MITRE ATT&CK Technique
T1059.003Windows Command Shell
- First Reported
- Sep 22, 2026
- Latest Reported
- Sep 27, 2026
Official Description
Adversaries may abuse the Windows command shell for execution. The Windows command shell ([cmd](https://attack.mitre.org/software/S0106)) is the primary command prompt on Windows systems. The Windows command prompt can be used to control almost any aspect of a system, with various permission levels required for different subsets of commands. The command prompt can be invoked remotely via [Remote Services](https://attack.mitre.org/techniques/T1021) such as [SSH](https://attack.mitre.org/techniques/T1021/004).(Citation: SSH in Windows)
Batch files (ex: .bat or .cmd) also provide the shell with a list of sequential commands to run, as well as normal scripting operations such as conditionals and loops. Common uses of batch files include long or repetitive tasks, or the need to run the same set of commands on multiple systems.
Adversaries may leverage [cmd](https://attack.mitre.org/software/S0106) to execute various commands and payloads. Common uses include [cmd](https://attack.mitre.org/software/S0106) to execute a single command, or abusing [cmd](https://attack.mitre.org/software/S0106) interactively with input and output forwarded over a command and control channel.
Batch files (ex: .bat or .cmd) also provide the shell with a list of sequential commands to run, as well as normal scripting operations such as conditionals and loops. Common uses of batch files include long or repetitive tasks, or the need to run the same set of commands on multiple systems.
Adversaries may leverage [cmd](https://attack.mitre.org/software/S0106) to execute various commands and payloads. Common uses include [cmd](https://attack.mitre.org/software/S0106) to execute a single command, or abusing [cmd](https://attack.mitre.org/software/S0106) interactively with input and output forwarded over a command and control channel.
- Tactics
- Execution
- Platforms
- Windows
- Parent Technique
- T1059 · Command and Scripting Interpreter
- MITRE Version
- 1.5
- Last Modified
- May 12, 2026
Reported Context (3)
- The reverse shell launched cmd.Exe with its input, output, and error handles connected to an attacker-accessible socket. Attackers Exploit Telerik CVE-2019-18935 to Install Web Shells and Scan for Exposed WordPress Pages
- The deployed web shells spawned cmd.exe on Windows to execute actor-supplied commands. ShinyHunters Resume Mass Exploitation of Oracle PeopleSoft Vulnerability CVE-2026-35273
- Batch droppers checked administrative rights and launched agent installation. CSuite Campaign Uses Phishing, M365 Session Theft and Remote-Access Tools Against US and EU Organizations
CVE (2)
Malware (2)
Threat Actors (3)
MITRE ATT&CK (38)
Vendors (12)
Products (16)
Tools (9)
Industries (6)
Countries (7)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.