EXPLORE
← Back to Explore
T1059

Command and Scripting Interpreter

Adversaries may abuse command and script interpreters to execute commands, scripts, or binaries. These interfaces and languages provide ways of interacting with computer systems and are a common feature across many different platforms. Most systems come with some built-in command-line interface and scripting capabilities, for example, macOS and Linux distributions include some flavor of [Unix Shell](https://attack.mitre.org/techniques/T1059/004) while Windows installations include the [Windows C...

ContainersESXiIaaSIdentity ProviderLinuxmacOSNetwork DevicesOffice SuiteSaaSWindows
532
Detections
7
Sources
17
Threat Actors

BY SOURCE

314elastic78sigma71sublime40splunk_escu12crowdstrike_cql11jamf_protect6kql

PROCEDURES (181)

Process Creation Monitoring30 detections

Auto-extracted: 30 detections for process creation monitoring

General Monitoring27 detections

Auto-extracted: 27 detections for general monitoring

Script Execution Monitoring24 detections

Auto-extracted: 24 detections for script execution monitoring

Persist10 detections

Auto-extracted: 10 detections for persist

Amsi9 detections

Auto-extracted: 9 detections for amsi

Exfiltrat8 detections

Auto-extracted: 8 detections for exfiltrat

Script Block8 detections

Auto-extracted: 8 detections for script block

Suspicious8 detections

Auto-extracted: 8 detections for suspicious

Privilege8 detections

Auto-extracted: 8 detections for privilege

Download7 detections

Auto-extracted: 7 detections for download

Http6 detections

Auto-extracted: 6 detections for http

Child Process6 detections

Auto-extracted: 6 detections for child process

Parent Process6 detections

Auto-extracted: 6 detections for parent process

Suspicious5 detections

Auto-extracted: 5 detections for suspicious

Parent Process5 detections

Auto-extracted: 5 detections for parent process

Email5 detections

Auto-extracted: 5 detections for email

Phish5 detections

Auto-extracted: 5 detections for phish

Network Connection Monitoring5 detections

Auto-extracted: 5 detections for network connection monitoring

Attachment5 detections

Auto-extracted: 5 detections for attachment

Exfiltrat5 detections

Auto-extracted: 5 detections for exfiltrat

Obfuscat5 detections

Auto-extracted: 5 detections for obfuscat

Inject5 detections

Auto-extracted: 5 detections for inject

Service5 detections

Auto-extracted: 5 detections for service

Email5 detections

Auto-extracted: 5 detections for email

Base645 detections

Auto-extracted: 5 detections for base64

Container5 detections

Auto-extracted: 5 detections for container

Suspicious5 detections

Auto-extracted: 5 detections for suspicious

Remote5 detections

Auto-extracted: 5 detections for remote

Service4 detections

Auto-extracted: 4 detections for service

Kubernetes4 detections

Auto-extracted: 4 detections for kubernetes

Startup4 detections

Auto-extracted: 4 detections for startup

Remote4 detections

Auto-extracted: 4 detections for remote

Container4 detections

Auto-extracted: 4 detections for container

Download4 detections

Auto-extracted: 4 detections for download

Powershell4 detections

Auto-extracted: 4 detections for powershell

Bypass4 detections

Auto-extracted: 4 detections for bypass

Bypass4 detections

Auto-extracted: 4 detections for bypass

Command And Control4 detections

Auto-extracted: 4 detections for command and control

Child Process4 detections

Auto-extracted: 4 detections for child process

Powershell4 detections

Auto-extracted: 4 detections for powershell

Unusual3 detections

Auto-extracted: 3 detections for unusual

Powershell3 detections

Auto-extracted: 3 detections for powershell

Child Process3 detections

Auto-extracted: 3 detections for child process

Suspicious3 detections

Auto-extracted: 3 detections for suspicious

Phish3 detections

Auto-extracted: 3 detections for phish

Ransomware3 detections

Auto-extracted: 3 detections for ransomware

Credential3 detections

Auto-extracted: 3 detections for credential

Service3 detections

Auto-extracted: 3 detections for service

Remote3 detections

Auto-extracted: 3 detections for remote

Child Process3 detections

Auto-extracted: 3 detections for child process

Azure3 detections

Auto-extracted: 3 detections for azure

Kubernetes3 detections

Auto-extracted: 3 detections for kubernetes

C23 detections

Auto-extracted: 3 detections for c2

Inject3 detections

Auto-extracted: 3 detections for inject

Powershell3 detections

Auto-extracted: 3 detections for powershell

Unusual3 detections

Auto-extracted: 3 detections for unusual

Token3 detections

Auto-extracted: 3 detections for token

Authentication Monitoring3 detections

Auto-extracted: 3 detections for authentication monitoring

Aws3 detections

Auto-extracted: 3 detections for aws

Persist3 detections

Auto-extracted: 3 detections for persist

Base643 detections

Auto-extracted: 3 detections for base64

Child Process2 detections

Auto-extracted: 2 detections for child process

Aws2 detections

Auto-extracted: 2 detections for aws

Suspicious2 detections

Auto-extracted: 2 detections for suspicious

Command Line Monitoring2 detections

Auto-extracted: 2 detections for command line monitoring

Attachment2 detections

Auto-extracted: 2 detections for attachment

Attachment2 detections

Auto-extracted: 2 detections for attachment

Office2 detections

Auto-extracted: 2 detections for office

Macro2 detections

Auto-extracted: 2 detections for macro

Kubernetes2 detections

Auto-extracted: 2 detections for kubernetes

C22 detections

Auto-extracted: 2 detections for c2

Lateral2 detections

Auto-extracted: 2 detections for lateral

Persist2 detections

Auto-extracted: 2 detections for persist

Service2 detections

Auto-extracted: 2 detections for service

Inject2 detections

Auto-extracted: 2 detections for inject

Http2 detections

Auto-extracted: 2 detections for http

Unusual2 detections

Auto-extracted: 2 detections for unusual

Exfiltrat2 detections

Auto-extracted: 2 detections for exfiltrat

Privilege2 detections

Auto-extracted: 2 detections for privilege

Office2 detections

Auto-extracted: 2 detections for office

C22 detections

Auto-extracted: 2 detections for c2

Parent Process2 detections

Auto-extracted: 2 detections for parent process

Email2 detections

Auto-extracted: 2 detections for email

Kerbero2 detections

Auto-extracted: 2 detections for kerbero

Registry1 detections

Auto-extracted: 1 detections for registry

Obfuscat1 detections

Auto-extracted: 1 detections for obfuscat

Suspicious1 detections

Auto-extracted: 1 detections for suspicious

Module Load Monitoring1 detections

Auto-extracted: 1 detections for module load monitoring

Unusual1 detections

Auto-extracted: 1 detections for unusual

Azure1 detections

Auto-extracted: 1 detections for azure

Obfuscat1 detections

Auto-extracted: 1 detections for obfuscat

Base641 detections

Auto-extracted: 1 detections for base64

Kernel1 detections

Auto-extracted: 1 detections for kernel

Cloud1 detections

Auto-extracted: 1 detections for cloud

Encrypt1 detections

Auto-extracted: 1 detections for encrypt

Kernel1 detections

Auto-extracted: 1 detections for kernel

Service1 detections

Auto-extracted: 1 detections for service

Evasion1 detections

Auto-extracted: 1 detections for evasion

Azure1 detections

Auto-extracted: 1 detections for azure

Wmi1 detections

Auto-extracted: 1 detections for wmi

Lateral1 detections

Auto-extracted: 1 detections for lateral

Office1 detections

Auto-extracted: 1 detections for office

Bypass1 detections

Auto-extracted: 1 detections for bypass

Service Monitoring1 detections

Auto-extracted: 1 detections for service monitoring

Amsi1 detections

Auto-extracted: 1 detections for amsi

Privilege1 detections

Auto-extracted: 1 detections for privilege

Token1 detections

Auto-extracted: 1 detections for token

Anomal1 detections

Auto-extracted: 1 detections for anomal

Base641 detections

Auto-extracted: 1 detections for base64

Command And Control1 detections

Auto-extracted: 1 detections for command and control

Persist1 detections

Auto-extracted: 1 detections for persist

Encrypt1 detections

Auto-extracted: 1 detections for encrypt

Container1 detections

Auto-extracted: 1 detections for container

Exfiltrat1 detections

Auto-extracted: 1 detections for exfiltrat

Tamper1 detections

Auto-extracted: 1 detections for tamper

Amsi1 detections

Auto-extracted: 1 detections for amsi

Privilege1 detections

Auto-extracted: 1 detections for privilege

Macro1 detections

Auto-extracted: 1 detections for macro

Script Block1 detections

Auto-extracted: 1 detections for script block

Tamper1 detections

Auto-extracted: 1 detections for tamper

Ransomware1 detections

Auto-extracted: 1 detections for ransomware

Macro1 detections

Auto-extracted: 1 detections for macro

Download1 detections

Auto-extracted: 1 detections for download

Kernel Monitoring1 detections

Auto-extracted: 1 detections for kernel monitoring

Evasion1 detections

Auto-extracted: 1 detections for evasion

Remote1 detections

Auto-extracted: 1 detections for remote

Cloud Monitoring1 detections

Auto-extracted: 1 detections for cloud monitoring

Persist1 detections

Auto-extracted: 1 detections for persist

Scheduled Task1 detections

Auto-extracted: 1 detections for scheduled task

Wmi1 detections

Auto-extracted: 1 detections for wmi

Remote1 detections

Auto-extracted: 1 detections for remote

Lateral1 detections

Auto-extracted: 1 detections for lateral

Encrypt1 detections

Auto-extracted: 1 detections for encrypt

Macro1 detections

Auto-extracted: 1 detections for macro

Suspicious1 detections

Auto-extracted: 1 detections for suspicious

Kernel1 detections

Auto-extracted: 1 detections for kernel

Unusual1 detections

Auto-extracted: 1 detections for unusual

Suspicious1 detections

Auto-extracted: 1 detections for suspicious

Amsi1 detections

Auto-extracted: 1 detections for amsi

Registry1 detections

Auto-extracted: 1 detections for registry

Amsi1 detections

Auto-extracted: 1 detections for amsi

Evasion1 detections

Auto-extracted: 1 detections for evasion

Wmi1 detections

Auto-extracted: 1 detections for wmi

Registry1 detections

Auto-extracted: 1 detections for registry

Container1 detections

Auto-extracted: 1 detections for container

Inject1 detections

Auto-extracted: 1 detections for inject

Privilege1 detections

Auto-extracted: 1 detections for privilege

C21 detections

Auto-extracted: 1 detections for c2

Anomal1 detections

Auto-extracted: 1 detections for anomal

Command And Control1 detections

Auto-extracted: 1 detections for command and control

Encrypt1 detections

Auto-extracted: 1 detections for encrypt

Tamper1 detections

Auto-extracted: 1 detections for tamper

Bypass1 detections

Auto-extracted: 1 detections for bypass

Inject1 detections

Auto-extracted: 1 detections for inject

Unusual1 detections

Auto-extracted: 1 detections for unusual

Parent Process1 detections

Auto-extracted: 1 detections for parent process

Parent Process1 detections

Auto-extracted: 1 detections for parent process

Dump1 detections

Auto-extracted: 1 detections for dump

Scheduled Task1 detections

Auto-extracted: 1 detections for scheduled task

Powershell1 detections

Auto-extracted: 1 detections for powershell

Lateral1 detections

Auto-extracted: 1 detections for lateral

Ransomware1 detections

Auto-extracted: 1 detections for ransomware

Bypass1 detections

Auto-extracted: 1 detections for bypass

Privilege1 detections

Auto-extracted: 1 detections for privilege

Process Access1 detections

Auto-extracted: 1 detections for process access

Powershell1 detections

Auto-extracted: 1 detections for powershell

Inject1 detections

Auto-extracted: 1 detections for inject

Cloud1 detections

Auto-extracted: 1 detections for cloud

Cloud1 detections

Auto-extracted: 1 detections for cloud

Token1 detections

Auto-extracted: 1 detections for token

Persist1 detections

Auto-extracted: 1 detections for persist

Ransomware1 detections

Auto-extracted: 1 detections for ransomware

Parent Process1 detections

Auto-extracted: 1 detections for parent process

Persist1 detections

Auto-extracted: 1 detections for persist

Dump1 detections

Auto-extracted: 1 detections for dump

Attachment1 detections

Auto-extracted: 1 detections for attachment

Anomal1 detections

Auto-extracted: 1 detections for anomal

Attachment1 detections

Auto-extracted: 1 detections for attachment

Wmi1 detections

Auto-extracted: 1 detections for wmi

Aws1 detections

Auto-extracted: 1 detections for aws

Amsi1 detections

Auto-extracted: 1 detections for amsi

DETECTIONS (532)

Abusable DLL Potential Sideloading From Suspicious Location
sigmahigh
Add Insecure Download Source To Winget
sigmahigh
Add New Download Source To Winget
sigmamedium
Add Potential Suspicious New Download Source To Winget
sigmamedium
AMSI Script Detection
kql
Anomalous Windows Process Creation
elasticlow
Apple Script Execution followed by Network Connection
elasticmedium
Apple Scripting Execution with Administrator Privileges
elasticmedium
AppleScript Clipboard Activity
jamf_protectinformational
AppleScript Dialog Activity
jamf_protectinformational
Applications Spawning CMD or Powershell
crowdstrike_cql
Applications Spawning CMD or Powershell
crowdstrike_cql
Attachment: .csproj with suspicious commands
sublimehigh
Attachment: Any .sap file (unsolicited)
sublimelow
Attachment: Archive contains DLL-loading macro
sublimehigh
Attachment: cmd file extension
sublimelow
Attachment: CVE-2021-40444 - MSHTML Remote Code Execution Vulnerability
sublimecritical
Attachment: CVE-2025-24071 - Microsoft Windows File Explorer Spoofing Vulnerability
sublimecritical
Attachment: Double base64-encoded zip file in HTML smuggling attachment
sublimehigh
Attachment: Embedded Javascript in SVG file
sublimehigh
Attachment: Embedded VBScript in MHT file
sublimemedium
Attachment: EML containing a base64 encoded script
sublimehigh
Attachment: EML with embedded Javascript in SVG file
sublimehigh
Attachment: Encrypted Microsoft Office file (unsolicited)
sublimemedium
Attachment: Fake Slack installer
sublimehigh
Attachment: Fake Zoom installer
sublimehigh
Attachment: File execution via Javascript
sublimemedium
Attachment: HTML attachment with Javascript location
sublimehigh
Attachment: HTML attachment with login portal indicators
sublimemedium
Attachment: HTML file contains exclusively Javascript
sublimemedium
Attachment: HTML file with excessive 'const' declarations and abnormally long timeouts
sublimehigh
Attachment: HTML file with reference to recipient and suspicious patterns
sublimehigh
Attachment: HTML smuggling 'body onload' linking to suspicious destination
sublimehigh
Attachment: HTML smuggling 'body onload' with high entropy and suspicious text
sublimehigh
Attachment: HTML smuggling with atob and high entropy
sublimehigh
Attachment: HTML smuggling with atob and high entropy via calendar invite
sublimehigh
Attachment: HTML smuggling with auto-downloaded file
sublimehigh
Attachment: HTML smuggling with base64 encoded JavaScript function
sublimehigh
Attachment: HTML smuggling with base64 encoded ZIP file
sublimemedium
Attachment: HTML smuggling with concatenation obfuscation
sublimehigh
Attachment: HTML smuggling with decimal encoding
sublimehigh
Attachment: HTML smuggling with embedded base64 streamed file download
sublimehigh
Attachment: HTML smuggling with eval and atob
sublimehigh
Attachment: HTML smuggling with eval and atob via calendar invite
sublimehigh
Attachment: HTML smuggling with excessive line break obfuscation
sublimehigh
Attachment: HTML smuggling with excessive string concatenation and suspicious patterns
sublimemedium
Attachment: HTML smuggling with fromCharCode and other signals
sublimehigh
Attachment: HTML smuggling with high entropy and other signals
sublimehigh
Attachment: HTML smuggling with RC4 decryption
sublimehigh
Attachment: HTML smuggling with ROT13
sublimehigh
Attachment: HTML smuggling with setTimeout
sublimehigh
Attachment: HTML smuggling with unescape
sublimehigh
Attachment: HTML with emoji-to-character map
sublimehigh
Attachment: HTML with hidden body
sublimehigh
Attachment: HTML with JavaScript functions for HTTP requests
sublimehigh
Attachment: HTML with obfuscation and recipient's email in JavaScript strings
sublimehigh
Attachment: ICS with embedded Javascript in SVG file
sublimehigh
Attachment: JavaScript file with suspicious base64-encoded executable
sublimehigh
Attachment: LNK with embedded content
sublimehigh
Attachment: Macro files containing MHT content
sublimemedium
Attachment: Macro with suspected use of COM ShellBrowserWindow object for process creation
sublimehigh
Attachment: Malicious OneNote commands
sublimehigh
Attachment: Microsoft impersonation via PDF with link and suspicious language
sublimehigh
Attachment: Office document with VSTO add-in
sublimehigh
Attachment: Office file with suspicious function calls or downloaded file path
sublimehigh
Attachment: PDF with embedded Javascript
sublimemedium
Attachment: PowerPoint with suspicious hyperlink
sublimehigh
Attachment: PowerShell content
sublimehigh
Attachment: SFX archive containing commands
sublimemedium
Attachment: SVG file execution
sublimehigh
Attempt to Install or Run Kali Linux via WSL
elastichigh
AWS Batch Job Submitted with Container Override by Unusual Identity
elasticmedium
AWS Bedrock High Risk Filesystem or Execution Tool Invocation
elastichigh
AWS CloudShell Environment Created
elastichigh
AWS EC2 LOLBin Execution via SSM SendCommand
elasticmedium
AWS EC2 Stop, Start, and User Data Modification Correlation
elastichigh
AWS SageMaker Notebook Lifecycle Configuration With Suspicious Script Content
elastichigh
AWS SSM `SendCommand` with Run Shell Command Parameters
elasticmedium
AWS SSM Session Manager Child Process Execution
elasticmedium
Azure New CloudShell Created
sigmamedium
Azure Run Command Correlated with Process Execution
elasticmedium
Azure Run Command Script Child Process
elasticmedium
Base64 Decoded Payload Piped to Interpreter
elastichigh
Binary Executed from Shared Memory Directory
elastichigh
Boot File Copy
elasticlow
BPF filter applied using TC
elastichigh
BPFDoor Abnormal Process ID or Lock File Accessed
sigmahigh
Capsh Shell Invocation - Linux
sigmahigh
Cassandra JavaScript UDF Creation
elastichigh
CHCP Command Execution
splunk_escu
Cisco NVM - Installation of Typosquatted Python Package
splunk_escu
Cisco NVM - Suspicious File Download via Headless Browser
splunk_escu
Cisco Secure Firewall - Binary File Type Download
splunk_escu
Cisco Secure Firewall - Citrix NetScaler Memory Overread Attempt
splunk_escu
Cisco Secure Firewall - High Volume of Intrusion Events Per Host
splunk_escu
Cisco Secure Firewall - Possibly Compromised Host
splunk_escu
Cisco Secure Firewall - Privileged Command Execution via HTTP
splunk_escu
Cisco Secure Firewall - Wget or Curl Download
splunk_escu
Clearing Windows Console History
elasticmedium
Clfs.SYS Loaded By Process Located In a Potential Suspicious Location
sigmamedium
ClickFix: Clipboard hijack lure with copy-paste-to-terminal instruction
sublimehigh
Command and Scripting Interpreter via Windows Scripts
elastichigh
Command Execution via SolarWinds Process
elasticmedium
Command Line Obfuscation via Whitespace Padding
elasticmedium
Command Shell Activity Started via RunDLL32
elasticlow
Conhost Spawned By Suspicious Parent Process
elastichigh
Conhost Spawned By Uncommon Parent Process
sigmamedium
Creation of Hidden Login Item via Apple Script
elasticmedium
Credential theft: JavaScript date manipulation in HTML body
sublimemedium
Cupsd or Foomatic-rip Shell Execution
elastichigh
Curl Execution via Shell Profile
elastichigh
Curl or Wget Egress Network Connection via LoLBin
elasticmedium
CVE-2023-5631 - Roundcube Webmail XSS via crafted SVG
sublimecritical
Decoded Payload Piped to Interpreter Detected via Defend for Containers
elastichigh
Delayed Execution via Ping
elasticlow
Deprecated - EggShell Backdoor Execution
elastichigh
Deprecated - Linux Restricted Shell Breakout via Linux Binary(s)
elasticmedium
Deprecated - Potential PowerShell Obfuscated Script
elasticlow
Deprecated - Uncommon Destination Port Connection by Web Server
elasticlow
Deprecated - Unusual Command Execution from Web Server Parent
elasticlow
Deprecated - Unusual Process Spawned from Web Server Parent
elasticlow
Detect Outbound LDAP Traffic
splunk_escu
Detection of External Direct IP Usage in CommandLine Windows and Mac
crowdstrike_cql
Detection of External Direct IP Usage in CommandLine Windows and Mac
crowdstrike_cql
Direct Interactive Kubernetes API Request by Common Utilities
elasticmedium
Direct Interactive Kubernetes API Request by Unusual Utilities
elasticlow
Direct Kubernetes API Request Detected via Defend for Containers
elasticlow
Direct Process Execution via Background Utility
elasticlow
Disabling Windows Defender Security Settings via PowerShell
elasticmedium
Dracut Module Creation
elasticlow
Dynamic IEX Reconstruction via Method String Access
elasticlow
Dynamic Linker (ld.so) Creation
elasticmedium
Egress Connection from Entrypoint in Container
elasticmedium
Elevated System Shell Spawned
sigmamedium
Elevated System Shell Spawned From Uncommon Parent Location
sigmamedium
Encoded Payload Detected via Defend for Containers
elasticmedium
Entra ID PowerShell Sign-in
elasticlow
ESXi Reverse Shell Patterns
splunk_escu
Excessive distinct processes from Windows Temp
splunk_escu
Excessive number of taskhost processes
splunk_escu
Exec Into Container Detected via Defend for Containers
elasticlow
Execution from Unusual Directory - Command Line
elasticmedium
Execution of a Downloaded Windows Script
elasticmedium
Execution of Persistent Suspicious Program
elasticmedium
Execution via Electron Child Process Node.js Module
elasticmedium
Execution via GitHub Actions Runner
elasticmedium
Execution via MSSQL xp_cmdshell Stored Procedure
elasticmedium
Execution via OpenClaw Agent
elasticmedium
Execution via Windows Subsystem for Linux
elasticmedium
Execution with Explicit Credentials via Scripting
elasticmedium
Exporting Exchange Mailbox via PowerShell
elasticmedium
File Creation and Execution Detected via Defend for Containers
elasticmedium
File Creation by Cups or Foomatic-rip Child
elasticmedium
File Creation in /var/log via Suspicious Process
elasticmedium
File Creation, Execution and Self-Deletion in Suspicious Directory
elastichigh
File Download Detected via Defend for Containers
elasticmedium
File Downloaded by Curl/Wget and Piped to Interpreter
elasticmedium
File Execution Permission Modification Detected via Defend for Containers
elasticlow
File Transfer or Listener Established via Netcat
elasticmedium
File Transfer Utility Launched from Unusual Parent
elasticmedium
Find OpenClaw on Endpoints
crowdstrike_cql
Find OpenClaw on Endpoints
crowdstrike_cql
First Time Python Spawned a Shell on Host
elasticmedium
Forbidden Direct Interactive Kubernetes API Request
elasticmedium
Forfiles Command Execution
sigmamedium
Git Hook Child Process
elasticlow
Git Hook Command Execution
elasticlow
Git Hook Created or Modified
elasticlow
Git Hook Egress Network Connection
elasticmedium
GitHub Actions Unusual Bot Push to Repository
elasticlow
GitHub Actions Workflow Modification Blocked
elasticmedium
Github Activity on a Private Repository from an Unusual IP
elasticlow
GitHub Authentication Token Access via Node.js
elasticmedium
GKE Pod Exec Potential Reverse Shell
elastichigh
Google Calendar C2 via Script Interpreter
elastichigh
HackTool - Sliver C2 Implant Activity Pattern
sigmacritical
HackTool - Stracciatella Execution
sigmahigh
Hacktool Ruler
sigmahigh
Host File System Changes via Windows Subsystem for Linux
elasticmedium
HTML smuggling containing recipient email address
sublimemedium
HTML: Bidirectional (BIDI) HTML override with right to left obfuscation
sublimemedium
Incoming Execution via PowerShell Remoting
elasticmedium
Ingress Tool Transfer Followed by Execution and Deletion Detected via Defend for Containers
elastichigh
Initramfs Unpacking via unmkinitramfs
elasticlow
Inline Python Execution - Spawn Shell Via OS System Library
sigmahigh
Install New Package Via Winget Local Manifest
sigmamedium
Installation of WSL Kali-Linux
sigmahigh
Interactive Shell Launched via Unusual Parent Process in a Container
elasticmedium
Interactive Shell Spawn Detected via Defend for Containers
elasticlow
Interactive Terminal Spawned via Perl
elastichigh
Interactive Terminal Spawned via Python
elastichigh
Juniper Networks Remote Code Execution Exploit Detection
splunk_escu
Kill Command Execution
elasticlow
Kubernetes Direct API Request via Curl or Wget
elasticmedium
Kubernetes Pod Exec Potential Reverse Shell
elastichigh
LeakNet Campaign: Deno Runtime & Klist Suspicious Execution Detection
crowdstrike_cql
LeakNet Campaign: Deno Runtime & Klist Suspicious Execution Detection
crowdstrike_cql
Link: Credential phishing with obfuscated JavaScript redirect
sublimehigh
Link: Cryptocurrency fraud with suspicious links
sublimehigh
Link: JavaScript obfuscation with Telegram bot integration
sublimehigh