Suspicious MSSQL xp_cmdshell Enablement via sp_configure (via process_creation)

PremiumReviewedSigma · High · v1
Category
process_creation
Author
HuntRule
Published
2026-10-10
Updated
2026-10-10

ATT&CK techniques

Execution
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule detects command lines that enable the MSSQL xp_cmdshell feature through sp_configure, a preparatory step used in the printer-and-BitLocker extortion scheme to unlock operating system command execution from the database. Enabling xp_cmdshell is a strong indicator of an attacker preparing to run OS commands via a compromised SQL server.

Related detections9 linkedT1059 — drag to rearrange
Suspicious Reconnaissance and Payload Download by Node Web Process
Malicious Netcat Reverse Shell via Masqueraded StartMenuExperienceHost
Malicious Text4Shell Apache Commons Text Interpolation Payload in HTTP Request
Malicious SolarWinds BusinessLayerHost Spawning Command Interpreter
Possible Apache ActiveMQ RCE via Jolokia addNetworkConnector (via webserver)
Possible LiteLLM Unauthenticated Command Execution via MCP Test Endpoints (via webserver)
Possible Ivanti Cloud Services Appliance Command Injection via datetime.php (via webserver)
Possible Log4Shell Exploitation via Java Spawning Shell or Download Utility
AutoIt Script Execution via A3X Payload
Suspicious MSSQL xp_cmdshell Enablement via sp_configure (via process_creation)
Pivot detection · T1059 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.