Skip to content

Hide Navigation Hide TOC

Shell Evasion Subshell and Command Substitution Injection - ATR-2026-01610 (aed6cefe-894c-525b-bbb4-0f7c59cf6912)

Detects shell command injection using subshell expansion techniques that evade simple keyword filters: backtick substitution (command), dollar-paren substitution ($(command)), Perl/Ruby interpolated execution (@{[system "cmd"]}), and PowerShell inline execution. These evasion forms are commonly embedded in user-supplied strings to exploit agents that pass input to shell-executing tools without stripping shell metacharacters. The BLNS (Big List of Naughty Strings) includes many of these patterns as documented injection vectors.

Cluster A Galaxy A Cluster B Galaxy B Level
Shell Evasion Subshell and Command Substitution Injection - ATR-2026-01610 (aed6cefe-894c-525b-bbb4-0f7c59cf6912) Agent Threat Rules Command and Scripting Interpreter - T1059 (7385dfaf-6886-4229-9ecd-6fd678040830) Attack Pattern 1
Shell Evasion Subshell and Command Substitution Injection - ATR-2026-01610 (aed6cefe-894c-525b-bbb4-0f7c59cf6912) Agent Threat Rules Command and Scripting Interpreter (716d3a6b-2f8c-4a1f-85f7-d884bb7b2800) MITRE ATLAS Attack Pattern 1