Detection rules › Elastic

Suspicious Windows Command Shell Execution

Source
github.com/elastic/protections-artifacts

Identifies the execution of the Windows Command Shell process (cmd.exe) with suspicious argument values. This behavior is often observed during malware installation.

MITRE ATT&CK coverage

Rule body

[rule]
description = """
Identifies the execution of the Windows Command Shell process (cmd.exe) with suspicious argument values. This behavior
is often observed during malware installation.
"""
id = "8dd7588d-fc28-40c0-adfb-14789c763984"
license = "Elastic License v2"
name = "Suspicious Windows Command Shell Execution"
os_list = ["windows"]
version = "1.0.57"

query = '''
process where event.action == "start" and
 (process.name : "cmd.exe" or process.pe.original_file_name ==  "Cmd.Exe") and not user.id : "S-1-5-18" and
 process.parent.executable != null and
 (

  process.command_line : ("*).Run(*", "*GetObject*", "* curl*regsvr32*", "*echo*wscript*", "*echo*ZONE.identifier*",
  "*ActiveXObject*", "*dir /s /b *echo*", "*unescape(*",  "*findstr*TVNDRgAAAA*", "*findstr*passw*", "*start*\\\\*\\DavWWWRoot\\*",
  "* explorer*%CD%*", "*%cd%\\*.js*", "*attrib*%CD%*", "*/?cMD<*", "*/AutoIt3ExecuteScript*..*", "*&cls&cls&cls&cls&cls&*",
  "*&#*;&#*;&#*;&#*;*", "* &&s^eT*", "*& ChrW(*", "*&explorer /root*", "*start __ & __\\*", "*findstr /V /L *forfiles*",
  "*=wscri& set *", "*http*!COmpUternaME!*", "*start *.pdf * start /min cmd.exe /c *\\\\*", "*pip install*System.Net.WebClient*",
  "*Invoke-WebRequest*Start-Process*", "*iwr *saps *", "*-command (Invoke-webrequest*", "*copy /b *\\\\* ping *-n*", "*echo*.ToCharArray*",
  "*curl --ntlm -u*", "*bat'; iwr $*", "*http*.Content;*", "*&(gcm i?x)*", "*!*!*!*!*!*!*", "*&& !*!!*", "*for %? in (?) do @set*",
  "*QUIT>>?&FTP/s:*", "*iwr *Start-Process*", "*irm https*| iex*", "*^S^T^a*",  "*javascript:alert*",
  "* /v /c *&&set *&&set *&&set *&&set *&&set*", "*net use *@ssl*rundll32*", "*echo F | xcopy*/h /y &&*",
  "* if /i \"%cd%\"==\"C:\\Windows\\System32\" ( echo *", "* if /i \"%cd%\"==\"C:\\Windows\\System32\" ( msg*",
  "* if /i \"%cd%\"==\"C:\\Windows\\System32\" (mshta *", "*/c*start*.doc&exit*", "*/k*start msedge*http*&*", "*)) | Invoke-Expression\"", 
  "*/c *.bat&*.pdf*", "*/c *.bat&*.mp4*", "*set \"*& set \"*& set \"* call %*") or

  (process.args_count == 3 and process.args : "%*%" and process.args:"/c") or

  process.args : ("1>?:\\*.vbs", "1>?:\\*.js") or 
  
  (process.args : "explorer.exe" and process.args : "type" and process.args  :  ">" and process.args : "start") or

  (process.parent.name : ("explorer.exe", "python.exe") and
   process.command_line :
           ("*&&S^eT *",
            "*&& set *&& set *&& set *&& set *&& set *&& call*",
            "**\\u00??\\u00??\\u00??\\u00??\\u00??\\u00??\\u00??\\u00??*",
            "*sTArT /MiN *POWeRsheLl -WiNdowStYlE hIddeN*",
            "*cURL -O *HtTP*.bat*")) or

   (process.parent.name : ("explorer.exe", "python.exe") and process.args : "copy" and
    process.args : "&&" and process.args : "\\\\*@*\\*")
  ) and

  /* false positives */
  not (process.args : "%TEMP%\\Spiceworks\\*" and process.parent.name : "wmiprvse.exe") and
  not (process.parent.name : "cmd.exe" and process.command_line : "*!iodp.wapps!PitaLogger*") and
  not process.working_directory like "C:\\Jenkins\\_Workspace\\*" and
  not process.parent.executable :
                ("?:\\Perl64\\bin\\perl.exe",
                 "?:\\Program Files\\nodejs\\node.exe",
                 "E:\\eGov\\eGovXtract.exe",
                 "?:\\Program Files\\HP\\RS\\pgsql\\bin\\pg_dumpall.exe",
                 "?:\\Program Files (x86)\\PRTG Network Monitor\\64 bit\\PRTG Server.exe",
                 "?:\\Program Files (x86)\\Spiceworks\\bin\\spiceworks-finder.exe",
                 "?:\\Program Files (x86)\\Zuercher Suite\\production\\leds\\leds.exe",
                 "?:\\Program Files\\Tripwire\\Agent\\Plugins\\twexec\\twexec.exe",
                 "D:\\Agents\\?\\_work\\_tasks\\*\\SonarScanner.MSBuild.exe",
                 "?:\\reps\\inventory\\.nodejs\\node\\node.exe",
                 "?:\\Program Files\\Microsoft VS Code\\Code.exe",
                 "?:\\Users\\*\\node.exe",
                 "?:\\nodejs\\node.exe",
                 "?:\\*\\.nodejs\\node\\node.exe",
                 "C:\\xampp\\php\\php.exe",
                 "C:\\officelauncher\\OfficeInstaller.exe",
                 "C:\\Program Files (x86)\\mRemoteNG\\mRemoteNG.exe",
                 "D:\\PROGRAMS\\Siebel\\siebsrvr\\BIN\\siebmtshmw.exe",
                 "C:\\Program Files (x86)\\NetDocuments\\ndOffice\\ndOffice.exe",
                 "C:\\Program Files\\Waves Central\\Waves Central.exe",
                 "C:\\Users\\*\\AppData\\Local\\MyASUS Update Messenger\\UpdateMessenger.exe",
                 "C:\\Program Files\\Microsoft SQL Server\\MSSQL??.MSSQLSERVER\\MSSQL\\Binn\\sqlservr.exe",
                 "?:\\programmiweb\\NetBeans-*\\netbeans\\bin\\netbeans64.exe",
                 "?:\\Users\\*\\AppData\\Local\\Zuercher Suite\\production\\leds\\leds.exe",
                 "?:\\Program Files (x86)\\Public Safety Suite Professional\\production\\leds\\leds.exe",
                 "?:\\Program Files (x86)\\Tier2Tickets\\button_gui.exe",
                 "?:\\Program Files\\NetBeans-*\\netbeans\\bin\\netbeans*.exe",
                 "C:\\Program Files (x86)\\Microsoft Visual Studio\\20??\\Enterprise\\Common?\\IDE\\devenv.exe",
                 "?:\\Program Files (x86)\\Helpdesk Button\\button_gui.exe",
                 "?:\\VTSPortable\\VTS\\jre\\bin\\javaw.exe",
                 "?:\\Program Files\\Bot Framework Composer\\Bot Framework Composer.exe",
                 "?:\\Users\\*\\AppData\\Local\\Programs\\*electron\\AXIS Device Manager Extend.exe",
                 "?:\\Users\\*\\AppData\\Local\\Programs\\Arduino IDE\\Arduino IDE.exe",
                 "?:\\Program Files\\KMSYS Worldwide\\eQuate\\*\\SessionMgr.exe",
                 "?:\\Program Files (x86)\\Craneware\\Pricing Analyzer\\Craneware.Pricing.Shell.exe",
                 "?:\\sonarqube\\MSBuild\\SonarScanner.MSBuild.exe",
                 "?:\\Program Files (x86)\\jumpcloud-agent-app\\jumpcloud-agent-app.exe",
                 "?:\\Program Files\\PostgreSQL\\*\\bin\\pg_dumpall.exe",
                 "?:\\Users\\*\\AppData\\Local\\Programs\\Microsoft VS Code\\Code.exe",
                 "?:\\Program Files\\Microsoft SQL Server\\*\\DTS\\Binn\\ISServerExec.exe",
                 "?:\\Program Files\\Microsoft SQL Server\\MSSQL*\\MSSQL\\Binn\\sqlservr.exe",
                 "?:\\Program Files (x86)\\Microsoft Visual Studio\\*\\IDE\\devenv.exe",
                 "C:\\Program Files\\Microsoft Visual Studio\\*\\Common?\\IDE\\devenv.exe",
                 "?:\\Program Files (x86)\\Vim\\vim*\\vimrun.exe",
                 "C:\\Program Files\\NetBeans-28\\bin\\netbeans64.exe",
                 "C:\\Program Files\\Microsoft Visual Studio\\*\\DtsDebugHost.exe",
                 "C:\\Program Files (x86)\\Microsoft Visual Studio\\*\\DtsDebugHost.exe",
                 "C:\\Program Files (x86)\\Quest Software\\*\\Toad.exe",
                 "?:\\Program Files\\Microsoft SQL Server\\*\\DTS\\Binn\\ISServerExec.exe") and
  not (process.args : "console|findstr" and process.parent.name : "cmd.exe") and
  not process.working_directory : "?:\\Program Files (x86)\\Spiceworks\\" and
  not (process.parent.name : "wscript.exe" and
       process.parent.args : ("D:\\intersystems\\hsfoundation\\databases\\data\\ELSAInfoServer.vbs", "\\\\*")) and
  not (process.parent.name : ("pwsh.exe", "powershell.exe") and process.args : "start" and
       process.args : "https://login.microsoftonline.com/*") and 
  not (process.args :  "?:\\Program Files\\Citrix\\Secure Access Client\\nsauto.exe" and process.parent.name : "userinit.exe") and
  not process.args :
            ("?:\\Program Files (x86)\\PCMatic\\PCPitstopScheduleService.exe",
             "?:\\Program Files (x86)\\AllesTechnologyAgent\\*",
             "https://auth.axis.com/oauth2/oauth-authorize*",
             "D:\\GitHub\\lilitech-cloud-app\\node_modules\\.bin\\*",
             "C:\\ProgramData\\santesocial\\commun\\adm\\produits",
             "*--flat-playlist^*--no-cache-dir^*",
             "/DIR=C:\\Program Files (x86)\\Zeiss\\Zeiss PDF Printer",
             "*plugins\\org.eclipse.birt.doc_*",
             "database.*password", 
             "usebackq delims=: tokens=2") and
  not process.command_line :
               ("\"cmd\" /c %NETBEANS_MAVEN_COMMAND_LINE%",
                "cmd /c %NETBEANS_MAVEN_COMMAND_LINE%",
                "/c echo %TERM%",
                "*RunAsync.vbs*",
                "?:\\Windows\\system32\\cmd.exe /q /d /s /c \"npm.cmd ^\"install^\" ^\"--no-bin-links^\" ^\"--production^\"\"") and
  not (process.name : "cmd.exe" and process.args : "%TEMP%\\Spiceworks\\*" and process.args : "http*/dataloader/persist_netstat_data") and
  not process.parent.command_line : "cmd  /q /k  prompt MAM:Remote$G" and
  not process.parent.args like  "C:\\WINDOWS\\Runtime\\utility\\wrapper.vbs" and
  not (process.args : "C:\\Windows\\TEMP\\nessus_*.TMP" and process.parent.name : "WmiPrvSE.exe") and
  not (process.parent.name : "WmiPrvSe.exe" and 
       process.args : "& {$j = sajb {$ErrorActionPreference = 'SilentlyContinue';$ErrorActionPreference = 'SilentlyContinue';$jars = $(Get-ChildItem -Path 'C:\\*' -Recurse -Include '*.jar','*.war','*.ear'*") and 
  not (process.parent.name : "wscript.exe" and
       process.parent.args : ("C:\\IBM\\ITM\\TMAITM6_x64\\K06_uninstall.vbs",
                              "C:\\Windows\\System32\\gatherNetworkInfo.vbs",
                              "C:\\Program Files\\Arcserve\\Unified Data Protection\\Engine\\BIN\\AStartupRun.vbs")) and
  not (process.args == "echo" and process.args == "GEQ" and process.args == "1073741824") and
  not (process.parent.name : "wscript.exe" and process.parent.args : "C:\\Program Files (x86)\\CaseWare\\Template\\FinancialsIFRS\\Packager\\After\\0\\FinancialsIFRSCreateShortcuts.js") and
  not (process.name : "cmd.exe" and process.parent.name : ("javaw.exe", "udt.exe") and
       process.command_line : ("cmd /C %JENV_0%", "/c echo %MENU_SYSTEM%", "/c echo %NJSEXIT7%", "%OPENER% %f%")) and
  not (process.parent.executable : "C:\\Users\\*\\AppData\\Local\\Temp\\is-*.tmp\\RublonForWindows-?.?.?.tmp" and
       process.command_line : "*https://core.rublon.net/api/app/init*") and
  not process.command_line : ("cmd /c echo AMD64", "cmd /c echo x86", "C:\\Windows\\system32\\cmd.exe /c mshta \"javascript:code(close(new ActiveXObject('Scripting.FileSystemObject').GetStandardStream(1).Write*")
'''

min_endpoint_version = "7.15.0"
[[actions]]
action = "kill_process"
field = "process.entity_id"
state = 0
tree = true

[[optional_actions]]
action = "rollback"
field = "process.entity_id"
state = 0

[[threat]]
framework = "MITRE ATT&CK"
[[threat.technique]]
id = "T1059"
name = "Command and Scripting Interpreter"
reference = "https://attack.mitre.org/techniques/T1059/"
[[threat.technique.subtechnique]]
id = "T1059.003"
name = "Windows Command Shell"
reference = "https://attack.mitre.org/techniques/T1059/003/"



[threat.tactic]
id = "TA0002"
name = "Execution"
reference = "https://attack.mitre.org/tactics/TA0002/"

[internal]
min_endpoint_version = "7.15.0"

Stages and Predicates

Stage 1: process

process where event.action == "start" and
 (process.name : "cmd.exe" or process.pe.original_file_name ==  "Cmd.Exe") and not user.id : "S-1-5-18" and
 process.parent.executable != null and
 (
  process.command_line : ("*).Run(*", "*GetObject*", "* curl*regsvr32*", "*echo*wscript*", "*echo*ZONE.identifier*",
  "*ActiveXObject*", "*dir /s /b *echo*", "*unescape(*",  "*findstr*TVNDRgAAAA*", "*findstr*passw*", "*start*\\\\*\\DavWWWRoot\\*",
  "* explorer*%CD%*", "*%cd%\\*.js*", "*attrib*%CD%*", "*/?cMD<*", "*/AutoIt3ExecuteScript*..*", "*&cls&cls&cls&cls&cls&*",
  "*&#*;&#*;&#*;&#*;*", "* &&s^eT*", "*& ChrW(*", "*&explorer /root*", "*start __ & __\\*", "*findstr /V /L *forfiles*",
  "*=wscri& set *", "*http*!COmpUternaME!*", "*start *.pdf * start /min cmd.exe /c *\\\\*", "*pip install*System.Net.WebClient*",
  "*Invoke-WebRequest*Start-Process*", "*iwr *saps *", "*-command (Invoke-webrequest*", "*copy /b *\\\\* ping *-n*", "*echo*.ToCharArray*",
  "*curl --ntlm -u*", "*bat'; iwr $*", "*http*.Content;*", "*&(gcm i?x)*", "*!*!*!*!*!*!*", "*&& !*!!*", "*for %? in (?) do @set*",
  "*QUIT>>?&FTP/s:*", "*iwr *Start-Process*", "*irm https*| iex*", "*^S^T^a*",  "*javascript:alert*",
  "* /v /c *&&set *&&set *&&set *&&set *&&set*", "*net use *@ssl*rundll32*", "*echo F | xcopy*/h /y &&*",
  "* if /i \"%cd%\"==\"C:\\Windows\\System32\" ( echo *", "* if /i \"%cd%\"==\"C:\\Windows\\System32\" ( msg*",
  "* if /i \"%cd%\"==\"C:\\Windows\\System32\" (mshta *", "*/c*start*.doc&exit*", "*/k*start msedge*http*&*", "*)) | Invoke-Expression\"",
  "*/c *.bat&*.pdf*", "*/c *.bat&*.mp4*", "*set \"*& set \"*& set \"* call %*") or
  (process.args_count == 3 and process.args : "%*%" and process.args:"/c") or
  process.args : ("1>?:\\*.vbs", "1>?:\\*.js") or
  (process.args : "explorer.exe" and process.args : "type" and process.args  :  ">" and process.args : "start") or
  (process.parent.name : ("explorer.exe", "python.exe") and
   process.command_line :
           ("*&&S^eT *",
            "*&& set *&& set *&& set *&& set *&& set *&& call*",
            "**\\u00??\\u00??\\u00??\\u00??\\u00??\\u00??\\u00??\\u00??*",
            "*sTArT /MiN *POWeRsheLl -WiNdowStYlE hIddeN*",
            "*cURL -O *HtTP*.bat*")) or
   (process.parent.name : ("explorer.exe", "python.exe") and process.args : "copy" and
    process.args : "&&" and process.args : "\\\\*@*\\*")
  ) and
  not (process.args : "%TEMP%\\Spiceworks\\*" and process.parent.name : "wmiprvse.exe") and
  not (process.parent.name : "cmd.exe" and process.command_line : "*!iodp.wapps!PitaLogger*") and
  not process.working_directory like "C:\\Jenkins\\_Workspace\\*" and
  not process.parent.executable :
                ("?:\\Perl64\\bin\\perl.exe",
                 "?:\\Program Files\\nodejs\\node.exe",
                 "E:\\eGov\\eGovXtract.exe",
                 "?:\\Program Files\\HP\\RS\\pgsql\\bin\\pg_dumpall.exe",
                 "?:\\Program Files (x86)\\PRTG Network Monitor\\64 bit\\PRTG Server.exe",
                 "?:\\Program Files (x86)\\Spiceworks\\bin\\spiceworks-finder.exe",
                 "?:\\Program Files (x86)\\Zuercher Suite\\production\\leds\\leds.exe",
                 "?:\\Program Files\\Tripwire\\Agent\\Plugins\\twexec\\twexec.exe",
                 "D:\\Agents\\?\\_work\\_tasks\\*\\SonarScanner.MSBuild.exe",
                 "?:\\reps\\inventory\\.nodejs\\node\\node.exe",
                 "?:\\Program Files\\Microsoft VS Code\\Code.exe",
                 "?:\\Users\\*\\node.exe",
                 "?:\\nodejs\\node.exe",
                 "?:\\*\\.nodejs\\node\\node.exe",
                 "C:\\xampp\\php\\php.exe",
                 "C:\\officelauncher\\OfficeInstaller.exe",
                 "C:\\Program Files (x86)\\mRemoteNG\\mRemoteNG.exe",
                 "D:\\PROGRAMS\\Siebel\\siebsrvr\\BIN\\siebmtshmw.exe",
                 "C:\\Program Files (x86)\\NetDocuments\\ndOffice\\ndOffice.exe",
                 "C:\\Program Files\\Waves Central\\Waves Central.exe",
                 "C:\\Users\\*\\AppData\\Local\\MyASUS Update Messenger\\UpdateMessenger.exe",
                 "C:\\Program Files\\Microsoft SQL Server\\MSSQL??.MSSQLSERVER\\MSSQL\\Binn\\sqlservr.exe",
                 "?:\\programmiweb\\NetBeans-*\\netbeans\\bin\\netbeans64.exe",
                 "?:\\Users\\*\\AppData\\Local\\Zuercher Suite\\production\\leds\\leds.exe",
                 "?:\\Program Files (x86)\\Public Safety Suite Professional\\production\\leds\\leds.exe",
                 "?:\\Program Files (x86)\\Tier2Tickets\\button_gui.exe",
                 "?:\\Program Files\\NetBeans-*\\netbeans\\bin\\netbeans*.exe",
                 "C:\\Program Files (x86)\\Microsoft Visual Studio\\20??\\Enterprise\\Common?\\IDE\\devenv.exe",
                 "?:\\Program Files (x86)\\Helpdesk Button\\button_gui.exe",
                 "?:\\VTSPortable\\VTS\\jre\\bin\\javaw.exe",
                 "?:\\Program Files\\Bot Framework Composer\\Bot Framework Composer.exe",
                 "?:\\Users\\*\\AppData\\Local\\Programs\\*electron\\AXIS Device Manager Extend.exe",
                 "?:\\Users\\*\\AppData\\Local\\Programs\\Arduino IDE\\Arduino IDE.exe",
                 "?:\\Program Files\\KMSYS Worldwide\\eQuate\\*\\SessionMgr.exe",
                 "?:\\Program Files (x86)\\Craneware\\Pricing Analyzer\\Craneware.Pricing.Shell.exe",
                 "?:\\sonarqube\\MSBuild\\SonarScanner.MSBuild.exe",
                 "?:\\Program Files (x86)\\jumpcloud-agent-app\\jumpcloud-agent-app.exe",
                 "?:\\Program Files\\PostgreSQL\\*\\bin\\pg_dumpall.exe",
                 "?:\\Users\\*\\AppData\\Local\\Programs\\Microsoft VS Code\\Code.exe",
                 "?:\\Program Files\\Microsoft SQL Server\\*\\DTS\\Binn\\ISServerExec.exe",
                 "?:\\Program Files\\Microsoft SQL Server\\MSSQL*\\MSSQL\\Binn\\sqlservr.exe",
                 "?:\\Program Files (x86)\\Microsoft Visual Studio\\*\\IDE\\devenv.exe",
                 "C:\\Program Files\\Microsoft Visual Studio\\*\\Common?\\IDE\\devenv.exe",
                 "?:\\Program Files (x86)\\Vim\\vim*\\vimrun.exe",
                 "C:\\Program Files\\NetBeans-28\\bin\\netbeans64.exe",
                 "C:\\Program Files\\Microsoft Visual Studio\\*\\DtsDebugHost.exe",
                 "C:\\Program Files (x86)\\Microsoft Visual Studio\\*\\DtsDebugHost.exe",
                 "C:\\Program Files (x86)\\Quest Software\\*\\Toad.exe",
                 "?:\\Program Files\\Microsoft SQL Server\\*\\DTS\\Binn\\ISServerExec.exe") and
  not (process.args : "console|findstr" and process.parent.name : "cmd.exe") and
  not process.working_directory : "?:\\Program Files (x86)\\Spiceworks\\" and
  not (process.parent.name : "wscript.exe" and
       process.parent.args : ("D:\\intersystems\\hsfoundation\\databases\\data\\ELSAInfoServer.vbs", "\\\\*")) and
  not (process.parent.name : ("pwsh.exe", "powershell.exe") and process.args : "start" and
       process.args : "https://login.microsoftonline.com/*") and
  not (process.args :  "?:\\Program Files\\Citrix\\Secure Access Client\\nsauto.exe" and process.parent.name : "userinit.exe") and
  not process.args :
            ("?:\\Program Files (x86)\\PCMatic\\PCPitstopScheduleService.exe",
             "?:\\Program Files (x86)\\AllesTechnologyAgent\\*",
             "https://auth.axis.com/oauth2/oauth-authorize*",
             "D:\\GitHub\\lilitech-cloud-app\\node_modules\\.bin\\*",
             "C:\\ProgramData\\santesocial\\commun\\adm\\produits",
             "*--flat-playlist^*--no-cache-dir^*",
             "/DIR=C:\\Program Files (x86)\\Zeiss\\Zeiss PDF Printer",
             "*plugins\\org.eclipse.birt.doc_*",
             "database.*password",
             "usebackq delims=: tokens=2") and
  not process.command_line :
               ("\"cmd\" /c %NETBEANS_MAVEN_COMMAND_LINE%",
                "cmd /c %NETBEANS_MAVEN_COMMAND_LINE%",
                "/c echo %TERM%",
                "*RunAsync.vbs*",
                "?:\\Windows\\system32\\cmd.exe /q /d /s /c \"npm.cmd ^\"install^\" ^\"--no-bin-links^\" ^\"--production^\"\"") and
  not (process.name : "cmd.exe" and process.args : "%TEMP%\\Spiceworks\\*" and process.args : "http*/dataloader/persist_netstat_data") and
  not process.parent.command_line : "cmd  /q /k  prompt MAM:Remote$G" and
  not process.parent.args like  "C:\\WINDOWS\\Runtime\\utility\\wrapper.vbs" and
  not (process.args : "C:\\Windows\\TEMP\\nessus_*.TMP" and process.parent.name : "WmiPrvSE.exe") and
  not (process.parent.name : "WmiPrvSe.exe" and
       process.args : "& {$j = sajb {$ErrorActionPreference = 'SilentlyContinue';$ErrorActionPreference = 'SilentlyContinue';$jars = $(Get-ChildItem -Path 'C:\\*' -Recurse -Include '*.jar','*.war','*.ear'*") and
  not (process.parent.name : "wscript.exe" and
       process.parent.args : ("C:\\IBM\\ITM\\TMAITM6_x64\\K06_uninstall.vbs",
                              "C:\\Windows\\System32\\gatherNetworkInfo.vbs",
                              "C:\\Program Files\\Arcserve\\Unified Data Protection\\Engine\\BIN\\AStartupRun.vbs")) and
  not (process.args == "echo" and process.args == "GEQ" and process.args == "1073741824") and
  not (process.parent.name : "wscript.exe" and process.parent.args : "C:\\Program Files (x86)\\CaseWare\\Template\\FinancialsIFRS\\Packager\\After\\0\\FinancialsIFRSCreateShortcuts.js") and
  not (process.name : "cmd.exe" and process.parent.name : ("javaw.exe", "udt.exe") and
       process.command_line : ("cmd /C %JENV_0%", "/c echo %MENU_SYSTEM%", "/c echo %NJSEXIT7%", "%OPENER% %f%")) and
  not (process.parent.executable : "C:\\Users\\*\\AppData\\Local\\Temp\\is-*.tmp\\RublonForWindows-?.?.?.tmp" and
       process.command_line : "*https://core.rublon.net/api/app/init*") and
  not process.command_line : ("cmd /c echo AMD64", "cmd /c echo x86", "C:\\Windows\\system32\\cmd.exe /c mshta \"javascript:code(close(new ActiveXObject('Scripting.FileSystemObject').GetStandardStream(1).Write*")

Exclusions

The rule actively suppresses these predicates.

FieldKindExcluded valuesSearch
process.argseq1073741824excludes:process.args field:"process.args" value:"1073741824"
process.argseqGEQexcludes:process.args field:"process.args" value:"GEQ"
process.argseqechoexcludes:process.args field:"process.args" value:"echo"
process.argseq?:\Program Files\Citrix\Secure Access Client\nsauto.exeexcludes:process.args field:"process.args" value:"?:\Program Files\Citrix\Secure Access Client\nsauto.exe"
process.parent.nameequserinit.exeexcludes:process.parent.name field:"process.parent.name" value:"userinit.exe"
process.argseqconsole|findstrexcludes:process.args field:"process.args" value:"console|findstr"
process.parent.nameeqcmd.exeexcludes:process.parent.name field:"process.parent.name" value:"cmd.exe"
process.argseqstartexcludes:process.args field:"process.args" value:"start"
process.argsstarts_withhttps://login.microsoftonline.com/excludes:process.args field:"process.args" value:"https://login.microsoftonline.com/"
process.parent.nameeqpwsh.exe, powershell.exeexcludes:process.parent.name field:"process.parent.name" value:"pwsh.exe" field:"process.parent.name" value:"powershell.exe"
process.argsstarts_with%TEMP%\Spiceworks\excludes:process.args field:"process.args" value:"%TEMP%\Spiceworks\"
process.argswildcardhttp*/dataloader/persist_netstat_dataexcludes:process.args field:"process.args" value:"http*/dataloader/persist_netstat_data"
process.nameeqcmd.exeexcludes:process.name field:"process.name" value:"cmd.exe"
process.parent.nameeqwmiprvse.exeexcludes:process.parent.name field:"process.parent.name" value:"wmiprvse.exe"
process.argswildcard& {$j = sajb {$ErrorActionPreference = 'SilentlyContinue';$ErrorActionPreference = 'SilentlyContinue';$jars = $(Get-ChildItem -Path 'C:\*' -Recurse -Include '*.jar','*.war','*.ear'*excludes:process.args field:"process.args" value:"& {$j = sajb {$ErrorActionPreference = 'SilentlyContinue';$ErrorActionPreference = 'SilentlyContinue';$jars = $(Get-ChildItem -Path 'C:\*' -Recurse -Include '*.jar','*.war','*.ear'*"
process.parent.nameeqWmiPrvSe.exeexcludes:process.parent.name field:"process.parent.name" value:"WmiPrvSe.exe"
process.argswildcardC:\Windows\TEMP\nessus_*.TMPexcludes:process.args field:"process.args" value:"C:\Windows\TEMP\nessus_*.TMP"
process.parent.nameeqWmiPrvSE.exeexcludes:process.parent.name field:"process.parent.name" value:"WmiPrvSE.exe"
process.command_lineeqcmd /C %JENV_0%, /c echo %MENU_SYSTEM%, /c echo %NJSEXIT7%, %OPENER% %f%excludes:process.command_line
process.parent.nameeqjavaw.exe, udt.exeexcludes:process.parent.name field:"process.parent.name" value:"javaw.exe" field:"process.parent.name" value:"udt.exe"
process.command_linematch!iodp.wapps!PitaLoggerexcludes:process.command_line field:"process.command_line" value:"!iodp.wapps!PitaLogger"
process.command_linematchhttps://core.rublon.net/api/app/initexcludes:process.command_line field:"process.command_line" value:"https://core.rublon.net/api/app/init"
process.parent.executablewildcardC:\Users\*\AppData\Local\Temp\is-*.tmp\RublonForWindows-?.?.?.tmpexcludes:process.parent.executable field:"process.parent.executable" value:"C:\Users\*\AppData\Local\Temp\is-*.tmp\RublonForWindows-?.?.?.tmp"
process.parent.argseqC:\IBM\ITM\TMAITM6_x64\K06_uninstall.vbs, C:\Windows\System32\gatherNetworkInfo.vbs, C:\Program Files\Arcserve\Unified Data Protection\Engine\BIN\AStartupRun.vbsexcludes:process.parent.args field:"process.parent.args" value:"C:\IBM\ITM\TMAITM6_x64\K06_uninstall.vbs" field:"process.parent.args" value:"C:\Windows\System32\gatherNetworkInfo.vbs" field:"process.parent.args" value:"C:\Program Files\Arcserve\Unified Data Protection\Engine\BIN\AStartupRun.vbs"
process.parent.nameeqwscript.exeexcludes:process.parent.name field:"process.parent.name" value:"wscript.exe"
process.parent.argseqC:\Program Files (x86)\CaseWare\Template\FinancialsIFRS\Packager\After\0\FinancialsIFRSCreateShortcuts.jsexcludes:process.parent.args field:"process.parent.args" value:"C:\Program Files (x86)\CaseWare\Template\FinancialsIFRS\Packager\After\0\FinancialsIFRSCreateShortcuts.js"
process.parent.argswildcardD:\intersystems\hsfoundation\databases\data\ELSAInfoServer.vbs, \\*excludes:process.parent.args field:"process.parent.args" value:"D:\intersystems\hsfoundation\databases\data\ELSAInfoServer.vbs" field:"process.parent.args" value:"\\*"
process.argswildcard?:\Program Files (x86)\PCMatic\PCPitstopScheduleService.exe, ?:\Program Files (x86)\AllesTechnologyAgent\*, https://auth.axis.com/oauth2/oauth-authorize*, D:\GitHub\lilitech-cloud-app\node_modules\.bin\*, C:\ProgramData\santesocial\commun\adm\produits, *--flat-playlist^*--no-cache-dir^*, /DIR=C:\Program Files (x86)\Zeiss\Zeiss PDF Printer, *plugins\org.eclipse.birt.doc_*, database.*password, usebackq delims=: tokens=2excludes:process.args
process.command_linewildcard"cmd" /c %NETBEANS_MAVEN_COMMAND_LINE%, cmd /c %NETBEANS_MAVEN_COMMAND_LINE%, /c echo %TERM%, *RunAsync.vbs*, ?:\Windows\system32\cmd.exe /q /d /s /c "npm.cmd ^"install^" ^"--no-bin-links^" ^"--production^""excludes:process.command_line
process.command_linewildcardcmd /c echo AMD64, cmd /c echo x86, C:\Windows\system32\cmd.exe /c mshta "javascript:code(close(new ActiveXObject('Scripting.FileSystemObject').GetStandardStream(1).Write*excludes:process.command_line
process.parent.argseqC:\WINDOWS\Runtime\utility\wrapper.vbsexcludes:process.parent.args field:"process.parent.args" value:"C:\WINDOWS\Runtime\utility\wrapper.vbs"
process.parent.command_lineeqcmd /q /k prompt MAM:Remote$Gexcludes:process.parent.command_line field:"process.parent.command_line" value:"cmd /q /k prompt MAM:Remote$G"
process.parent.executablewildcard?:\Perl64\bin\perl.exe, ?:\Program Files\nodejs\node.exe, E:\eGov\eGovXtract.exe, ?:\Program Files\HP\RS\pgsql\bin\pg_dumpall.exe, ?:\Program Files (x86)\PRTG Network Monitor\64 bit\PRTG Server.exe, ?:\Program Files (x86)\Spiceworks\bin\spiceworks-finder.exe, ?:\Program Files (x86)\Zuercher Suite\production\leds\leds.exe, ?:\Program Files\Tripwire\Agent\Plugins\twexec\twexec.exe, D:\Agents\?\_work\_tasks\*\SonarScanner.MSBuild.exe, ?:\reps\inventory\.nodejs\node\node.exe, ?:\Program Files\Microsoft VS Code\Code.exe, ?:\Users\*\node.exe, ?:\nodejs\node.exe, ?:\*\.nodejs\node\node.exe, C:\xampp\php\php.exe, C:\officelauncher\OfficeInstaller.exe, C:\Program Files (x86)\mRemoteNG\mRemoteNG.exe, D:\PROGRAMS\Siebel\siebsrvr\BIN\siebmtshmw.exe, C:\Program Files (x86)\NetDocuments\ndOffice\ndOffice.exe, C:\Program Files\Waves Central\Waves Central.exe, C:\Users\*\AppData\Local\MyASUS Update Messenger\UpdateMessenger.exe, C:\Program Files\Microsoft SQL Server\MSSQL??.MSSQLSERVER\MSSQL\Binn\sqlservr.exe, ?:\programmiweb\NetBeans-*\netbeans\bin\netbeans64.exe, ?:\Users\*\AppData\Local\Zuercher Suite\production\leds\leds.exe, ?:\Program Files (x86)\Public Safety Suite Professional\production\leds\leds.exe, ?:\Program Files (x86)\Tier2Tickets\button_gui.exe, ?:\Program Files\NetBeans-*\netbeans\bin\netbeans*.exe, C:\Program Files (x86)\Microsoft Visual Studio\20??\Enterprise\Common?\IDE\devenv.exe, ?:\Program Files (x86)\Helpdesk Button\button_gui.exe, ?:\VTSPortable\VTS\jre\bin\javaw.exe, ?:\Program Files\Bot Framework Composer\Bot Framework Composer.exe, ?:\Users\*\AppData\Local\Programs\*electron\AXIS Device Manager Extend.exe, ?:\Users\*\AppData\Local\Programs\Arduino IDE\Arduino IDE.exe, ?:\Program Files\KMSYS Worldwide\eQuate\*\SessionMgr.exe, ?:\Program Files (x86)\Craneware\Pricing Analyzer\Craneware.Pricing.Shell.exe, ?:\sonarqube\MSBuild\SonarScanner.MSBuild.exe, ?:\Program Files (x86)\jumpcloud-agent-app\jumpcloud-agent-app.exe, ?:\Program Files\PostgreSQL\*\bin\pg_dumpall.exe, ?:\Users\*\AppData\Local\Programs\Microsoft VS Code\Code.exe, ?:\Program Files\Microsoft SQL Server\*\DTS\Binn\ISServerExec.exe, ?:\Program Files\Microsoft SQL Server\MSSQL*\MSSQL\Binn\sqlservr.exe, ?:\Program Files (x86)\Microsoft Visual Studio\*\IDE\devenv.exe, C:\Program Files\Microsoft Visual Studio\*\Common?\IDE\devenv.exe, ?:\Program Files (x86)\Vim\vim*\vimrun.exe, C:\Program Files\NetBeans-28\bin\netbeans64.exe, C:\Program Files\Microsoft Visual Studio\*\DtsDebugHost.exe, C:\Program Files (x86)\Microsoft Visual Studio\*\DtsDebugHost.exe, C:\Program Files (x86)\Quest Software\*\Toad.exe, ?:\Program Files\Microsoft SQL Server\*\DTS\Binn\ISServerExec.exeexcludes:process.parent.executable
process.working_directoryeq?:\Program Files (x86)\Spiceworks\excludes:process.working_directory field:"process.working_directory" value:"?:\Program Files (x86)\Spiceworks\"
process.working_directorystarts_withC:\Jenkins\_Workspace\excludes:process.working_directory field:"process.working_directory" value:"C:\Jenkins\_Workspace\"
user.ideqS-1-5-18excludes:user.id field:"user.id" value:"S-1-5-18"

Indicators

These rows show field, operator, and value matches.

FieldKindValuesSearch
event.actioneq
  • start corpus 391 (elastic 391)
field:"EventType" kind:eq value:"start"
process.argswildcard
  • %*%
  • && corpus 2 (elastic 2)
  • /c corpus 7 (elastic 7)
  • 1>?:\*.js corpus 2 (elastic 2)
  • 1>?:\*.vbs corpus 2 (elastic 2)
  • > corpus 4 (elastic 4)
  • \\*@*\* corpus 3 (elastic 3)
  • copy corpus 5 (elastic 5)
  • explorer.exe corpus 2 (elastic 2)
  • start corpus 7 (elastic 7)
  • type corpus 3 (elastic 3)
field:"process.args" kind:wildcard
process.args_counteq
  • 3 transforms: number corpus 22 (elastic 22)
field:"process.args_count" kind:eq value:"3"
process.command_linewildcard
  • * &&s^eT*
  • * /v /c *&&set *&&set *&&set *&&set *&&set*
  • * curl*regsvr32* corpus 2 (elastic 2)
  • * explorer*%CD%* corpus 2 (elastic 2)
  • * if /i "%cd%"=="C:\Windows\System32" ( echo *
  • * if /i "%cd%"=="C:\Windows\System32" ( msg*
  • * if /i "%cd%"=="C:\Windows\System32" (mshta *
  • *!*!*!*!*!*!*
  • *%cd%\*.js* corpus 2 (elastic 2)
  • *& ChrW(*
  • *&#*;&#*;&#*;&#*;* corpus 2 (elastic 2)
  • *&& !*!!*
  • *&& set *&& set *&& set *&& set *&& set *&& call* corpus 2 (elastic 2)
  • *&&S^eT *
  • *&(gcm i?x)*
  • *&cls&cls&cls&cls&cls&*
  • *&explorer /root*
  • *)) | Invoke-Expression"
  • *).Run(*
  • **\u00??\u00??\u00??\u00??\u00??\u00??\u00??\u00??*
  • *-command (Invoke-webrequest*
  • */?cMD<*
  • */AutoIt3ExecuteScript*..* corpus 2 (elastic 2)
  • */c *.bat&*.mp4*
  • */c *.bat&*.pdf*
  • */c*start*.doc&exit*
  • */k*start msedge*http*&*
  • *=wscri& set *
  • *ActiveXObject*
  • *GetObject*
  • *Invoke-WebRequest*Start-Process*
  • *QUIT>>?&FTP/s:*
  • *^S^T^a*
  • *attrib*%CD%* corpus 2 (elastic 2)
  • *bat'; iwr $*
  • *cURL -O *HtTP*.bat*
  • *copy /b *\\* ping *-n* corpus 2 (elastic 2)
  • *curl --ntlm -u*
  • *dir /s /b *echo* corpus 2 (elastic 2)
  • *echo F | xcopy*/h /y &&*
  • +21 more values (see full rule source)
field:"CommandLine" kind:wildcard
process.namewildcard
  • cmd.exe corpus 121 (elastic 92, splunk 29)
field:"process_name" kind:wildcard value:"cmd.exe"
process.parent.executableis_not_null
  • (no value, null check)
field:"ParentImage" kind:is_not_null
process.parent.namewildcard
  • explorer.exe corpus 51 (elastic 50, splunk 1)
  • python.exe corpus 4 (elastic 4)
field:"parent_process_name" kind:wildcard
process.pe.original_file_nameeq
  • Cmd.Exe corpus 81 (sigma 43, elastic 21, splunk 17)
field:"OriginalFileName" kind:eq value:"Cmd.Exe"