Suspicious Host Reconnaissance Command Chain via cmd

PremiumReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
HuntRule
Published
2026-10-09
Updated
2026-10-09

ATT&CK techniques

Execution → Discovery
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects a single command shell invocation chaining whoami, tasklist, systeminfo and netstat reconnaissance commands. The Notepad++ supply chain attack ran this exact recon chain and redirected the results to a file as reported by Kaspersky. Bundling these discovery commands in one shell line is a strong automated reconnaissance indicator.

Related detections9 linkedT1059.003 — drag to rearrange
Suspicious Reconnaissance Commands Spawned by Samsung MagicINFO Server
Cisco AAA discovery via show/dir commands
Suspicious Child Process Spawned by Notepad++ Updater GUP
Suspicious PIF AutoIt Interpreter Executing a3x Compiled Script
Malicious Netcat SSL Reverse Shell Execution via process_creation
Suspicious Executable Execution From Users Public Directory via Process Creation
Malicious DinodasRAT Hidden Config File Creation on Linux (via file_event)
Malicious Child Process Spawned From n8n Node Process
Malicious IIS w3wp Worker Spawning Command Interpreter via SharePoint Web Shell
Suspicious Host Reconnaissance Command Chain via cmd
Pivot detection · T1059.003 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.