M ManySignal
T1059 MITRE ATT&CK

T1059 Command and Scripting Interpreter — Detection & Response

Adversaries may abuse command and script interpreters to execute commands, scripts, or binaries. These interfaces and languages provide ways of interacting with computer systems and are a common feature across many different platforms. Most systems come with some built-in command-line interface and scripting capabilities.

Coverage at a glance

Detections shipped
4
Avg. verdict time
< 5 min
Data sources
3+

Threat context

How adversaries use T1059 Command and Scripting Interpreter — Detection & Response

Adversaries may abuse command and script interpreters to execute commands, scripts, or binaries. These interfaces and languages provide ways of interacting with computer systems and are a common feature across many different platforms. Most systems come with some built-in command-line interface and scripting capabilities.

PowerShell (T1059.001) is the most abused scripting interpreter in Windows enterprise environments due to its deep OS integration and ability to operate in-memory. Attackers use PowerShell for downloading and executing payloads, reconnaissance, credential dumping, and lateral movement. Cloud API (T1059.009) abuse via AWS CLI, az CLI, and gcloud is the cloud-native equivalent — an attacker with stolen cloud credentials uses these tools to enumerate, escalate, and exfiltrate without touching the endpoint.

Detections ManySignal ships

Ready-to-deploy detection rules

Rule name Severity Data source

Encoded PowerShell Execution — Base64 encoded command in PowerShell arguments

PowerShell launched with -EncodedCommand argument, commonly used to obfuscate malicious commands.

High Windows Event Log / CrowdStrike

PowerShell Download Cradle — Invoke-WebRequest or IEX in PowerShell command

PowerShell script includes net.webclient.downloadstring or Invoke-Expression with a URL, indicating payload download.

Critical CrowdStrike / SentinelOne

AWS CLI Mass Enumeration — High volume of describe/list API calls via CLI user agent

Unusual volume of read API calls from the aws-cli user agent, consistent with post-compromise cloud enumeration.

High AWS CloudTrail

New Process from Scripting Host — wscript.exe or cscript.exe spawning child process

Windows Script Host spawns a new process, commonly seen in macro-based malware and phishing payload execution.

Medium CrowdStrike / SentinelOne

T1059 Command and Scripting Interpreter — Detection & Response: frequently asked questions

Does ManySignal detect AMSI bypass techniques?

ManySignal receives CrowdStrike and SentinelOne detections that include AMSI bypass events. The EDR vendor detects the bypass at the kernel level; ManySignal enriches the alert with identity and network context to establish scope and blast radius.

See the agentic SOC in action

Watch AI agents work a real alert queue — verdicts, evidence, and confidence scores included. In-house SOC or MDR, your call.