T1202

Indirect Command Execution

Windowsnothing on this site yetT1202 on attack.mitre.org

Adversaries may abuse utilities that allow for command execution to bypass security restrictions that limit the use of command-line interpreters. Various Windows utilities may be used to execute commands, possibly without invoking cmd.

MITRE ATT&CK 19.2, retrieved 2026-09-12

how MITRE says to see it

Indirect Command Execution – Windows utility abuse behavior chain

  • Cause→effect chain: (1) A user or service launches an indirection utility (e.g., forfiles.exe, pcalua.exe, wsl.exe, scriptrunner.exe, ssh.exe with -o ProxyCommand/LocalCommand).

The description, detection analytics and mitigations are reproduced from MITRE ATT&CK, version 19.2, under its terms of use. The checklists, hunts, labs and everything else linked here are this site’s.