Windows DataSvcUtil.exe Command-Line Exfiltration Using /in:, /out:, and /uri:

Alerts on DataSvcUtil.exe runs with /in:, /out:, and /uri: parameters that may indicate data exfiltration activity.

FreeReviewedSigma · Medium · v2
Product
windows
Category
process_creation
Author
Ialle Teixeira @teixeira0xfffff, Austin Songer @austinsonger (SigmaHQ), DRL 1.1
Published
2021-09-30
Updated
2026-07-31

ATT&CK techniques

Exfiltration
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. C2

  13. Impact

What it detects

This rule identifies potential data exfiltration activity when DataSvcUtil.exe is executed with command-line parameters indicating input (/in:), output (/out:), and a service endpoint (/uri:). Such usage can be abused to collect or marshal data from a targeted source and then write it to an output location for transfer. The detection relies on Windows process creation telemetry, specifically the executable image and command-line contents.

Related detections9 linkedT1567 — drag to rearrange
Malicious Destructive Recursive Delete of Home Directory
Malicious Madgicx Plus Extension C2 Domain Resolution
Suspicious Credential Exfiltration to webhook.site (via dns_query)
Suspicious HTTP POST to Local AI Malware Exfil Endpoint (via proxy)
Malicious Mini Shai-Hulud TanStack C2 git-tanstack and getsession (via dns_query)
Suspicious Data Exfiltration to Webhook.site via Command Line (via process_creation)
Malicious GitHub Repository Creation With s1ngularity Exfiltration Name
Suspicious SNS Email Subscription for Data Exfiltration
Suspicious Azure OpenAI Training File Upload via Files Import Operation (via azure)
Windows DataSvcUtil.exe Command-Line Exfiltration Using /in:, /out:, and /uri:
Pivot detection · T1567 · 9 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.