FORENSIA

ATT&CK · T1059.006 · sub-technique

Python

Tactics: execution

About

Adversaries may abuse Python commands and scripts for execution. Python is a very popular scripting/programming language, with capabilities to perform many functions. Python can be executed interactively from the command-line (via the <code>python.exe</code> interpreter) or via scripts (.py) that can be written and distributed to different systems. Python code can also be compiled into binary executables. Python comes with many built-in packages to interact with the underlying system, such as file operations and device I/O. Adversaries can use these libraries to download and execute commands or other scripts as well as perform various malicious behaviors.

Platforms: ESXi, Linux, macOS, WindowsParent: T1059 Command and Scripting InterpreterMITRE ATT&CK ↗

Used by actors

18 known groups

Software

37 malware/tools implement this

Cobalt StrikePupyPUNCHBUGGYBandookKeydnapRemcosCoinTickerSpeakUpEburyKeyBoyMachetePoetRATMechaFlounderBundloreCookieMinerDropBookIronNetInjectorPysaChaesTurianLizarSILENTTRINITYDonutPyDCryptSmall SieveFRAMESTINGUPSTYLEreGeorgNeo-reGeorgLumma StealerVIRTUALPITAVIRTUALPIETHINCRUSTInvisibleFerretDRYHOOKSPAWNCHIMERALAMEHUG

Corpus indicators tagged with this technique

216 indicators in the corpus carry T1059.006.

IndicatorTypeFamilySevSrc
cve-2021-27137cve858
cve-2025-34054cve854
cve-2016-15047cve854
b1b7aaa5bd4408a4d3003a9fabcdd041hash803
aeaf583e20347bf850e2fabdcd6f4982996ba023f8c2cd56bbd299cfd56516f5hashsupply_chain801
6d332f814f15f19758d65026bbfd0a8c49671b319ec77b8fa1b27fc48afff7d9hashsupply_chain802
123e80a34508c4dede7cc70e76931fcchash803
069ac1dc7f7649b76bc72a11ac700f373804bfd81dab7e561157b703999f44cehashsupply_chain801
873f1277a42de5c82f869459e7fb7c94554a642bhash803
681075027553546c119ec447eb8df84633dcffcehash803
7d80b3ef74ad7992b93c31966962612e4e2ceb93e7727cdbd1d2a9af47d44ba8hashsupply_chain801
52886aab179f26421678ff23af1b0fabf0a17ffbb534369cdbbac8008cbed8e7hashphishing802
62761f38ed194c59abe15c49f09f0ebc431ac852c965180c9327ed84d3a454fbhashphishing802
6506d31707a39949f89534bf9705bcf889f1ecae3dbc6f4ff88d67a8be3d01b2hashsupply_chain802
00e195d94d3b1f7092eb9ed132f89d1bhash803
2654c08491a0f7c4a3dfc6282de5638bhash803
625b6535321d58bb5c613e85332bf731hash803
4c0d9b802c075be79e9edb52d88f8dd72e6904f5c58267213745818470945c78hashphishing802
808e7154b7af2bc7a4b28d577297c55f77221c355191cbe00f9f1810b6d4a619hashphishing802
bb10adac5b0124efedfe71102c1d5638135ec9e1cde8c8cb3353c5ed91bb9f81hashphishing802
d3ebce2f05fe91a8260e87fd11a6ea17c156703d081b3f91d9bbe5fd6aeedc10hashphishing802
d5e9288693aa745dc89368deac677e7ea1ec81e663283af30838cdae189b7a7ehashphishing802
f4d77958a12a0778283d3e679b24b18f82e332c4hash803
b8eed63ab9cbdca494f26a6f66bfd4a0a693b3f0hash803
6328567511d88fdc2ae0939c5ef17b7a63d2a833881900de018a4f12f4982525sha256prompt_injection802
eead44c0af7ddb12cece1a6125cf213bab3c22511cd59aff9d63dcfddb7d4386hash804
3d1158884fb339b3328bd330fcc27598e1f1c94bcac39e75d1a272afa4deee1asha256ransomware801
9c44bc9373377831c45dd0ac2661a28ehash803
a08d8e63b0cd3638fb40b8e6da546e26da69439597565827f9cec87915f78568sha256ransomware801
84ad78b2bab946c3677fdc28ebd8a774hash803

Showing the top 30 by severity of 216.