Command Injection
Command injection occurs when application input is incorporated into an operating-system command in a way that lets data alter command execution.
Mechanism
A server passes untrusted input into a shell or command interpreter instead of using a fixed executable with structured arguments.
Indicators to watch
Unexpected child processes, shell interpreters spawned by web services, unusual command-line arguments, abnormal process trees, and access to unexpected files or network destinations.
Concept diagram
Defensive controls
Avoid shell invocation when possible, use fixed APIs and argument arrays, strict allow-lists, least privilege, sandboxing, EDR monitoring, and application isolation.
Recommended security control
EDR / Sysmon process-tree monitoring
Use a local sandbox and benign commands when learning detection.
Defense tool
The administrator has not attached a tool yet. This slot will show “Build Soon” until a link or file is configured.
All attack descriptions are for defensive education. Test scanning, traffic generation, interception, wireless testing, and vulnerable applications only on systems and networks you own or are explicitly authorized to assess.