Windows GoAnywhere MFT exploitation: suspicious PowerShell and cmd child process activity

Flags Windows process trees where GoAnywhere Tomcat spawns suspicious cmd/PowerShell command lines consistent with exploitation activity.

FreeUnreviewedSigmahighv1
title: "Windows GoAnywhere MFT exploitation: suspicious PowerShell and cmd child process activity"
id: da6f9601-94b8-49d7-8021-8a0bcca3ee3c
status: experimental
description: This rule identifies potentially malicious post-exploitation behavior by looking for GoAnywhere Tomcat processes spawning suspicious child command executions. It matches child processes such as cmd.exe along with command lines referencing common recon and download/execution patterns, including PowerShell flags indicative of obfuscated or hidden execution. The detection relies on Windows process creation telemetry, using parent/child image paths and command-line content patterns to flag behavior consistent with active exploitation and subsequent attacker tooling.
references:
  - https://www.microsoft.com/en-us/security/blog/2025/10/06/investigating-active-exploitation-of-cve-2025-10035-goanywhere-managed-file-transfer-vulnerability/
  - https://github.com/SigmaHQ/sigma/blob/master/rules-emerging-threats/2025/Exploits/CVE-2025-10035/proc_creation_win_exploit_cve_2025_10035.yml
author: MSFT (idea), Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule Team
date: 2025-10-07
tags:
  - attack.initial-access
  - attack.t1190
  - attack.execution
  - attack.t1059.001
  - attack.persistence
  - attack.t1133
  - detection.emerging-threats
  - cve.2025-10035
logsource:
  category: process_creation
  product: windows
detection:
  selection_parent:
    ParentImage|contains: \GoAnywhere\tomcat\
  selection_powershell_img:
    Image|endswith:
      - \powershell.exe
      - \powershell_ise.exe
      - \pwsh.exe
  selection_powershell_cmd:
    - CommandLine|contains|all:
        - IEX
        - enc
        - Hidden
        - bypass
    - CommandLine|re:
        - net\s+user
        - net\s+group
        - query\s+session
    - CommandLine|contains:
        - whoami
        - systeminfo
        - dsquery
        - localgroup administrators
        - nltest
        - samaccountname=
        - adscredentials
        - o365accountconfiguration
        - .DownloadString(
        - .DownloadFile(
        - FromBase64String(
        - System.IO.Compression
        - System.IO.MemoryStream
        - curl
  selection_child_cmd:
    Image|endswith: \cmd.exe
    CommandLine|contains:
      - powershell
      - whoami
      - net.exe
      - net1.exe
      - rundll32
      - quser
      - nltest
      - curl
  selection_child_others:
    CommandLine|contains:
      - bitsadmin
      - certutil
      - mshta
      - cscript
      - wscript
  condition: selection_parent and (all of selection_powershell_* or 1 of selection_child_*)
falsepositives:
  - Legitimate administrative scripts or built-in GoAnywhere functions could potentially trigger this rule. Tuning may be required based on normal activity in your environment.
level: high
license: DRL-1.1
related:
  - id: 6c76b3d0-afe4-4870-9443-ffe6773c5fef
    type: derived

What it detects

This rule identifies potentially malicious post-exploitation behavior by looking for GoAnywhere Tomcat processes spawning suspicious child command executions. It matches child processes such as cmd.exe along with command lines referencing common recon and download/execution patterns, including PowerShell flags indicative of obfuscated or hidden execution. The detection relies on Windows process creation telemetry, using parent/child image paths and command-line content patterns to flag behavior consistent with active exploitation and subsequent attacker tooling.

Known false positives

  • Legitimate administrative scripts or built-in GoAnywhere functions could potentially trigger this rule. Tuning may be required based on normal activity in your environment.

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.