Potential Defense Evasion Via Right-to-Left Override

 Original Source: [Sigma source]
Title: Potential Defense Evasion Via Right-to-Left Override
Status: test
Description:Detects the presence of the "u202+E" character, which causes a terminal, browser, or operating system to render text in a right-to-left sequence. This character is used as an obfuscation and masquerading techniques by adversaries to trick users into opening malicious files.
References:
  -https://redcanary.com/blog/right-to-left-override/
  -https://www.malwarebytes.com/blog/news/2014/01/the-rtlo-method
  -https://unicode-explorer.com/c/202E
  -https://tria.ge/241015-l98snsyeje/behavioral2
  -https://unprotect.it/technique/right-to-left-override-rlo-extension-spoofing/
Author: Micah Babinski, @micahbabinski, Swachchhanda Shrawan Poudel (Nextron Systems), Luc Génaux
Date: 2023-02-15
modified:2026-03-20
Tags:
  • -'attack.stealth'
  • -'attack.t1036.002'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection:
    CommandLine|contains:
      -'\u202e'
      -'[U+202E]'
      -'‮'

  condition:selection
Falsepositives:
  -Commandlines that contains scriptures such as arabic or hebrew might make use of this character
Level: high