmware, and Information Integrity | Protects | T1059.003 | Windows Command Shell | |
action.hacking.variety.Abuse of functionality | Abuse of functionality | related-to | T1059.003 | Command and Scripting Interpreter: Windows Command Shell | |
action.hacking.vector.Command shell | Remote shell | related-to | T1059.003 | Command and Scripting Interpreter: Windows Command Shell |