Potentially Suspicious CMD Shell Output Redirect

 Original Source: [Sigma source]
Title: Potentially Suspicious CMD Shell Output Redirect
Status: test
Description:Detects inline Windows shell commands redirecting output via the ">" symbol to a suspicious location. This technique is sometimes used by malicious actors in order to redirect the output of reconnaissance commands such as "hostname" and "dir" to files for future exfiltration.
References:
  -https://thedfirreport.com/2022/07/11/select-xmrig-from-sqlserver/
Author: Nasreddine Bencherchali (Nextron Systems)
Date: 2022-07-12
modified:2024-03-19
Tags:
  • -'attack.stealth'
  • -'attack.t1218'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_img:
Image|endswith:'\cmd.exe' OriginalFileName:'Cmd.Exe'   selection_cli_1:
    CommandLine|contains:
      -'>?%APPDATA%\'
      -'>?%TEMP%\'
      -'>?%TMP%\'
      -'>?%USERPROFILE%\'
      -'>?C:\ProgramData\'
      -'>?C:\Temp\'
      -'>?C:\Users\Public\'
      -'>?C:\Windows\Temp\'

  selection_cli_2:
    CommandLine|contains:
      -' >'
      -'">'
      -''>'

    CommandLine|contains|all:
      -'C:\Users\'
      -'\AppData\Local\'

  condition:selection_img and 1 of selection_cli_*
Falsepositives:
  -Legitimate admin or third party scripts used for diagnostic collection might generate some false positives
Level: medium