This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Recon Command Output Piped To Findstr.EXE
Original Source:
[Sigma source]
Title:
Recon Command Output Piped To Findstr.EXE
Status:
test
Description:
Detects the execution of a potential recon command where the results are piped to "findstr". This is meant to trigger on inline calls of "cmd.exe" via the "/c" or "/k" for example. Attackers often time use this technique to extract specific information they require in their reconnaissance phase.
References:
-https://github.com/redcanaryco/atomic-red-team/blob/02cb591f75064ffe1e0df9ac3ed5972a2e491c97/atomics/T1057/T1057.md#atomic-test-6---discover-specific-process---tasklist
-https://www.hhs.gov/sites/default/files/manage-engine-vulnerability-sector-alert-tlpclear.pdf
-https://www.trendmicro.com/en_us/research/22/d/spring4shell-exploited-to-deploy-cryptocurrency-miners.html
Author:
Nasreddine Bencherchali (Nextron Systems), frack113
Date:
2023-07-06
modified:
2025-10-08
Tags:
-'attack.discovery'
-'attack.t1057'
Logsource:
category: process_creation
product: windows
Detection:
selection:
CommandLine|contains
:
-'ipconfig*|*find'
-'net*|*find'
-'netstat*|*find'
-'ping*|*find'
-'systeminfo*|*find'
-'tasklist*|*find'
-'whoami*|*find'
filter_optional_xampp:
CommandLine|contains|all
:
-'cmd.exe /c TASKLIST /V |'
-'FIND /I'
-'\xampp\'
-'\catalina_start.bat'
condition
:
selection and not 1 of filter_optional_*
Falsepositives:
-Unknown
Level:
medium