Malicious SQL Server Command Execution Spawning Download Utilities via Process Creation

PremiumReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
HuntRule
Published
2026-09-17
Updated
2026-09-17

ATT&CK techniques

Execution → Persistence
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Priv Esc

  5. Defense Evasion

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects the SQL Server service process spawning download capable utilities such as certutil bitsadmin powershell or cmd which in the REF0657 financial services intrusion followed xp_cmdshell abuse to pull tooling onto a compromised database server. The database engine launching these binaries indicates command execution through SQL and should not occur in normal operation.

Related detections9 linkedT1059.001 — drag to rearrange
Malicious Command Shell Spawned by SQL Server via xp_cmdshell
Suspicious Script Host Spawning PowerShell via Process Creation
Suspicious PIKABOT PowerShell Download to Public Directory via Process Creation
Suspicious PowerShell Script Fetching Remote Batch File From Paste Site (via ps_script)
Suspicious PowerShell Download of Payload From Pastebin (via process_creation)
Suspicious PowerShell Interaction with ProgramData SysInt Log via Process Creation
Suspicious Node.js Spawning Script Interpreter for Dropped Payload
Suspicious PowerShell Remote Download and Execution via Invoke-WebRequest
Suspicious Script Host Spawning Hidden PowerShell (via process_creation)
Malicious SQL Server Command Execution Spawning Download Utilities via Process Creation
Pivot detection · T1059.001 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.