Malicious PowerShell UrlDecode Payload Spawned by SQL Server after FortiClient EMS Exploitation

PremiumReviewedSigma · Critical · v1
Product
windows
Category
process_creation
Author
HuntRule
Published
2026-10-08
Updated
2026-10-08

ATT&CK techniques

Initial Access → Execution
  1. Recon

  2. Resource Dev

  3. Persistence

  4. Priv Esc

  5. Defense Evasion

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects a command shell launching PowerShell that loads System.Web and calls UrlDecode as a child of the SQL Server process. Attackers exploiting the patched FortiClient EMS vulnerability use this chain to decode and run staged payloads through the exposed database service. A SQL Server process invoking encoded PowerShell indicates post-exploitation code execution.

Related detections9 linkedT1059.001 — drag to rearrange
Malicious IIS w3wp Worker Spawning Command Interpreter via SharePoint Web Shell
Suspicious SolarWinds Web Help Desk Java Process Spawning Command Shell
Malicious IIS Worker Process Spawning PowerShell via Gladinet CentreStack Exploit
Suspicious PowerShell Out-of-Band Request to Interactsh Domain
Exchange Worker Process Spawning Command Shell via OWASSRF
Suspicious SharePoint Worker Process Spawning Command Interpreter via ToolShell
Malicious ActiveMQ Exploitation Java Spawning PowerShell Downloader (via process_creation)
Suspicious Cleo Autorun Health Check File Drop (via file_event)
Obfuscated IIS Worker Spawning Encoded PowerShell after SharePoint ToolShell (via process_creation)
Malicious PowerShell UrlDecode Payload Spawned by SQL Server after FortiClient EMS Exploitation
Pivot detection · T1059.001 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.