Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0202 — Behavioral Detection of Windows Command Shell Execution
DET0202

Behavioral Detection of Windows Command Shell Execution

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN0578 Analytic 0578
Windows

Detects interactive or scripted abuse of cmd.exe, batch files, or shell invocation chains. Focuses on parent-child relationships (e.g., cmd.exe launched from unusual parents), anomalous command-line parameters, and chaining with discovery, credential access, or lateral movement behaviors.

WinEventLog:Security EventCode=4688 WinEventLog:Sysmon EventCode=7 EDR:scriptblock Process Tree + Script Block Logging
[ParentProcessName] Cmd.exe launched from uncommon parents (e.g., msedge.exe, winword.exe) may indicate abuse.
[TimeWindow] Cmd or .bat execution during non-working hours may indicate automation or C2 activity.
[CommandLinePattern] Flags suspicious switches (e.g., /c ping, /k whoami) or command chaining (&&, ^).
[ScriptStoragePath] Batch file execution from %TEMP%, C:\Users\Public, or external drives.
[UserContext] Flags admin-level users executing cmd outside expected baselines.

Detected Techniques

1

Details

MITRE ID
DET0202
STIX ID
x-mitre-detection-strategy--1806ad13-6fa8-4cb0-9d91-c8a989a1d9fe
Analytics
1
Techniques Detected
1
By Tactic
Execution
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.