Technique.View on attack.mitre.org
Adversaries may abuse utilities that allow for command execution to bypass security restrictions that limit the use of command-line interpreters. Various Windows utilities may be used to execute commands, possibly without invoking cmd. For example, Forfiles, the Program Compatibility Assistant (`pcalua.exe`), components of the Windows Subsystem for Linux (WSL), `Scriptrunner.exe`, as well as other utilities may invoke the execution of programs and commands from a Command and Scripting Interpreter, Run window, or via scripts. Adversaries may also abuse the `ssh.exe` binary to execute malicious commands via the `ProxyCommand` and `LocalCommand` options, which can be invoked via the `-o` flag or by modifying the SSH config file.
Adversaries may abuse these features for Stealth, specifically to perform arbitrary execution while subverting detections and/or mitigation controls (such as Group Policy) that limit/prevent the usage of cmd or file extensions more commonly associated with malicious payloads.
Rules on DetectionCode tagged with T1202.
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Microsoft Intune Device Health Scripts | Hunting | NULL | Azure Monitor Activity |
| Microsoft Intune Mobile Apps | Hunting | NULL | Azure Monitor Activity |
| Windows Content Copied from Browser was Executed | TTP | NULL | Sysmon EventID 13 AND Sysmon EventID 24 |
| Windows Indirect Command Execution Via forfiles | TTP | NULL | Sysmon EventID 1, CrowdStrike ProcessRollup2 |
| Windows Indirect Command Execution Via pcalua | TTP | NULL | Sysmon EventID 1, CrowdStrike ProcessRollup2 |
| Windows Indirect Command Execution Via Series Of Forfiles | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows RunMRU Command Execution | Anomaly | NULL | Sysmon EventID 13 |
None recorded.
| Used by | Procedure example |
|---|---|
| GroupLazarus Group | Lazarus Group persistence mechanisms have used |
| GroupRedCurl | RedCurl has used pcalua.exe to obfuscate binary execution and remote connections. |
| Used by | Procedure example |
|---|---|
| ToolForfiles | Forfiles can be used to subvert controls and possibly conceal command execution by not directly invoking cmd. |
| MalwareRevenge RAT | Revenge RAT uses the Forfiles utility to execute commands on the system. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.