Suspicious Data Exfiltration via finger to Remote Host

PremiumReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
HuntRule
Published
2026-09-28
Updated
2026-09-28

ATT&CK techniques

C2 → Exfiltration
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. Impact

What it detects

This rule detects execution of the legacy finger client against a remote host, abused in this case to exfiltrate directory and task listings and to pull down content over TCP port 79. The finger utility has virtually no legitimate use on modern Windows, so its execution against an external host indicates a living-off-the-land exfiltration or download channel.

Related detections9 linkedT1105 — drag to rearrange
Suspicious Data Transfer via curl to Raw IP Address
Suspicious Download or Exfiltration via Finger LOLBin
Suspicious File Download via PowerShell WebClient DownloadFile
Suspicious Remote HTA Execution via mshta over HTTP
Suspicious Encoded PowerShell DownloadString Execution
Malicious Remote MSI Install of RuntimeBroker via msiexec
Suspicious File Download via certutil urlcache
Suspicious Remote MSI Installation via msiexec from HTTP URL
Suspicious PowerShell Download Cradle via Invoke-WebRequest Piped to iex (via process_creation)
Suspicious Data Exfiltration via finger to Remote Host
Pivot detection · T1105 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.