Skip to content

Hide Navigation Hide TOC

Shell Evasion Eval and Language-Level Exec Injection - ATR-2026-01611 (4fe78d7b-9788-5ec7-a985-a25b64ef56dd)

Detects language-level eval/exec injection evasion techniques used when direct shell metacharacters would be caught. Patterns include: Ruby's eval("...") and Kernel.exec("..."), Python's eval()/exec()/os.system(), JavaScript's eval()/Function() constructor, and shell's eval statement. These allow arbitrary command execution through language interpreters rather than direct shell expansion, bypassing filters that only inspect for shell metacharacters like $() or backticks.

Cluster A Galaxy A Cluster B Galaxy B Level
Command and Scripting Interpreter - T1059 (7385dfaf-6886-4229-9ecd-6fd678040830) Attack Pattern Shell Evasion Eval and Language-Level Exec Injection - ATR-2026-01611 (4fe78d7b-9788-5ec7-a985-a25b64ef56dd) Agent Threat Rules 1
Shell Evasion Eval and Language-Level Exec Injection - ATR-2026-01611 (4fe78d7b-9788-5ec7-a985-a25b64ef56dd) Agent Threat Rules Command and Scripting Interpreter (716d3a6b-2f8c-4a1f-85f7-d884bb7b2800) MITRE ATLAS Attack Pattern 1