T1202
Indirect Command Execution
Windowsnothing on this site yetT1202 on attack.mitre.org
Adversaries may abuse utilities that allow for command execution to bypass security restrictions that limit the use of command-line interpreters. Various Windows utilities may be used to execute commands, possibly without invoking cmd.
how MITRE says to see it
Indirect Command Execution – Windows utility abuse behavior chain
- Cause→effect chain: (1) A user or service launches an indirection utility (e.g., forfiles.exe, pcalua.exe, wsl.exe, scriptrunner.exe, ssh.exe with -o ProxyCommand/LocalCommand).