Windows: Detect MODE.COM Changing Code Page Settings
Detects MODE.COM executions that include code page selection parameters.
- Product
- windows
- Category
- process_creation
- Author
- Nasreddine Bencherchali (Nextron Systems), Joseliyo Sanchez, @Joseliyo_Jstnk (SigmaHQ), DRL 1.1
- Published
- 2024-01-19
- Updated
- 2026-07-31
ATT&CK techniques
Defense EvasionRecon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule flags process executions of MODE.COM where the command line includes typical parameters for changing code page and selecting a code page ("cp" and "select="). Attackers may use this to alter how text/console output is interpreted or recorded, which can affect operator visibility and downstream tooling. The detection relies on Windows process creation telemetry, matching the executable name/path and specific command-line substrings.
Reporting behind it
- learn.microsoft.comhttps://learn.microsoft.com/en-us/windows/win32/intl/code-page-identifiers
- learn.microsoft.comhttps://learn.microsoft.com/en-us/windows-server/administration/windows-commands/mode
- strontic.github.iohttps://strontic.github.io/xcyclopedia/library/mode.com-59D1ED51ACB8C3D50F1306FD75F20E99.html
- virustotal.comhttps://www.virustotal.com/gui/file/5e75ef02517afd6e8ba6462b19217dc4a5a574abb33d10eb0f2bab49d8d48c22/behavior
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules-threat-hunting/windows/process_creation/proc_creation_win_mode_codepage_change.yml
Changelog
v5- v5Candidate ingested via manual entry.2026-07-31
- v4Candidate ingested via manual entry.2026-07-31
- v3Candidate ingested via manual entry.2026-07-31
- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: "Windows: Detect MODE.COM Changing Code Page Settings"
id: 3e0928dd-4294-4a80-a1ee-22bb3ca30076
related:
- id: 12fbff88-16b5-4b42-9754-cd001a789fb3
type: derived
- id: d48c5ffa-3b02-4c0f-9a9e-3c275650dd0e
type: derived
status: test
description: This rule flags process executions of MODE.COM where the command line includes typical parameters for changing code page and selecting a code page ("cp" and "select="). Attackers may use this to alter how text/console output is interpreted or recorded, which can affect operator visibility and downstream tooling. The detection relies on Windows process creation telemetry, matching the executable name/path and specific command-line substrings.
references:
- https://learn.microsoft.com/en-us/windows/win32/intl/code-page-identifiers
- https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/mode
- https://strontic.github.io/xcyclopedia/library/mode.com-59D1ED51ACB8C3D50F1306FD75F20E99.html
- https://www.virustotal.com/gui/file/5e75ef02517afd6e8ba6462b19217dc4a5a574abb33d10eb0f2bab49d8d48c22/behavior
- https://github.com/SigmaHQ/sigma/blob/master/rules-threat-hunting/windows/process_creation/proc_creation_win_mode_codepage_change.yml
author: Nasreddine Bencherchali (Nextron Systems), Joseliyo Sanchez, @Joseliyo_Jstnk, Huntrule Team
date: 2024-01-19
tags:
- attack.stealth
- attack.t1036
- detection.threat-hunting
logsource:
category: process_creation
product: windows
detection:
selection_img:
- Image|endswith: \mode.com
- OriginalFileName: MODE.COM
selection_cli:
CommandLine|contains|all:
- " con "
- " cp "
- " select="
condition: all of selection_*
falsepositives:
- Unknown
level: low
license: DRL-1.1