Insensitive Subfolder Search Via Findstr.EXE

 Original Source: [Sigma source]
Title: Insensitive Subfolder Search Via Findstr.EXE
Status: test
Description:Detects execution of findstr with the "s" and "i" flags for a "subfolder" and "insensitive" search respectively. Attackers sometimes leverage this built-in utility to search the system for interesting files or filter through results of commands.
References:
  -https://lolbas-project.github.io/lolbas/Binaries/Findstr/
  -https://oddvar.moe/2018/04/11/putting-data-in-alternate-data-streams-and-how-to-execute-it-part-2/
  -https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f
Author: Furkan CALISKAN, @caliskanfurkan_, @oscd_initiative, Nasreddine Bencherchali (Nextron Systems)
Date: 2020-10-05
modified:2024-03-05
Tags:
  • -'attack.credential-access'
  • -'attack.command-and-control'
  • -'attack.stealth'
  • -'attack.t1218'
  • -'attack.t1564.004'
  • -'attack.t1552.001'
  • -'attack.t1105'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_findstr:
CommandLine|contains:'findstr' Image|endswith:'findstr.exe' OriginalFileName:'FINDSTR.EXE'   selection_cli_search_subfolder:
    CommandLine|contains|windash: ' -s '
  selection_cli_search_insensitive:
    CommandLine|contains|windash: ' -i '
  condition:selection_findstr and all of selection_cli_search_*
Falsepositives:
  -Administrative or software activity
Level: low