Windows findstr.exe Security Tool Keyword Lookup via Command Line

Alerts on Windows findstr.exe executions that filter output using security software and antivirus-related keywords.

FreeUnreviewedSigmamediumv1
title: Windows findstr.exe Security Tool Keyword Lookup via Command Line
id: 591d2d8c-1231-4da4-8e27-06509814d90c
related:
  - id: fe63010f-8823-4864-a96b-a7b4a0f7b929
    type: derived
  - id: 4fe074b4-b833-4081-8f24-7dcfeca72b42
    type: derived
status: test
description: This rule flags process executions of findstr.exe (or find.exe variants) whose command line ends with security-tool related keywords such as antivirus, specific vendor names, and other common security terms. Attackers may use findstr to filter command output during discovery and reconnaissance, focusing results on security-related indicators. It relies on Windows process creation telemetry capturing the executable path and command-line text.
references:
  - https://github.com/redcanaryco/atomic-red-team/blob/987e3ca988ae3cff4b9f6e388c139c05bf44bbb8/atomics/T1518.001/T1518.001.md#atomic-test-1---security-software-discovery
  - https://www.microsoft.com/en-us/security/blog/2023/10/18/multiple-north-korean-threat-actors-exploiting-the-teamcity-cve-2023-42793-vulnerability/
  - https://www.hhs.gov/sites/default/files/manage-engine-vulnerability-sector-alert-tlpclear.pdf
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_findstr_security_keyword_lookup.yml
author: Nasreddine Bencherchali (Nextron Systems), frack113, Huntrule Team
date: 2023-10-20
modified: 2023-11-14
tags:
  - attack.discovery
  - attack.t1518.001
logsource:
  category: process_creation
  product: windows
detection:
  selection_img:
    - Image|endswith:
        - \find.exe
        - \findstr.exe
    - OriginalFileName:
        - FIND.EXE
        - FINDSTR.EXE
  selection_cli:
    CommandLine|endswith:
      - " avira"
      - ' avira"'
      - " cb"
      - ' cb"'
      - " cylance"
      - ' cylance"'
      - " defender"
      - ' defender"'
      - " kaspersky"
      - ' kaspersky"'
      - " kes"
      - ' kes"'
      - " mc"
      - ' mc"'
      - " sec"
      - ' sec"'
      - " sentinel"
      - ' sentinel"'
      - " symantec"
      - ' symantec"'
      - " virus"
      - ' virus"'
  condition: all of selection_*
falsepositives:
  - Unknown
level: medium
regression_tests_path: regression_data/rules/windows/process_creation/proc_creation_win_findstr_security_keyword_lookup/info.yml
simulation:
  - type: atomic-red-team
    name: Security Software Discovery
    technique: T1518.001
    atomic_guid: f92a380f-ced9-491f-b338-95a991418ce2
license: DRL-1.1

What it detects

This rule flags process executions of findstr.exe (or find.exe variants) whose command line ends with security-tool related keywords such as antivirus, specific vendor names, and other common security terms. Attackers may use findstr to filter command output during discovery and reconnaissance, focusing results on security-related indicators. It relies on Windows process creation telemetry capturing the executable path and command-line text.

Known false positives

  • Unknown

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.