Title:Potentially Suspicious CMD Shell Output Redirect Status:test Description:Detects inline Windows shell commands redirecting output via the ">" symbol to a suspicious location.
This technique is sometimes used by malicious actors in order to redirect the output of reconnaissance commands such as "hostname" and "dir" to files for future exfiltration.
References: -https://thedfirreport.com/2022/07/11/select-xmrig-from-sqlserver/ Author: Nasreddine Bencherchali (Nextron Systems) Date: 2022-07-12 modified:2024-03-19 Tags:
condition:selection_img and 1 of selection_cli_* Falsepositives:
-Legitimate admin or third party scripts used for diagnostic collection might generate some false positives Level:medium