Potential Data Exfiltration Activity Via CommandLine Tools

 Original Source: [Sigma source]
Title: Potential Data Exfiltration Activity Via CommandLine Tools
Status: test
Description:Detects the use of various CLI utilities exfiltrating data via web requests
References:
  -https://www.sentinelone.com/blog/living-off-windows-defender-lockbit-ransomware-sideloads-cobalt-strike-through-microsoft-security-tool/
Author: Nasreddine Bencherchali (Nextron Systems)
Date: 2022-08-02
modified:2025-10-19
Tags:
  • -'attack.execution'
  • -'attack.t1059.001'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_iwr:
    Image|endswith:
      -'\powershell_ise.exe'
      -'\powershell.exe'
      -'\pwsh.exe'
      -'\cmd.exe'

    CommandLine|contains:
      -'curl '
      -'Invoke-RestMethod'
      -'Invoke-WebRequest'
      -'irm '
      -'iwr '
      -'wget '

    CommandLine|contains|all:
      -' -ur'
      -' -me'
      -' -b'
      -' POST '

  selection_curl:
    Image|endswith: '\curl.exe'
    CommandLine|contains: '--ur'
  selection_curl_data:
    CommandLine|contains:
      -' -d '
      -' --data '

  selection_wget:
    Image|endswith: '\wget.exe'
    CommandLine|contains:
      -'--post-data'
      -'--post-file'

  payloads:
    - CommandLine|re:
      - 'net\s+view'
      - 'sc\s+query'
    - CommandLine|contains:
      - 'Get-Content'
      - 'GetBytes'
      - 'hostname'
      - 'ifconfig'
      - 'ipconfig'
      - 'netstat'
      - 'nltest'
      - 'qprocess'
      - 'systeminfo'
      - 'tasklist'
      - 'ToBase64String'
      - 'whoami'
    - CommandLine|contains|all:
      - 'type '
      - ' > '
      - ' C:\'
  condition:(selection_iwr or all of selection_curl* or selection_wget) and payloads
Falsepositives:
  -Unlikely
Level: high