Indirect Command Execution T1202

Tactic: Stealth

Adversaries may abuse utilities that allow for command execution to bypass security restrictions that limit the use of command-line interpreters. Various Windows utilities may be used to execute commands, possibly without invoking cmd. For example, Forfiles, the Program Compatibility Assistant (`pcalua.exe`), components of the Windows Subsystem for Linux (WSL), `Scriptrunner.exe`, as well as other utilities may invoke the execution of programs and commands from a Command and Scripting Interpreter, Run window, or via scripts. Adversaries may also abuse the `ssh.exe` binary to execute malicious commands via the `ProxyCommand` and `LocalCommand` options, which can be invoked via the `-o` flag or by modifying the SSH config file.

Events covered

8 catalog events are tagged with this technique by at least one rule.

Authoring guide

These 71 rules share fields, values, and exclusions.

Fields filtered most (33 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
Image35ends_with 29, contains 7, eq 2, starts_with 2, wildcard 2, is_null 1, regex_match 1\msdt.exe, \winword.exe, :\temp\, :\users\public\, :\windows\system32\bash.exe
CommandLine31contains 21, ends_with 4, regex_match 4, wildcard 2, eq 1, is_not_null 1, is_null 1(?i)conhost\.exe.*?\.exe, ^\S+\s, conhost.exe 0xffffffff -ForceV1, --exec, --install
OriginalFileName22eq 22bash.exe, winword.exe, excel.exe, forfiles.exe, ftp.exe
ParentImage15ends_with 13, contains 1, is_not_null 1\bginfo.exe, \bginfo64.exe, \conhost.exe, \wsl.exe, \wslhost.exe
event.type12eq 12start, change
host.os.type12eq 12
process_name12eq 9, regex_match 2, in 1(?i)^ssh\.exe, forfiles.exe, wsl.exe, aa-exec, aoss
parent_process_name7eq 5, regex_match 2(?i)(forfiles|fodhelper|ftp|pcalua)\.exe, forfiles.exe, wsl.exe, conhost.exe, pcalua.exe
EventID6eq 64688, 1
process.args5eq 5, starts_with 3, wildcard 2, contains 1&>, */etc/passwd*, */etc/shadow*, --distribution, --headless
EventType4eq 4exec, start, connection_attempted
ParentCommandLine4eq 2, starts_with 1, wildcard 1* curl *, *cmd /c *, *conhost* *.exe*, *forfiles* /c *, *pcalua* -a*
operationName4contains 3, in 1DeviceComplianceScript, DeviceManagementScript, create mobileapp, devicehealthscript, mobileapp
Type3eq 3
CurrentDirectory2contains 1, wildcard 1?:\, ?:\*\AppData\*, ?:\Windows\*, \\\\wsl.localhost

Top indicator values (744 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
event.typeeq
start
111078
EventIDeq
4688
4317
EventIDeq
1
2241
Imageends_with
\cmd.exe
4130
Imageends_with
\cscript.exe
472
Imageends_with
\powershell.exe
4179
Imageends_with
\pwsh.exe
4165
Imageends_with
\wscript.exe
474
Imageends_with
\calc.exe
314
Imageends_with
\msdt.exe
39
Imageends_with
\mshta.exe
366
Imageends_with
\regsvr32.exe
364
Imageends_with
\winword.exe
317
Imageends_with
:\windows\system32\bash.exe
22
Imageends_with
:\windows\syswow64\bash.exe
22
Imageends_with
\excel.exe
216
Imageends_with
\ftp.exe
22
Imageends_with
\powerpnt.exe
214
Imageends_with
\rundll32.exe
294
OriginalFileNameeq
bash.exe
34
OriginalFileNameeq
winword.exe
36
CommandLineregex_match
(?i)conhost\.exe.*?\.exe
22
CommandLineregex_match
^\S+\s
22
CommandLineregex_match
conhost.exe 0xffffffff -ForceV1
22
CommandLinewildcard
*schtasks*
22
EventTypeeq
exec
2576
EventTypeeq
start
2391
Imagecontains
:\temp\
211
Imagecontains
:\users\public\
213
Imagecontains
:\windows\temp\
28

Exclusions (196 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
process_nameeq
cmd.exe
2
process_nameeq
powershell.exe
2
CommandLinecontains
--install
1
CommandLinecontains
--unregister
1
CommandLinecontains
-d
1
CommandLinecontains
-e kill
1
CommandLinecontains
-i
1
CommandLinecontains
/home/linuxbrew/.linuxbrew/
1
CommandLinecontains
bash -
1
CommandLinecontains
bash.exe -
1
CommandLinecontains
homebrew
1
CommandLinecontains
wau-notify.ps1
1
CommandLinecontains
webhook
1
CommandLineends_with
.dotx
1
CommandLineends_with
.potx
1

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Sigma 40 rules

Elastic 14 rules

Splunk 15 rules

Panther 2 rules