This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Use Short Name Path in Command Line
Original Source:
[Sigma source]
Title:
Use Short Name Path in Command Line
Status:
test
Description:
Detect use of the Windows 8.3 short name. Which could be used as a method to avoid command-line detection
References:
-https://www.acunetix.com/blog/articles/windows-short-8-3-filenames-web-security-problem/
-https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-2000-server/cc959352(v=technet.10)
-https://twitter.com/frack113/status/1555830623633375232
Author:
frack113, Nasreddine Bencherchali
Date:
2022-08-07
modified:
2025-07-04
Tags:
-'attack.defense-evasion'
-'attack.t1564.004'
Logsource:
category: process_creation
product: windows
Detection:
selection:
CommandLine|contains
:
-'~1\'
-'~2\'
filter:
- ParentImage
:
- 'C:\Windows\System32\Dism.exe'
- 'C:\Windows\System32\cleanmgr.exe'
- 'C:\Program Files\GPSoftware\Directory Opus\dopus.exe'
- ParentImage|endswith
:
- '\WebEx\WebexHost.exe'
- '\thor\thor64.exe'
- '\veam.backup.shell.exe'
- '\winget.exe'
- '\Everything\Everything.exe'
- '\aurora-agent-64.exe'
- '\aurora-agent.exe'
ParentImage|contains
:
'\AppData\Local\Temp\WinGet\'
- CommandLine|contains
:
- '\appdata\local\webex\webex64\meetings\wbxreport.exe'
- 'C:\Program Files\Git\post-install.bat'
- 'C:\Program Files\Git\cmd\scalar.exe'
condition
:
selection and not filter
Falsepositives:
-Applications could use this notation occasionally which might generate some false positives. In that case investigate the parent and child process.
Level:
medium