Windows Process Execution: curl.exe Downloading Files From an IP URL

Flags curl.exe commands that download via an IP-based URL using output/remote-name flags.

FreeReviewedSigma · Medium · v2
Product
windows
Category
process_creation
Author
Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2023-10-18
Updated
2026-07-31

What it detects

This rule identifies Windows process creation events where curl.exe is executed with a URL that directly contains an IPv4 address. It looks for command-line patterns consistent with HTTP/URL usage and file output flags (such as --output or -O). Excluding common executable and script/media extensions helps reduce overlap with related detections. Telemetry relied upon is Windows process creation command-line data, including Image/OriginalFileName and CommandLine content.

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.