Windows CHCP Console Code Page Lookup Triggered From cmd.exe

Flags cmd.exe-launched chcp.com executions likely used to query system code page/locale for discovery.

FreeReviewedSigma · Medium · v2
Product
windows
Category
process_creation
Author
_pete_0, TheDFIRReport (SigmaHQ), DRL 1.1
Published
2022-02-21
Updated
2026-07-31

ATT&CK techniques

Discovery
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule identifies process creation where cmd.exe launches chcp.com with a command line that invokes CHCP. The activity is used to query system code page or locale-related values during host discovery, which can support reconnaissance prior to other actions. It relies on Windows process creation telemetry including ParentImage, ParentCommandLine, Image, and CommandLine fields.

Related detections3 linkedT1614.001 — drag to rearrange
CHCP CodePage Locale Lookup
Suspicious External IP Discovery via api.ipify.org
Windows Registry Query for System Language Using reg.exe
Windows CHCP Console Code Page Lookup Triggered From cmd.exe
Pivot detection · T1614.001 · 3 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.