Adversaries may abuse Python commands and scripts for execution. Python is a very popular scripting/programming language, with capabilities to perform many functions. Python can be executed interactively from the command-line (via the python.exe interpreter) or via scripts (.py) that can be written and distributed to different systems. Python code can also be compiled into binary executables.(Citation: Zscaler APT31 Covid-19 October 2020) Python comes with many built-in packages to interact with the underlying system, such as file operations and device I/O. Adversaries can use these libraries to download and execute commands or other scripts as well as perform various malicious behaviors.

Linked Issues

Issuelinks
Linktype Issue
is related to Techniques
is blocked by Audit
is blocked by Antivirus/Antimalware
is blocked by Limit Software Installation
is blocked by Execution Prevention
is blocked by Cross-Platform Behavioral Detection of Python Execution
is blocked by Configuration Change Control
is blocked by Access Restriction For Change
is blocked by Secure Baseline Configurations
is blocked by User-Installed Software
is blocked by Continuous Monitoring
is blocked by Malicious Code Protection (Anti-Malware)
is blocked by Endpoint File Integrity Monitoring (FIM)
is blocked by Account Management
is blocked by Access Enforcement
is blocked by Least Privilege
is blocked by Remote Access
is blocked by Memory Protection
is blocked by Input Data Validation
is blocked by Software & Firmware Patching
Impressum German English