{"id":"T1059.003","name":"Windows Command Shell","url":"https://attack.mitre.org/techniques/T1059/003","tactics":["execution"],"platforms":["Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0202","stix_id":"x-mitre-detection-strategy--1806ad13-6fa8-4cb0-9d91-c8a989a1d9fe","name":"Behavioral Detection of Windows Command Shell Execution","url":"https://attack.mitre.org/detectionstrategies/DET0202","analytics":[{"id":"AN0578","stix_id":"x-mitre-analytic--60d70569-0d28-4d98-957c-4676b2411685","name":"Analytic 0578","description":"Detects interactive or scripted abuse of cmd.exe, batch files, or shell invocation chains. Focuses on parent-child relationships (e.g., cmd.exe launched from unusual parents), anomalous command-line parameters, and chaining with discovery, credential access, or lateral movement behaviors.","url":"https://attack.mitre.org/detectionstrategies/DET0202#AN0578","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Security","channel":"EventCode=4688","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:Sysmon","channel":"EventCode=7","data_component":"DC0016","data_component_name":"Module Load","log_source_slug":"wineventlog-sysmon"},{"name":"EDR:scriptblock","channel":"Process Tree + Script Block Logging","data_component":"DC0029","data_component_name":"Script Execution","log_source_slug":"edr-scriptblock"}],"mutable_elements":[{"field":"ParentProcessName","description":"Cmd.exe launched from uncommon parents (e.g., msedge.exe, winword.exe) may indicate abuse."},{"field":"TimeWindow","description":"Cmd or .bat execution during non-working hours may indicate automation or C2 activity."},{"field":"CommandLinePattern","description":"Flags suspicious switches (e.g., /c ping, /k whoami) or command chaining (&&, ^)."},{"field":"ScriptStoragePath","description":"Batch file execution from %TEMP%, C:\\Users\\Public, or external drives."},{"field":"UserContext","description":"Flags admin-level users executing cmd outside expected baselines."}],"live":true,"detection_strategies":["DET0202"],"techniques":["T1059.003"]}],"live":true,"version":"1.0","techniques":["T1059.003"]}],"sigma_rules":[{"id":"00ca75ab-d5ce-43be-b86c-55ff39c6abfc","title":"Headless Process Launched Via Conhost.EXE","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2024-07-23","modified":null,"description":"Detects the launch of a child process via \"conhost.exe\" with the \"--headless\" flag.\nThe \"--headless\" flag hides the windows from the user upon execution.\n","references":["https://www.huntress.com/blog/fake-browser-updates-lead-to-boinc-volunteer-computing-software"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.execution","attack.t1059.001","attack.t1059.003","detection.threat-hunting"],"path":"rules-threat-hunting/windows/process_creation/proc_creation_win_conhost_headless_execution.yml","techniques":["T1059.001","T1059.003"],"cves":[]},{"id":"023394c4-29d5-46ab-92b8-6a534c6f447b","title":"Suspicious HWP Sub Processes","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2019-10-24","modified":"2021-11-27","description":"Detects suspicious Hangul Word Processor (Hanword) sub processes that could indicate an exploitation","references":["https://www.securitynewspaper.com/2016/11/23/technical-teardown-exploit-malware-hwp-files/","https://www.hybrid-analysis.com/search?query=context:74940dcc5b38f9f9b1a0fea760d344735d7d91b610e6d5bd34533dd0153402c5&from_sample=5db135000388385a7644131f&block_redirect=1","https://twitter.com/cyberwar_15/status/1187287262054076416","https://blog.alyac.co.kr/1901","https://en.wikipedia.org/wiki/Hangul_(word_processor)"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.initial-access","attack.t1566.001","attack.execution","attack.t1203","attack.t1059.003","attack.g0032"],"path":"rules/windows/process_creation/proc_creation_win_hwp_exploits.yml","techniques":["T1566.001","T1203","T1059.003"],"cves":[]},{"id":"056c7317-9a09-4bd4-9067-d051312752ea","title":"Powershell Executed From Headless ConHost Process","author":"Matt Anderson (Huntress)","status":"test","level":"medium","date":"2024-07-23","modified":null,"description":"Detects the use of powershell commands from headless ConHost window.\nThe \"--headless\" flag hides the windows from the user upon execution.\n","references":["https://www.huntress.com/blog/fake-browser-updates-lead-to-boinc-volunteer-computing-software"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.execution","attack.stealth","attack.t1059.001","attack.t1059.003","attack.t1564.003"],"path":"rules/windows/process_creation/proc_creation_win_conhost_headless_powershell.yml","techniques":["T1059.001","T1059.003","T1564.003"],"cves":[]},{"id":"058f4380-962d-40a5-afce-50207d36d7e2","title":"HackTool - CrackMapExec Execution Patterns","author":"Thomas Patzke","status":"stable","level":"high","date":"2020-05-22","modified":"2023-11-06","description":"Detects various execution patterns of the CrackMapExec pentesting framework","references":["https://github.com/byt3bl33d3r/CrackMapExec"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.privilege-escalation","attack.persistence","attack.execution","attack.t1047","attack.t1053","attack.t1059.003","attack.t1059.001","attack.s0106"],"path":"rules/windows/process_creation/proc_creation_win_hktl_crackmapexec_execution_patterns.yml","techniques":["T1047","T1053","T1059.003","T1059.001"],"cves":[]},{"id":"076ebe48-cc05-4d8f-9d41-89245cd93a14","title":"Remote Access Tool - ScreenConnect Command Execution","author":"Ali Alwashali","status":"test","level":"low","date":"2023-10-10","modified":null,"description":"Detects command execution via ScreenConnect RMM","references":["https://www.huntandhackett.com/blog/revil-the-usage-of-legitimate-remote-admin-tooling","https://github.com/SigmaHQ/sigma/pull/4467"],"logsource":{"product":"windows","service":"application"},"tags":["attack.execution","attack.t1059.003"],"path":"rules/windows/builtin/application/screenconnect/win_app_remote_access_tools_screenconnect_command_exec.yml","techniques":["T1059.003"],"cves":[]},{"id":"087790e3-3287-436c-bccf-cbd0184a7db1","title":"Potential CommandLine Path Traversal Via Cmd.EXE","author":"xknow @xknow_infosec, Tim Shelton","status":"test","level":"high","date":"2020-06-11","modified":"2023-03-06","description":"Detects potential path traversal attempt via cmd.exe. Could indicate possible command/argument confusion/hijacking","references":["https://hackingiscool.pl/cmdhijack-command-argument-confusion-with-path-traversal-in-cmd-exe/","https://twitter.com/Oddvarmoe/status/1270633613449723905"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.execution","attack.t1059.003"],"path":"rules/windows/process_creation/proc_creation_win_cmd_path_traversal.yml","techniques":["T1059.003"],"cves":[]},{"id":"0a99eb3e-1617-41bd-b095-13dc767f3def","title":"HackTool - Jlaive In-Memory Assembly Execution","author":"Jose Luis Sanchez Martinez (@Joseliyo_Jstnk)","status":"test","level":"medium","date":"2022-05-24","modified":"2023-02-22","description":"Detects the use of Jlaive to execute assemblies in a copied PowerShell","references":["https://jstnk9.github.io/jstnk9/research/Jlaive-Antivirus-Evasion-Tool","https://web.archive.org/web/20220514073704/https://github.com/ch2sh/Jlaive"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.execution","attack.t1059.003"],"path":"rules/windows/process_creation/proc_creation_win_hktl_jlaive_batch_execution.yml","techniques":["T1059.003"],"cves":[]},{"id":"0afecb6e-6223-4a82-99fb-bf5b981e92a5","title":"Remote Access Tool - ScreenConnect Temporary File","author":"Ali Alwashali","status":"test","level":"low","date":"2023-10-10","modified":null,"description":"Detects the creation of files in a specific location by ScreenConnect RMM.\nScreenConnect has feature to remotely execute binaries on a target machine. These binaries will be dropped to \":\\Users\\<username>\\Documents\\ConnectWiseControl\\Temp\\\" before execution.\n","references":["https://github.com/SigmaHQ/sigma/pull/4467"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.execution","attack.t1059.003"],"path":"rules/windows/file/file_event/file_event_win_remote_access_tools_screenconnect_remote_file.yml","techniques":["T1059.003"],"cves":[]},{"id":"0e9e6c63-1350-48c4-9fa1-7ccb235edc68","title":"Rorschach Ransomware Execution Activity","author":"X__Junior (Nextron Systems)","status":"test","level":"critical","date":"2023-04-04","modified":"2023-04-22","description":"Detects Rorschach ransomware execution activity","references":["https://research.checkpoint.com/2023/rorschach-a-new-sophisticated-and-fast-ransomware/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.execution","attack.t1059.003","attack.t1059.001","detection.emerging-threats"],"path":"rules-emerging-threats/2023/Malware/Rorschach/proc_creation_win_malware_rorschach_ransomware_activity.yml","techniques":["T1059.003","T1059.001"],"cves":[]},{"id":"0fdc7c7f-c690-4217-9ae3-31f5156eed72","title":"Potential Exploitation of CrushFTP RCE Vulnerability (CVE-2025-54309)","author":"Nisarg Suthar","status":"experimental","level":"high","date":"2025-08-01","modified":null,"description":"Detects suspicious child processes created by CrushFTP. It could be an indication of exploitation of a RCE vulnerability such as CVE-2025-54309.","references":["https://reliaquest.com/blog/threat-spotlight-cve-2025-54309-crushftp-exploit/","https://pwn.guide/free/web/crushftp","https://firecompass.com/crushftp-vulnerability-cve-2025-54309-securing-file-transfer-services/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.privilege-escalation","attack.initial-access","attack.execution","attack.t1059.001","attack.t1059.003","attack.t1068","attack.t1190","cve.2025-54309","detection.emerging-threats"],"path":"rules-emerging-threats/2025/Exploits/CVE-2025-54309/proc_creation_win_exploit_cve_2025_54309.yml","techniques":["T1059.001","T1059.003","T1068","T1190"],"cves":["CVE-2025-54309"]},{"id":"1ab3c5ed-5baf-417b-bb6b-78ca33f6c3df","title":"AWS EC2 Startup Shell Script Change","author":"faloker","status":"test","level":"high","date":"2020-02-12","modified":"2022-06-07","description":"Detects changes to the EC2 instance startup script. The shell script will be executed as root/SYSTEM every time the specific instances are booted up.","references":["https://github.com/RhinoSecurityLabs/pacu/blob/866376cd711666c775bbfcde0524c817f2c5b181/pacu/modules/ec2__startup_shell_script/main.py#L9"],"logsource":{"product":"aws","service":"cloudtrail"},"tags":["attack.execution","attack.t1059.001","attack.t1059.003","attack.t1059.004"],"path":"rules/cloud/aws/cloudtrail/aws_ec2_startup_script_change.yml","techniques":["T1059.001","T1059.003","T1059.004"],"cves":[]},{"id":"1ac8666b-046f-4201-8aba-1951aaec03a3","title":"Command Line Execution with Suspicious URL and AppData Strings","author":"Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community","status":"test","level":"medium","date":"2019-01-16","modified":"2021-11-27","description":"Detects a suspicious command line execution that includes an URL and AppData string in the command line parameters as used by several droppers (js/vbs > powershell)","references":["https://www.hybrid-analysis.com/sample/3a1f01206684410dbe8f1900bbeaaa543adfcd07368ba646b499fa5274b9edf6?environmentId=100","https://www.hybrid-analysis.com/sample/f16c729aad5c74f19784a24257236a8bbe27f7cdc4a89806031ec7f1bebbd475?environmentId=100"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.execution","attack.command-and-control","attack.t1059.003","attack.t1059.001","attack.t1105"],"path":"rules/windows/process_creation/proc_creation_win_cmd_http_appdata.yml","techniques":["T1059.003","T1059.001","T1105"],"cves":[]},{"id":"1c373b6d-76ce-4553-997d-8c1da9a6b5f5","title":"Exploiting SetupComplete.cmd CVE-2019-1378","author":"Florian Roth (Nextron Systems), oscd.community, Jonhnathan Ribeiro","status":"test","level":"high","date":"2019-11-15","modified":"2021-11-27","description":"Detects exploitation attempt of privilege escalation vulnerability via SetupComplete.cmd and PartnerSetupComplete.cmd described in CVE-2019-1378","references":["https://web.archive.org/web/20200530031708/https://www.embercybersecurity.com/blog/cve-2019-1378-exploiting-an-access-control-privilege-escalation-vulnerability-in-windows-10-update-assistant-wua"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.persistence","attack.privilege-escalation","attack.stealth","attack.t1068","attack.execution","attack.t1059.003","attack.t1574","cve.2019-1378","detection.emerging-threats"],"path":"rules-emerging-threats/2019/Exploits/CVE-2019-1378/proc_creation_win_exploit_cve_2019_1378.yml","techniques":["T1068","T1059.003","T1574"],"cves":["CVE-2019-1378"]},{"id":"241e802a-b65e-484f-88cd-c2dc10f9206d","title":"Read Contents From Stdin Via Cmd.EXE","author":"frack113, Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2023-03-07","modified":null,"description":"Detect the use of \"<\" to read and potentially execute a file via cmd.exe","references":["https://github.com/redcanaryco/atomic-red-team/blob/40b77d63808dd4f4eafb83949805636735a1fd15/atomics/T1059.003/T1059.003.md","https://web.archive.org/web/20220306121156/https://www.x86matthew.com/view_post?id=ntdll_pipe"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.execution","attack.t1059.003"],"path":"rules/windows/process_creation/proc_creation_win_cmd_stdin_redirect.yml","techniques":["T1059.003"],"cves":[]},{"id":"2782fbd8-b662-4eb5-9962-5bfbfb671e7b","title":"Suspicious Usage of For Loop with Recursive Directory Search in CMD","author":"Joseliyo Sanchez, @Joseliyo_Jstnk","status":"experimental","level":"medium","date":"2025-11-12","modified":null,"description":"Detects suspicious usage of the cmd.exe 'for /f' loop combined with the 'tokens=' parameter and a recursive directory listing.\nThis pattern may indicate an attempt to discover and execute system binaries dynamically, for example powershell, a technique sometimes used by attackers to evade detection.\nThis behavior has been observed in various malicious lnk files.\n","references":["https://www.virustotal.com/gui/file/29837d0d3202758063185828c8f8d9e0b7b42b365c8941cc926d2d7c7bae2fb3"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.execution","attack.stealth","attack.t1059.003","attack.t1027.010"],"path":"rules/windows/process_creation/proc_creation_win_susp_cmd_for_loop_execution_with_recursive_directory_search.yml","techniques":["T1059.003","T1027.010"],"cves":[]},{"id":"2b30fa36-3a18-402f-a22d-bf4ce2189f35","title":"Potential Baby Shark Malware Activity","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2019-02-24","modified":"2023-03-08","description":"Detects activity that could be related to Baby Shark malware","references":["https://unit42.paloaltonetworks.com/new-babyshark-malware-targets-u-s-national-security-think-tanks/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.execution","attack.discovery","attack.stealth","attack.t1012","attack.t1059.003","attack.t1059.001","attack.t1218.005","detection.emerging-threats"],"path":"rules-emerging-threats/2019/Malware/BabyShark/proc_creation_win_malware_babyshark.yml","techniques":["T1012","T1059.003","T1059.001","T1218.005"],"cves":[]},{"id":"2d79e371-2a27-42de-87a4-b4213fc72a6a","title":"Suspicious Process Spawned by CentreStack Portal AppPool","author":"Jason Rathbun (Blackpoint Cyber)","status":"experimental","level":"high","date":"2025-04-17","modified":null,"description":"Detects unexpected command shell execution (cmd.exe) from w3wp.exe when tied to CentreStack's portal.config, indicating potential exploitation (e.g., CVE-2025-30406)\n","references":["https://nvd.nist.gov/vuln/detail/CVE-2025-30406","https://blackpointcyber.com/blog/racing-to-exploit-centrestacks-cve-2025-30406/","https://gladinetsupport.s3.us-east-1.amazonaws.com/gladinet/securityadvisory-cve-2005.pdf","https://www.bleepingcomputer.com/news/security/centrestack-rce-exploited-as-zero-day-to-breach-file-sharing-servers/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.persistence","attack.execution","attack.t1059.003","attack.t1505.003","cve.2025-30406","detection.emerging-threats"],"path":"rules-emerging-threats/2025/Exploits/CVE-2025-30406/proc_creation_win_exploit_cve_2025_30406_centrestack_portal_child_process.yml","techniques":["T1059.003","T1505.003"],"cves":["CVE-2025-30406"]},{"id":"2fdaf50b-9fd5-449f-ba69-f17248119af6","title":"Network Connection Initiated via Finger.EXE","author":"Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"high","date":"2025-11-19","modified":null,"description":"Detects network connections via finger.exe, which can be abused by threat actors to retrieve remote commands for execution on Windows devices.\nIn one ClickFix malware campaign, adversaries leveraged the finger protocol to fetch commands from a remote server.\nSince the finger utility is not commonly used in modern Windows environments, its presence already raises suspicion.\nInvestigating such network connections can also help identify potential malicious infrastructure used by threat actors\n","references":["https://www.bleepingcomputer.com/news/security/decades-old-finger-protocol-abused-in-clickfix-malware-attacks/"],"logsource":{"product":"windows","category":"network_connection"},"tags":["attack.command-and-control","attack.t1071.004","attack.execution","attack.t1059.003"],"path":"rules/windows/network_connection/net_connection_win_finger.yml","techniques":["T1071.004","T1059.003"],"cves":[]},{"id":"401e5d00-b944-11ea-8f9a-00163ecd60ae","title":"AppLocker Prevented Application or Script from Running","author":"Pushkarev Dmitry","status":"test","level":"medium","date":"2020-06-28","modified":"2025-12-03","description":"Detects when AppLocker prevents the execution of an Application, DLL, Script, MSI, or Packaged-App from running.\n","references":["https://learn.microsoft.com/en-us/windows/security/application-security/application-control/windows-defender-application-control/applocker/what-is-applocker","https://learn.microsoft.com/en-us/windows/security/application-security/application-control/windows-defender-application-control/applocker/using-event-viewer-with-applocker","https://nxlog.co/documentation/nxlog-user-guide/applocker.html"],"logsource":{"product":"windows","service":"applocker"},"tags":["attack.execution","attack.t1204.002","attack.t1059.001","attack.t1059.003","attack.t1059.005","attack.t1059.006","attack.t1059.007"],"path":"rules/windows/builtin/applocker/win_applocker_application_was_prevented_from_running.yml","techniques":["T1204.002","T1059.001","T1059.003","T1059.005","T1059.006","T1059.007"],"cves":[]},{"id":"42a993dd-bb3e-48c8-b372-4d6684c4106c","title":"HackTool - CrackMapExec Execution","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2022-02-25","modified":"2023-03-08","description":"This rule detect common flag combinations used by CrackMapExec in order to detect its use even if the binary has been replaced.","references":["https://mpgn.gitbook.io/crackmapexec/smb-protocol/authentication/checking-credentials-local","https://www.mandiant.com/resources/telegram-malware-iranian-espionage","https://www.infosecmatter.com/crackmapexec-module-library/?cmem=mssql-mimikatz","https://www.infosecmatter.com/crackmapexec-module-library/?cmem=smb-pe_inject"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.execution","attack.persistence","attack.privilege-escalation","attack.credential-access","attack.discovery","attack.t1047","attack.t1053","attack.t1059.003","attack.t1059.001","attack.t1110","attack.t1201"],"path":"rules/windows/process_creation/proc_creation_win_hktl_crackmapexec_execution.yml","techniques":["T1047","T1053","T1059.003","T1059.001","T1110","T1201"],"cves":[]},{"id":"459628e3-1b00-4e9b-9e5b-7da8961aea35","title":"Suspicious CrushFTP Child Process","author":"Craig Sweeney, Matt Anderson, Jose Oregon, Tim Kasper, Faith Stratton, Samantha Shaw, Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"medium","date":"2025-04-10","modified":null,"description":"Detects suspicious child processes spawned by the CrushFTP service that may indicate exploitation of remote code execution vulnerabilities such as\nCVE-2025-31161, where attackers can achieve RCE through crafted HTTP requests.\nThe detection focuses on commonly abused Windows executables (like powershell.exe, cmd.exe etc.) that attackers typically use post-exploitation to execute malicious commands.\n","references":["https://nvd.nist.gov/vuln/detail/CVE-2025-2825","https://www.crushftp.com/crush11wiki/Wiki.jsp?page=Update","https://outpost24.com/blog/crushftp-auth-bypass-vulnerability/","https://attackerkb.com/topics/k0EgiL9Psz/cve-2025-2825/rapid7-analysis","https://projectdiscovery.io/blog/crushftp-authentication-bypass"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.initial-access","attack.execution","attack.t1059.001","attack.t1059.003","attack.t1190","cve.2025-31161","detection.emerging-threats"],"path":"rules-emerging-threats/2025/Exploits/CVE-2025-31161/proc_creation_win_crushftp_susp_child_processes.yml","techniques":["T1059.001","T1059.003","T1190"],"cves":["CVE-2025-31161"]},{"id":"4f154fb6-27d1-4813-a759-78b93e0b9c48","title":"Operator Bloopers Cobalt Strike Modules","author":"_pete_0, TheDFIRReport","status":"test","level":"high","date":"2022-05-06","modified":"2023-01-30","description":"Detects Cobalt Strike module/commands accidentally entered in CMD shell","references":["https://hstechdocs.helpsystems.com/manuals/cobaltstrike/current/userguide/content/cobalt-4-5-user-guide.pdf","https://thedfirreport.com/2021/10/04/bazarloader-and-the-conti-leaks/","https://thedfirreport.com/2022/06/16/sans-ransomware-summit-2022-can-you-detect-this/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.execution","attack.t1059.003"],"path":"rules/windows/process_creation/proc_creation_win_hktl_cobaltstrike_bloopers_modules.yml","techniques":["T1059.003"],"cves":[]},{"id":"52cad028-0ff0-4854-8f67-d25dfcbc78b4","title":"HTML Help HH.EXE Suspicious Child Process","author":"Maxim Pavlunin, Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2020-04-01","modified":"2023-04-12","description":"Detects a suspicious child process of a Microsoft HTML Help (HH.exe)","references":["https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/chm-badness-delivers-a-banking-trojan/","https://github.com/elastic/protections-artifacts/commit/746086721fd385d9f5c6647cada1788db4aea95f#diff-27939090904026cc396b0b629c8e4314acd6f5dac40a676edbc87f4567b47eb7","https://www.ptsecurity.com/ww-en/analytics/pt-esc-threat-intelligence/higaisa-or-winnti-apt-41-backdoors-old-and-new/","https://www.zscaler.com/blogs/security-research/unintentional-leak-glimpse-attack-vectors-apt37"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.execution","attack.initial-access","attack.stealth","attack.t1047","attack.t1059.001","attack.t1059.003","attack.t1059.005","attack.t1059.007","attack.t1218","attack.t1218.001","attack.t1218.010","attack.t1218.011","attack.t1566","attack.t1566.001"],"path":"rules/windows/process_creation/proc_creation_win_hh_html_help_susp_child_process.yml","techniques":["T1047","T1059.001","T1059.003","T1059.005","T1059.007","T1218","T1218.001","T1218.010","T1218.011","T1566","T1566.001"],"cves":[]},{"id":"557e3bd3-7f21-495d-8d50-7c8bdfb8041c","title":"AppLocker Application Would Have Been Blocked","author":"heyyanu","status":"experimental","level":"medium","date":"2026-03-26","modified":null,"description":"Detects when AppLocker \"Audit only\" enforcement mode reports that an Application, DLL, Script, MSI, or Packaged-App would have been blocked if AppLocker \"Enforce rules\" enforcement mode was enabled.\n","references":["https://learn.microsoft.com/en-us/windows/security/application-security/application-control/windows-defender-application-control/applocker/what-is-applocker","https://learn.microsoft.com/en-us/windows/security/application-security/application-control/windows-defender-application-control/applocker/using-event-viewer-with-applocker","https://www.splunk.com/en_us/blog/security/deploy-test-monitor-mastering-microsoft-applocker-part-2.html","https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-r2-and-2012/ee844150(v=ws.11)"],"logsource":{"product":"windows","service":"applocker"},"tags":["attack.execution","attack.t1204.002","attack.t1059.001","attack.t1059.003","attack.t1059.005","attack.t1059.006","attack.t1059.007"],"path":"rules/windows/builtin/applocker/win_applocker_application_would_have_been_blocked.yml","techniques":["T1204.002","T1059.001","T1059.003","T1059.005","T1059.006","T1059.007"],"cves":[]},{"id":"5b304bcb-ac33-49d0-87af-fa1b3ca94333","title":"Suspicious Child Process of SAP NetWeaver","author":"Elastic (idea), Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"medium","date":"2025-04-28","modified":null,"description":"Detects suspicious child processes spawned by SAP NetWeaver that could indicate potential\nexploitation of vulnerability that allows arbitrary execution via webshells such as CVE-2025-31324.\n","references":["https://reliaquest.com/blog/threat-spotlight-reliaquest-uncovers-vulnerability-behind-sap-netweaver-compromise/","https://onapsis.com/blog/active-exploitation-of-sap-vulnerability-cve-2025-31324/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.execution","attack.initial-access","attack.t1190","attack.persistence","attack.t1059.003","cve.2025-31324","detection.emerging-threats"],"path":"rules-emerging-threats/2025/Exploits/CVE-2025-31324/proc_creation_win_sap_netweaver_susp_child_process.yml","techniques":["T1190","T1059.003"],"cves":["CVE-2025-31324"]},{"id":"5b91409c-cb18-4ab6-ac75-c5759f998409","title":"Potential SAP NetWeaver Webshell Creation - Linux","author":"Elastic (idea), Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"medium","date":"2025-04-28","modified":null,"description":"Detects the creation of suspicious files (jsp, java, class) in SAP NetWeaver directories,\nwhich may indicate exploitation attempts of vulnerabilities such as CVE-2025-31324.\n","references":["https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-31324","https://reliaquest.com/blog/threat-spotlight-reliaquest-uncovers-vulnerability-behind-sap-netweaver-compromise/","https://onapsis.com/blog/active-exploitation-of-sap-vulnerability-cve-2025-31324/"],"logsource":{"product":"linux","category":"file_event"},"tags":["attack.execution","attack.initial-access","attack.t1190","attack.persistence","attack.t1059.003","cve.2025-31324","detection.emerging-threats"],"path":"rules-emerging-threats/2025/Exploits/CVE-2025-31324/file_event_lnx_sap_netweaver_webshell_creation.yml","techniques":["T1190","T1059.003"],"cves":["CVE-2025-31324"]},{"id":"5cddf373-ef00-4112-ad72-960ac29bac34","title":"HackTool - Koadic Execution","author":"wagga, Jonhnathan Ribeiro, oscd.community","status":"test","level":"high","date":"2020-01-12","modified":"2023-02-11","description":"Detects command line parameters used by Koadic hack tool","references":["https://unit42.paloaltonetworks.com/unit42-sofacy-groups-parallel-attacks/","https://github.com/offsecginger/koadic/blob/457f9a3ff394c989cdb4c599ab90eb34fb2c762c/data/stager/js/stdlib.js","https://blog.f-secure.com/hunting-for-koadic-a-com-based-rootkit/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.execution","attack.t1059.003","attack.t1059.005","attack.t1059.007"],"path":"rules/windows/process_creation/proc_creation_win_hktl_koadic.yml","techniques":["T1059.003","T1059.005","T1059.007"],"cves":[]},{"id":"5d19eb78-5b5b-4ef2-a9f0-4bfa94d58a13","title":"Remote Access Tool - ScreenConnect File Transfer","author":"Ali Alwashali","status":"test","level":"low","date":"2023-10-10","modified":null,"description":"Detects file being transferred via ScreenConnect RMM","references":["https://www.huntandhackett.com/blog/revil-the-usage-of-legitimate-remote-admin-tooling","https://github.com/SigmaHQ/sigma/pull/4467"],"logsource":{"product":"windows","service":"application"},"tags":["attack.execution","attack.t1059.003"],"path":"rules/windows/builtin/application/screenconnect/win_app_remote_access_tools_screenconnect_file_transfer.yml","techniques":["T1059.003"],"cves":[]},{"id":"647c7b9e-d784-4fda-b9a0-45c565a7b729","title":"Operator Bloopers Cobalt Strike Commands","author":"_pete_0, TheDFIRReport","status":"test","level":"high","date":"2022-05-06","modified":"2023-01-30","description":"Detects use of Cobalt Strike commands accidentally entered in the CMD shell","references":["https://hstechdocs.helpsystems.com/manuals/cobaltstrike/current/userguide/content/cobalt-4-5-user-guide.pdf","https://thedfirreport.com/2021/10/04/bazarloader-and-the-conti-leaks/","https://thedfirreport.com/2022/06/16/sans-ransomware-summit-2022-can-you-detect-this/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.execution","attack.t1059.003","stp.1u"],"path":"rules/windows/process_creation/proc_creation_win_hktl_cobaltstrike_bloopers_cmd.yml","techniques":["T1059.003"],"cves":[]},{"id":"6676896b-2cce-422d-82af-5a1abe65e241","title":"Potential APT FIN7 Exploitation Activity","author":"Alex Walston (@4ayymm)","status":"test","level":"medium","date":"2024-07-29","modified":null,"description":"Detects potential APT FIN7 exploitation activity as reported by Google.\nIn order to obtain initial access, FIN7 used compromised Remote Desktop Protocol (RDP) credentials to login to a target server and initiate specific Windows process chains.\n","references":["https://cloud.google.com/blog/topics/threat-intelligence/evolution-of-fin7/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.execution","attack.t1059.001","attack.t1059.003","detection.emerging-threats"],"path":"rules-emerging-threats/2024/TA/FIN7/proc_creation_win_apt_fin7_exploitation_indicators.yml","techniques":["T1059.001","T1059.003"],"cves":[]},{"id":"69dea60b-2deb-4c9e-a685-ad542f4367f9","title":"Suspicious Child Process of SAP NetWeaver - Linux","author":"Elastic (idea), Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"medium","date":"2025-04-28","modified":null,"description":"Detects suspicious child processes spawned by SAP NetWeaver on Linux systems that could indicate potential\nexploitation of vulnerability that allows arbitrary execution via webshells such as CVE-2025-31324.\n","references":["https://reliaquest.com/blog/threat-spotlight-reliaquest-uncovers-vulnerability-behind-sap-netweaver-compromise/","https://onapsis.com/blog/active-exploitation-of-sap-vulnerability-cve-2025-31324/"],"logsource":{"product":"linux","category":"process_creation"},"tags":["attack.execution","attack.initial-access","attack.t1190","attack.persistence","attack.t1059.003","cve.2025-31324","detection.emerging-threats"],"path":"rules-emerging-threats/2025/Exploits/CVE-2025-31324/proc_creation_lnx_sap_netweaver_susp_child_process.yml","techniques":["T1190","T1059.003"],"cves":["CVE-2025-31324"]},{"id":"7f3a9c2d-4e8b-4a7f-9d3e-5c6f8a9b2e1d","title":"OpenEDR Spawning Command Shell","author":"@kostastsale","status":"experimental","level":"medium","date":"2026-02-19","modified":null,"description":"Detects the OpenEDR ssh-shellhost.exe spawning a command shell (cmd.exe) or PowerShell with PTY (pseudo-terminal) capabilities.\nThis may indicate remote command execution through OpenEDR's remote management features, which could be legitimate administrative activity or potential abuse of the remote access tool.\nThreat actors may leverage OpenEDR's remote shell capabilities to execute commands on compromised systems, facilitating lateral movement or other command-and-control operations.\n","references":["https://kostas-ts.medium.com/detecting-abuse-of-openedrs-permissive-edr-trial-a-security-researcher-s-perspective-fc55bf53972c"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.execution","attack.t1059.003","attack.lateral-movement","attack.t1021.004","attack.command-and-control","attack.t1219"],"path":"rules/windows/process_creation/proc_creation_win_comodo_ssh_shellhost_cmd_spawn.yml","techniques":["T1059.003","T1021.004","T1219"],"cves":[]},{"id":"846b866e-2a57-46ee-8e16-85fa92759be7","title":"Exploited CVE-2020-10189 Zoho ManageEngine","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2020-03-25","modified":"2023-01-21","description":"Detects the exploitation of Zoho ManageEngine Desktop Central Java Deserialization vulnerability reported as CVE-2020-10189","references":["https://www.fireeye.com/blog/threat-research/2020/03/apt41-initiates-global-intrusion-campaign-using-multiple-exploits.html","https://vulmon.com/exploitdetails?qidtp=exploitdb&qid=48224"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.initial-access","attack.t1190","attack.execution","attack.t1059.001","attack.t1059.003","attack.s0190","cve.2020-10189","detection.emerging-threats"],"path":"rules-emerging-threats/2020/Exploits/CVE-2020-10189/proc_creation_win_exploit_cve_2020_10189.yml","techniques":["T1190","T1059.001","T1059.003"],"cves":["CVE-2020-10189"]},{"id":"86a7c91f-98c3-4f14-a58d-d989421e1234","title":"Potential SAP NetWeaver Webshell Creation","author":"Elastic (idea), Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"medium","date":"2025-04-28","modified":null,"description":"Detects the creation of suspicious files (jsp, java, class) in SAP NetWeaver directories,\nwhich may indicate exploitation attempts of vulnerabilities such as CVE-2025-31324.\n","references":["https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-31324","https://reliaquest.com/blog/threat-spotlight-reliaquest-uncovers-vulnerability-behind-sap-netweaver-compromise/","https://onapsis.com/blog/active-exploitation-of-sap-vulnerability-cve-2025-31324/"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.execution","attack.initial-access","attack.t1190","attack.persistence","attack.t1059.003","cve.2025-31324","detection.emerging-threats"],"path":"rules-emerging-threats/2025/Exploits/CVE-2025-31324/file_event_win_sap_netweaver_webshell_creation.yml","techniques":["T1190","T1059.003"],"cves":["CVE-2025-31324"]},{"id":"95022b85-ff2a-49fa-939a-d7b8f56eeb9b","title":"HackTool - RedMimicry Winnti Playbook Execution","author":"Alexander Rausch","status":"test","level":"high","date":"2020-06-24","modified":"2023-03-01","description":"Detects actions caused by the RedMimicry Winnti playbook a automated breach emulations utility","references":["https://redmimicry.com/posts/redmimicry-winnti/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.execution","attack.stealth","attack.t1106","attack.t1059.003","attack.t1218.011"],"path":"rules/windows/process_creation/proc_creation_win_hktl_redmimicry_winnti_playbook.yml","techniques":["T1106","T1059.003","T1218.011"],"cves":[]},{"id":"b1f73849-6329-4069-bc8f-78a604bb8b23","title":"Remote Access Tool - ScreenConnect Remote Command Execution","author":"Ali Alwashali","status":"test","level":"low","date":"2023-10-10","modified":"2024-02-26","description":"Detects the execution of a system command via the ScreenConnect RMM service.","references":["https://github.com/SigmaHQ/sigma/pull/4467"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.execution","attack.t1059.003"],"path":"rules/windows/process_creation/proc_creation_win_remote_access_tools_screenconnect_remote_execution.yml","techniques":["T1059.003"],"cves":[]},{"id":"b5522a23-82da-44e5-9c8b-e10ed8955f88","title":"Powershell Execute Batch Script","author":"frack113","status":"test","level":"medium","date":"2022-01-02","modified":null,"description":"Adversaries may abuse the Windows command shell for execution.\nThe Windows command shell ([cmd](https://attack.mitre.org/software/S0106)) is the primary command prompt on Windows systems.\nThe Windows command prompt can be used to control almost any aspect of a system, with various permission levels required for different subsets of commands.\nBatch files (ex: .bat or .cmd) also provide the shell with a list of sequential commands to run, as well as normal scripting operations such as conditionals and loops.\nCommon uses of batch files include long or repetitive tasks, or the need to run the same set of commands on multiple system\n","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1059.003/T1059.003.md#atomic-test-1---create-and-execute-batch-script"],"logsource":{"product":"windows","category":"ps_script"},"tags":["attack.execution","attack.t1059.003"],"path":"rules/windows/powershell/powershell_script/posh_ps_susp_execute_batch_script.yml","techniques":["T1059.003"],"cves":[]},{"id":"ba778144-5e3d-40cf-8af9-e28fb1df1e20","title":"Sofacy Trojan Loader Activity","author":"Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community","status":"test","level":"high","date":"2018-03-01","modified":"2023-05-31","description":"Detects Trojan loader activity as used by APT28","references":["https://researchcenter.paloaltonetworks.com/2018/02/unit42-sofacy-attacks-multiple-government-entities/","https://www.hybrid-analysis.com/sample/ff808d0a12676bfac88fd26f955154f8884f2bb7c534b9936510fd6296c543e8?environmentId=110","https://twitter.com/ClearskySec/status/960924755355369472"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.execution","attack.stealth","attack.g0007","attack.t1059.003","attack.t1218.011","car.2013-10-002","detection.emerging-threats"],"path":"rules-emerging-threats/2018/TA/APT28/proc_creation_win_apt_sofacy.yml","techniques":["T1059.003","T1218.011"],"cves":[]},{"id":"c082c2b0-525b-4dbc-9a26-a57dc4692074","title":"DNS Query by Finger Utility","author":"Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"high","date":"2025-11-19","modified":null,"description":"Detects DNS queries made by the finger utility, which can be abused by threat actors to retrieve remote commands for execution on Windows devices.\nIn one ClickFix malware campaign, adversaries leveraged the finger protocol to fetch commands from a remote server.\nSince the finger utility is not commonly used in modern Windows environments, its presence already raises suspicion.\nInvestigating such DNS queries can also help identify potential malicious infrastructure used by threat actors for command and control (C2) communication.\n","references":["https://www.bleepingcomputer.com/news/security/decades-old-finger-protocol-abused-in-clickfix-malware-attacks/"],"logsource":{"product":"windows","category":"dns_query"},"tags":["attack.command-and-control","attack.t1071.004","attack.execution","attack.t1059.003"],"path":"rules/windows/dns_query/dns_query_win_finger.yml","techniques":["T1071.004","T1059.003"],"cves":[]},{"id":"d2b749ee-4225-417e-b20e-a8d2193cbb84","title":"PUA - AdvancedRun Execution","author":"Florian Roth (Nextron Systems)","status":"test","level":"medium","date":"2022-01-20","modified":"2023-02-21","description":"Detects the execution of AdvancedRun utility","references":["https://twitter.com/splinter_code/status/1483815103279603714","https://medium.com/s2wblog/analysis-of-destructive-malware-whispergate-targeting-ukraine-9d5d158f19f3","https://www.elastic.co/security-labs/operation-bleeding-bear","https://www.winhelponline.com/blog/run-program-as-system-localsystem-account-windows/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.execution","attack.privilege-escalation","attack.stealth","attack.t1564.003","attack.t1134.002","attack.t1059.003"],"path":"rules/windows/process_creation/proc_creation_win_pua_advancedrun.yml","techniques":["T1564.003","T1134.002","T1059.003"],"cves":[]},{"id":"e507feb7-5f73-4ef6-a970-91bb6f6d744f","title":"Elise Backdoor Activity","author":"Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"critical","date":"2018-01-31","modified":"2023-03-09","description":"Detects Elise backdoor activity used by APT32","references":["https://community.rsa.com/community/products/netwitness/blog/2018/02/13/lotus-blossom-continues-asean-targeting","https://web.archive.org/web/20200302083912/https://www.accenture.com/t20180127T003755Z_w_/us-en/_acnmedia/PDF-46/Accenture-Security-Dragonfish-Threat-Analysis.pdf"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.g0030","attack.g0050","attack.s0081","attack.execution","attack.t1059.003","detection.emerging-threats"],"path":"rules-emerging-threats/2018/Malware/Elise-Backdoor/proc_creation_win_malware_elise.yml","techniques":["T1059.003"],"cves":[]},{"id":"e5144106-8198-4f6e-bfc2-0a551cc8dd94","title":"Potential Pikabot Infection - Suspicious Command Combinations Via Cmd.EXE","author":"Alejandro Houspanossian ('@lekz86')","status":"test","level":"medium","date":"2024-01-02","modified":null,"description":"Detects the execution of concatenated commands via \"cmd.exe\". Pikabot often executes a combination of multiple commands via the command handler \"cmd /c\" in order to download and execute additional payloads.\nCommands such as \"curl\", \"wget\" in order to download extra payloads. \"ping\" and \"timeout\" are abused to introduce delays in the command execution and \"Rundll32\" is also used to execute malicious DLL files.\nIn the observed Pikabot infections, a combination of the commands described above are used to orchestrate the download and execution of malicious DLL files.\n","references":["https://github.com/pr0xylife/Pikabot/blob/7f7723a74ca325ec54c6e61e076acce9a4b20538/Pikabot_30.10.2023.txt","https://github.com/pr0xylife/Pikabot/blob/7f7723a74ca325ec54c6e61e076acce9a4b20538/Pikabot_22.12.2023.txt"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.command-and-control","attack.execution","attack.stealth","attack.t1059.003","attack.t1105","attack.t1218","detection.emerging-threats"],"path":"rules-emerging-threats/2023/Malware/Pikabot/proc_creation_win_malware_pikabot_combined_commands_execution.yml","techniques":["T1059.003","T1105","T1218"],"cves":[]},{"id":"e8a95b5e-c891-46e2-b33a-93937d3abc31","title":"Suspicious HH.EXE Execution","author":"Maxim Pavlunin","status":"test","level":"high","date":"2020-04-01","modified":"2023-04-12","description":"Detects a suspicious execution of a Microsoft HTML Help (HH.exe)","references":["https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/chm-badness-delivers-a-banking-trojan/","https://github.com/elastic/protections-artifacts/commit/746086721fd385d9f5c6647cada1788db4aea95f#diff-27939090904026cc396b0b629c8e4314acd6f5dac40a676edbc87f4567b47eb7","https://www.ptsecurity.com/ww-en/analytics/pt-esc-threat-intelligence/higaisa-or-winnti-apt-41-backdoors-old-and-new/","https://www.zscaler.com/blogs/security-research/unintentional-leak-glimpse-attack-vectors-apt37"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.execution","attack.initial-access","attack.stealth","attack.t1047","attack.t1059.001","attack.t1059.003","attack.t1059.005","attack.t1059.007","attack.t1218","attack.t1218.001","attack.t1218.010","attack.t1218.011","attack.t1566","attack.t1566.001"],"path":"rules/windows/process_creation/proc_creation_win_hh_susp_execution.yml","techniques":["T1047","T1059.001","T1059.003","T1059.005","T1059.007","T1218","T1218.001","T1218.010","T1218.011","T1566","T1566.001"],"cves":[]},{"id":"ee5e119b-1f75-4b34-add8-3be976961e39","title":"Conhost.exe CommandLine Path Traversal","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2022-06-14","modified":null,"description":"detects the usage of path traversal in conhost.exe indicating possible command/argument confusion/hijacking","references":["https://pentestlab.blog/2020/07/06/indirect-command-execution/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.execution","attack.t1059.003"],"path":"rules/windows/process_creation/proc_creation_win_conhost_path_traversal.yml","techniques":["T1059.003"],"cves":[]},{"id":"f0b70adb-0075-43b0-9745-e82a1c608fcc","title":"ZxShell Malware","author":"Florian Roth (Nextron Systems), oscd.community, Jonhnathan Ribeiro","status":"test","level":"critical","date":"2017-07-20","modified":"2021-11-27","description":"Detects a ZxShell start by the called and well-known function name","references":["https://www.hybrid-analysis.com/sample/5d2a4cde9fa7c2fdbf39b2e2ffd23378d0c50701a3095d1e91e3cf922d7b0b16?environmentId=100","https://pub-7cb8ac806c1b4c4383e585c474a24719.r2.dev/116309e7121bc8b0e66e4166c06f7b818e1d3629.pdf"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.execution","attack.stealth","attack.t1059.003","attack.t1218.011","attack.s0412","attack.g0001","detection.emerging-threats"],"path":"rules-emerging-threats/2014/TA/Axiom/proc_creation_win_apt_zxshell.yml","techniques":["T1059.003","T1218.011"],"cves":[]},{"id":"f6c27ecc-d890-4452-80e6-2e274a10e097","title":"Axios NPM Compromise Indicators - Windows","author":"Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"high","date":"2026-04-01","modified":null,"description":"Detects the specific Windows execution chain and process tree associated with the Axios NPM supply chain compromise.\nOn March 30, 2026, malicious versions (1.14.1, 0.30.4) were published to npm, injecting a dependency (plain-crypto-js@4.2.1) that executed a postinstall script as a cross-platform RAT dropper.\nThe dropper contacted a C2 server, delivered platform-specific payloads, deleted itself, and replaced package.json to evade detection.\nThe attack used cscript.exe (VBScript), curl.exe (C2), and PowerShell masquerading as Windows Terminal.\n","references":["https://www.stepsecurity.io/blog/axios-compromised-on-npm-malicious-versions-drop-remote-access-trojan","https://thehackernews.com/2026/03/axios-supply-chain-attack-pushes-cross.html?m=1","https://www.derp.ca/research/axios-npm-supply-chain-rat/","https://www.elastic.co/security-labs/axios-supply-chain-compromise-detections","https://www.virustotal.com/gui/file/e10b1fa84f1d6481625f741b69892780140d4e0e7769e7491e5f4d894c2e0e09"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.initial-access","attack.t1195.002","attack.execution","attack.command-and-control","attack.t1059.003","attack.t1059.005","attack.t1105","detection.emerging-threats"],"path":"rules-emerging-threats/2026/Malware/Axios-NPM-Compromise/proc_creation_win_axios_npm_compromise_indicators.yml","techniques":["T1195.002","T1059.003","T1059.005","T1105"],"cves":[]}],"kev_cves":[{"cveID":"CVE-2025-49704","state":"mapped","mapping_types":["primary_impact"]},{"cveID":"CVE-2025-49706","state":"mapped","mapping_types":["secondary_impact"]},{"cveID":"CVE-2023-42793","state":"mapped","mapping_types":["primary_impact"]},{"cveID":"CVE-2023-27532","state":"mapped","mapping_types":["primary_impact"]},{"cveID":"CVE-2021-40449","state":"mapped","mapping_types":["secondary_impact"]},{"cveID":"CVE-2021-22899","state":"mapped","mapping_types":["primary_impact"]}],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}