T1059.006SubTechniqueexecutionagent-callable

T1059.006Python

Sub-technique of T1059

Platforms: Linux · Windows · macOS

ATT&CK version: 14.1

What it is

Adversaries may abuse Python commands and scripts for execution. Python is a very popular scripting/programming language, with capabilities to perform many functions. Python can be executed interactively from the command-line (via the <code>python.exe</code> interpreter) or via scripts (.py) that can be written and distributed to different systems. Python code can also be compiled into binary executables. Python comes with many built-in packages to interact with the underlying system, such as file operations and device I/O. Adversaries can use these libraries to download and execute commands or other scripts as well as perform various malicious behaviors.

ATT&CK tactics· 1

Execution

References

  1. https://attack.mitre.org/techniques/T1059/006
Sourced from MITRE ATT&CK Enterprise v14.1. Curated and contextualized for EU compliance use cases by Adam Lundqvist, Founder at SQUR.