Windows findstr.exe Security Tool Keyword Lookup via Command Line
Alerts on Windows findstr.exe executions that filter output using security software and antivirus-related keywords.
FreeUnreviewedSigmamediumv1
windows-findstr-exe-security-tool-keyword-lookup-via-command-line-4fe074b4
title: Windows findstr.exe Security Tool Keyword Lookup via Command Line
id: 591d2d8c-1231-4da4-8e27-06509814d90c
related:
- id: fe63010f-8823-4864-a96b-a7b4a0f7b929
type: derived
- id: 4fe074b4-b833-4081-8f24-7dcfeca72b42
type: derived
status: test
description: This rule flags process executions of findstr.exe (or find.exe variants) whose command line ends with security-tool related keywords such as antivirus, specific vendor names, and other common security terms. Attackers may use findstr to filter command output during discovery and reconnaissance, focusing results on security-related indicators. It relies on Windows process creation telemetry capturing the executable path and command-line text.
references:
- https://github.com/redcanaryco/atomic-red-team/blob/987e3ca988ae3cff4b9f6e388c139c05bf44bbb8/atomics/T1518.001/T1518.001.md#atomic-test-1---security-software-discovery
- https://www.microsoft.com/en-us/security/blog/2023/10/18/multiple-north-korean-threat-actors-exploiting-the-teamcity-cve-2023-42793-vulnerability/
- https://www.hhs.gov/sites/default/files/manage-engine-vulnerability-sector-alert-tlpclear.pdf
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_findstr_security_keyword_lookup.yml
author: Nasreddine Bencherchali (Nextron Systems), frack113, Huntrule Team
date: 2023-10-20
modified: 2023-11-14
tags:
- attack.discovery
- attack.t1518.001
logsource:
category: process_creation
product: windows
detection:
selection_img:
- Image|endswith:
- \find.exe
- \findstr.exe
- OriginalFileName:
- FIND.EXE
- FINDSTR.EXE
selection_cli:
CommandLine|endswith:
- " avira"
- ' avira"'
- " cb"
- ' cb"'
- " cylance"
- ' cylance"'
- " defender"
- ' defender"'
- " kaspersky"
- ' kaspersky"'
- " kes"
- ' kes"'
- " mc"
- ' mc"'
- " sec"
- ' sec"'
- " sentinel"
- ' sentinel"'
- " symantec"
- ' symantec"'
- " virus"
- ' virus"'
condition: all of selection_*
falsepositives:
- Unknown
level: medium
regression_tests_path: regression_data/rules/windows/process_creation/proc_creation_win_findstr_security_keyword_lookup/info.yml
simulation:
- type: atomic-red-team
name: Security Software Discovery
technique: T1518.001
atomic_guid: f92a380f-ced9-491f-b338-95a991418ce2
license: DRL-1.1
What it detects
This rule flags process executions of findstr.exe (or find.exe variants) whose command line ends with security-tool related keywords such as antivirus, specific vendor names, and other common security terms. Attackers may use findstr to filter command output during discovery and reconnaissance, focusing results on security-related indicators. It relies on Windows process creation telemetry capturing the executable path and command-line text.
Known false positives
- Unknown
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.