The sub-techniques beta is now live! Read the release blog post for more info.


cmd is the Windows command-line interpreter that can be used to interact with systems and execute other processes and utilities. [1]

Cmd.exe contains native functionality to perform many operations to interact with the system, including listing files in a directory (e.g., dir [2]), deleting files (e.g., del [3]), and copying files (e.g., copy [4]).

ID: S0106
Associated Software: cmd.exe
Type: TOOL
Platforms: Windows
Version: 1.0
Created: 31 May 2017
Last Modified: 17 October 2018

Techniques Used

Domain ID Name Use
Enterprise T1059 Command-Line Interface

cmd is used to execute programs and other actions at the command-line interface.[1]

Enterprise T1083 File and Directory Discovery

cmd can be used to find files and directories with native functionality such as dir commands.[2]

Enterprise T1107 File Deletion

cmd can be used to delete files from the file system.[3]

Enterprise T1105 Remote File Copy

cmd can be used to copy files to a remotely connected system.[4]

Enterprise T1082 System Information Discovery

cmd can be used to find information about the operating system.[2]

Groups That Use This Software

ID Name References
G0072 Honeybee [6]
G0026 APT18 [7]
G0071 Orangeworm [8]
G0045 menuPass [9]
G0093 Soft Cell [10]