Suspicious node.exe Spawning tasklist Process Enumeration

PremiumReviewedSigma · Medium · v1
Product
windows
Category
process_creation
Author
HuntRule
Published
2026-09-22
Updated
2026-09-22

ATT&CK techniques

Discovery
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule detects a Node.js process spawning tasklist with CSV no-header output, the process-enumeration recon used by OmniStealer to identify security tooling. The malware parsed the CSV process list to hash and match process names before attempting to terminate defenders. A node.exe parent running tasklist in this scripted format indicates automated host reconnaissance by the RAT.

Related detections9 linkedT1057 — drag to rearrange
Suspicious Virtual Machine Detection via WMI Win32_Process Query (via process_creation)
Antivirus Software Discovery via tasklist and findstr
Suspicious Security Software Discovery via tasklist and findstr (via process_creation)
Suspicious Security Process Enumeration via Tasklist And Findstr
Suspicious ESXi Virtual Machine Enumeration via esxcli Process List
Linux sysinfo Syscall for System Information Discovery
Windows: Recon command output piped to findstr.exe
Windows Process Execution of PCHunter (PCHunter64.exe or PCHunter32.exe)
Windows PowerShell: Suspicious Process Discovery Using Get-Process
Suspicious node.exe Spawning tasklist Process Enumeration
Pivot detection · T1057 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.