Indirect Command Execution

T1202

Technique.View on attack.mitre.org

About this technique

Adversaries may abuse utilities that allow for command execution to bypass security restrictions that limit the use of command-line interpreters. Various Windows utilities may be used to execute commands, possibly without invoking cmd. For example, Forfiles, the Program Compatibility Assistant (`pcalua.exe`), components of the Windows Subsystem for Linux (WSL), `Scriptrunner.exe`, as well as other utilities may invoke the execution of programs and commands from a Command and Scripting Interpreter, Run window, or via scripts. Adversaries may also abuse the `ssh.exe` binary to execute malicious commands via the `ProxyCommand` and `LocalCommand` options, which can be invoked via the `-o` flag or by modifying the SSH config file.

Adversaries may abuse these features for Stealth, specifically to perform arbitrary execution while subverting detections and/or mitigation controls (such as Group Policy) that limit/prevent the usage of cmd or file extensions more commonly associated with malicious payloads.

Detection rules47

Rules on DetectionCode tagged with T1202.

Sigma40

RuleLevelLog source
Custom File Open Handler Executes PowerShellhighwindows / registry_set
Diagnostic Library Sdiageng.DLL Loaded By Msdt.EXEhighwindows / image_load
Outlook EnableUnsafeClientMailRules Setting Enabledhighwindows / process_creation
Potential Arbitrary Command Execution Using Msdt.EXEhighwindows / process_creation
Potential Arbitrary File Download Using Office Applicationhighwindows / process_creation
Potentially Suspicious Child Processes Spawned by ConHosthighwindows / process_creation
Potentially Suspicious Office Document Executed From Trusted Locationhighwindows / process_creation
Renamed NirCmd.EXE Executionhighwindows / process_creation
Renamed PAExec Executionhighwindows / process_creation
Renamed PingCastle Binary Executionhighwindows / process_creation
Renamed ZOHO Dctask64 Executionhighwindows / process_creation
Rundll32 Execution Without CommandLine Parametershighwindows / process_creation
Suspicious Child Process Of BgInfo.EXEhighwindows / process_creation
Suspicious Remote Child Process From Outlookhighwindows / process_creation
Suspicious Service Binary Directoryhighwindows / process_creation

Splunk7

RuleTypeRiskData source
Microsoft Intune Device Health ScriptsHuntingNULLAzure Monitor Activity
Microsoft Intune Mobile AppsHuntingNULLAzure Monitor Activity
Windows Content Copied from Browser was ExecutedTTPNULLSysmon EventID 13 AND Sysmon EventID 24
Windows Indirect Command Execution Via forfilesTTPNULLSysmon EventID 1, CrowdStrike ProcessRollup2
Windows Indirect Command Execution Via pcaluaTTPNULLSysmon EventID 1, CrowdStrike ProcessRollup2
Windows Indirect Command Execution Via Series Of ForfilesAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Windows RunMRU Command ExecutionAnomalyNULLSysmon EventID 13

Groups2

Software2

Campaigns0

None recorded.

Procedure examples4

Groups2

Used byProcedure example
GroupLazarus Group

Lazarus Group persistence mechanisms have used forfiles.exe to execute .htm files.

GroupRedCurl

RedCurl has used pcalua.exe to obfuscate binary execution and remote connections.

Software2

Used byProcedure example
ToolForfiles

Forfiles can be used to subvert controls and possibly conceal command execution by not directly invoking cmd.

MalwareRevenge RAT

Revenge RAT uses the Forfiles utility to execute commands on the system.

References6

  1. Bleeping Computer - Scriptrunner.exe Open source
    Bill Toulas. (2023, January 4). Hackers abuse Windows error reporting tool to deploy malware. Retrieved July 8, 2024.
  2. Evi1cg Forfiles Nov 2017 Open source
    Evi1cg. (2017, November 26). block cmd.exe ? try this :. Retrieved September 12, 2024.
  3. SS64 Open source
    SS64. (n.d.). ScriptRunner.exe. Retrieved July 8, 2024.
  4. Secure Team - Scriptrunner.exe Open source
    Secure Team - Information Assurance. (2023, January 8). Windows Error Reporting Tool Abused to Load Malware. Retrieved July 8, 2024.
  5. Threat Actor Targets the Manufacturing industry with Lumma Stealer and Amadey Bot Open source
    Cyble. (2024, December 5). Threat Actor Targets the Manufacturing industry with Lumma Stealer and Amadey Bot. Retrieved February 4, 2025.
  6. VectorSec ForFiles Aug 2017 Open source
    vector_sec. (2017, August 11). Defenders watching launches of cmd? What about forfiles?. Retrieved September 12, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.