Suspicious Cursor Editor Process Spawning PowerShell

PremiumReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
HuntRule
Published
2026-10-09
Updated
2026-10-09

ATT&CK techniques

Initial Access → Execution
  1. Recon

  2. Resource Dev

  3. Persistence

  4. Priv Esc

  5. Defense Evasion

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects the Cursor AI editor spawning PowerShell which a malicious open-source extension abuses to run its payload through the trusted editor process. This supply-chain compromise turned a Cursor package into a crypto heist that deployed Quasar and PureLogs via ScreenConnect. A code editor launching PowerShell is an uncommon and high-value execution path to monitor.

Related detections9 linkedT1059.001 — drag to rearrange
Suspicious GitVenom Visual Studio Pre-Build Event Shell Execution via process_creation
Suspicious PowerShell Base64 Encoded Staged Downloader via process_creation
Malicious PowerShell UrlDecode Payload Spawned by SQL Server after FortiClient EMS Exploitation
Suspicious PowerShell Version Pinning with Encoded Command
Suspicious Encoded PowerShell Spawned from Explorer via ClickFix
Suspicious MeshAgent Masquerading as NetworkDrivers Spawned by PowerShell
PowerShell ExportedCommands Array Index for Indirect Cmdlet Execution (Windows Process Creation)
Obfuscated PowerShell Script: Indirect Cmdlet Execution via ExportedCommands Array Index
Malicious Shadow Copy Deletion via WMI PowerShell
Suspicious Cursor Editor Process Spawning PowerShell
Pivot detection · T1059.001 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.