Compliance Node Overview
MITRE ATT&CK T1059.006 (Python) is an Enterprise Execution sub-technique of T1059 (Command and Scripting Interpreter). Adversaries may abuse Python commands and scripts for execution. Python is a very popular scripting/programming language, with capabilities to perform many functions. Python can be executed interactively from the command-line (via the python.exe interpreter) or via scripts (.py) that can be written and distributed to different systems. Python code can also be compiled into binary executables. Python comes with many built-in packages to interact with the underlying system, such as file operations and device I/O. Affected platforms: Linux, Windows, macOS. MITRE-documented mitigations include M1047 Audit, M1049 Antivirus/Antimalware, M1033 Limit Software Installation, M1038 Execution Prevention. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-02, AC-03, AC-05, AC-06, AC-17, CA-07, CM-02, CM-03.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1059/006/
SHA-256 integrity: eaf719f0a80cf6b5bc77e7d7296c73484abb855baa49aa649152495814ea8fbb
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1059.006: Python (https://attack.mitre.org/techniques/T1059/006/)
- MITRE ATT&CK Tactic TA0002: Execution (https://attack.mitre.org/tactics/TA0002/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access