Suspicious Command Execution via ComSpec Environment Variable Obfuscation

PremiumReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
HuntRule
Published
2026-09-28
Updated
2026-09-28

ATT&CK techniques

Execution → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Persistence

  5. Priv Esc

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects command lines that reference the delayed-expansion ComSpec variable using the exclamation syntax, an obfuscation Raspberry Robin uses when piping junk-laden files into cmd. Legitimate command lines almost never contain this token, making it a reliable indicator of obfuscated batch execution.

Related detections9 linkedT1059.003 — drag to rearrange
Suspicious PIF Payload Assembly via copy /b Binary Concatenation
Obfuscated Encoded PowerShell Payload Deployed via Process Execution (via process_creation)
Malicious KB Document Masqueraded Executable Spawned by Script Interpreter via RoKRAT Loader (via process_creation)
Malicious Payload Assembly via MZ Header Prepend and copy Concatenation (via process_creation)
Suspicious File Concatenation via copy Binary Mode
Suspicious Hidden PowerShell Launched by Batch Script
Suspicious Command Shell Executing Batch Script from LNK Delivery
Suspicious PowerShell String Concatenation Obfuscation for Batch Extension via LNK (via process_creation)
Suspicious Office Application Spawning Script Interpreter Chain
Suspicious Command Execution via ComSpec Environment Variable Obfuscation
Pivot detection · T1059.003 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.