Skip to content

S0106 cmd

cmd is the Windows command-line interpreter that can be used to interact with systems and execute other processes and utilities. 1

Cmd.exe contains native functionality to perform many operations to interact with the system, including listing files in a directory (e.g., dir 4), deleting files (e.g., del 3), and copying files (e.g., copy 2).

Item Value
ID S0106
Associated Names
Type TOOL
Version 1.2
Created 31 May 2017
Last Modified 13 October 2022
Navigation Layer View In ATT&CK® Navigator

Techniques Used

Domain ID Name Use
enterprise T1059 Command and Scripting Interpreter -
enterprise T1059.003 Windows Command Shell cmd is used to execute programs and other actions at the command-line interface.1
enterprise T1083 File and Directory Discovery cmd can be used to find files and directories with native functionality such as dir commands.4
enterprise T1070 Indicator Removal -
enterprise T1070.004 File Deletion cmd can be used to delete files from the file system.3
enterprise T1105 Ingress Tool Transfer cmd can be used to copy files to/from a remotely connected external system.2
enterprise T1570 Lateral Tool Transfer cmd can be used to copy files to/from a remotely connected internal system.2
enterprise T1082 System Information Discovery cmd can be used to find information about the operating system.4

Groups That Use This Software

ID Name References
G0071 Orangeworm 6
G0026 APT18 7
G0060 BRONZE BUTLER 8
G0045 menuPass 9
G0093 GALLIUM 1011

References