Windows: AnyDesk Password Piped via CMD Using --set-password
Alerts on Windows command lines that echo a value and set an AnyDesk password non-interactively via --set-password.
- Product
- windows
- Category
- process_creation
- Author
- Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
- Published
- 2022-09-28
- Updated
- 2026-07-30
ATT&CK techniques
C2Recon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
Exfiltration
Impact
What it detects
This rule flags process executions where command lines include a CMD invocation that echoes a value and runs AnyDesk with the --set-password flag. Attackers may use this to automate credential setup for remote access tools without interactive input. The detection relies on Windows process creation telemetry and matches specific command-line substrings associated with piping a password through CMD.
Reporting behind it
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: "Windows: AnyDesk Password Piped via CMD Using --set-password"
id: cd656cde-34f8-49ab-9f3a-b12519460534
status: test
description: This rule flags process executions where command lines include a CMD invocation that echoes a value and runs AnyDesk with the --set-password flag. Attackers may use this to automate credential setup for remote access tools without interactive input. The detection relies on Windows process creation telemetry and matches specific command-line substrings associated with piping a password through CMD.
references:
- https://redcanary.com/blog/misbehaving-rats/
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_remote_access_tools_anydesk_piped_password_via_cli.yml
author: Nasreddine Bencherchali (Nextron Systems), Huntrule Team
date: 2022-09-28
modified: 2023-03-05
tags:
- attack.command-and-control
- attack.t1219.002
logsource:
category: process_creation
product: windows
detection:
selection:
CommandLine|contains|all:
- "/c "
- "echo "
- .exe --set-password
condition: selection
falsepositives:
- Legitimate piping of the password to anydesk
- Some FP could occur with similar tools that uses the same command line '--set-password'
level: medium
license: DRL-1.1
related:
- id: b1377339-fda6-477a-b455-ac0923f9ec2c
type: derived