Conhost.exe CommandLine Path Traversal

 Original Source: [Sigma source]
Title: Conhost.exe CommandLine Path Traversal
Status: test
Description:detects the usage of path traversal in conhost.exe indicating possible command/argument confusion/hijacking
References:
  -https://pentestlab.blog/2020/07/06/indirect-command-execution/
Author: Nasreddine Bencherchali (Nextron Systems)
Date: 2022-06-14
modified:None
Tags:
  • -'attack.execution'
  • -'attack.t1059.003'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection:
    ParentCommandLine|contains: 'conhost'
    CommandLine|contains: '/../../'
  condition:selection
Falsepositives:
  -Unlikely
Level: high