Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0200 — Indirect Command Execution – Windows utility abuse behavior chain
DET0200

Indirect Command Execution – Windows utility abuse behavior chain

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN0576 Analytic 0576
Windows

Cause→effect chain: (1) A user or service launches an indirection utility (e.g., forfiles.exe, pcalua.exe, wsl.exe, scriptrunner.exe, ssh.exe with -o ProxyCommand/LocalCommand). (2) That utility spawns a secondary program/command (PowerShell, cmd, msiexec, regsvr32, curl, arbitrary EXE) and/or opens outbound network connections. (3) Optional precursor modification of SSH config to persist LocalCommand/ProxyCommand. Correlate process creation, command/script content, file access to %USERPROFILE%\.ssh\config, and network connections from the utility or its child.

WinEventLog:Sysmon EventCode=1 WinEventLog:Sysmon EventCode=3, 22 WinEventLog:Sysmon EventCode=11
[TimeWindow] Correlation window between indirect launcher and spawned child/network activity (e.g., 10–30 minutes).
[AllowedUtilities] Utilities permitted on admin/Jumphosts (forfiles, wsl, ssh) to reduce noise.
[HighRiskChildren] Child images that indicate abuse (powershell.exe, cmd.exe, rundll32.exe, regsvr32.exe, mshta.exe, msiexec.exe, curl.exe, bitsadmin.exe).
[UserContext] Raise severity when the actor is a standard/interactive user on a workstation rather than a server or CI agent.
[DestCIDRs] Known-good egress networks for SSH/WSL activity to suppress expected admin automations.

Detected Techniques

1

Details

MITRE ID
DET0200
STIX ID
x-mitre-detection-strategy--f3cc2f0f-c657-4453-90a8-d7c9a59d6e37
Analytics
1
Techniques Detected
1
By Tactic
Stealth
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.