T1059 — Command and Scripting Interpreter
MITRE ATT&CK technique observed against the OffSeq honeypot fleet
Last 7 days · #10 most-observed technique · last seen 3 minutes ago
11,387
Observed attacks
185
Distinct source IPs
The #10 most-observed ATT&CK technique across captured attacks.
Command execution via a scripting interpreter after gaining access. OffSeq honeypots observed this technique in 11,387 attacks from 185 distinct source IPs over the last 7 days.
Top CVEs exploited across the fleet (last 7 days)
Fleet-wide, not scoped to T1059.
- CVE-2019-0708501
- CVE-2024-4577479
- CVE-2021-26855479
- CVE-2017-9841401
- CVE-2017-0144252
- CVE-2025-324890