Forfiles Command Execution

 Original Source: [Sigma source]
Title: Forfiles Command Execution
Status: test
Description:Detects the execution of "forfiles" with the "/c" flag. While this is an expected behavior of the tool, it can be abused in order to proxy execution through it with any binary. Can be used to bypass application whitelisting.
References:
  -https://lolbas-project.github.io/lolbas/Binaries/Forfiles/
  -https://pentestlab.blog/2020/07/06/indirect-command-execution/
Author: Tim Rauch, Elastic, E.M. Anhaus (originally from Atomic Blue Detections, Endgame), oscd.community
Date: 2022-06-14
modified:2024-03-05
Tags:
  • -'attack.execution'
  • -'attack.t1059'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_img:
Image|endswith:'\forfiles.exe' OriginalFileName:'forfiles.exe'   selection_cli:
    CommandLine|contains|windash: ' -c '
  condition:all of selection_*
Falsepositives:
  -Legitimate use via a batch script or by an administrator.
Level: medium