Windows GoAnywhere MFT exploitation: suspicious PowerShell and cmd child process activity
Flags Windows process trees where GoAnywhere Tomcat spawns suspicious cmd/PowerShell command lines consistent with exploitation activity.
FreeUnreviewedSigmahighv1
windows-goanywhere-mft-exploitation-suspicious-powershell-and-cmd-child-process--6c76b3d0
title: "Windows GoAnywhere MFT exploitation: suspicious PowerShell and cmd child process activity"
id: da6f9601-94b8-49d7-8021-8a0bcca3ee3c
status: experimental
description: This rule identifies potentially malicious post-exploitation behavior by looking for GoAnywhere Tomcat processes spawning suspicious child command executions. It matches child processes such as cmd.exe along with command lines referencing common recon and download/execution patterns, including PowerShell flags indicative of obfuscated or hidden execution. The detection relies on Windows process creation telemetry, using parent/child image paths and command-line content patterns to flag behavior consistent with active exploitation and subsequent attacker tooling.
references:
- https://www.microsoft.com/en-us/security/blog/2025/10/06/investigating-active-exploitation-of-cve-2025-10035-goanywhere-managed-file-transfer-vulnerability/
- https://github.com/SigmaHQ/sigma/blob/master/rules-emerging-threats/2025/Exploits/CVE-2025-10035/proc_creation_win_exploit_cve_2025_10035.yml
author: MSFT (idea), Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule Team
date: 2025-10-07
tags:
- attack.initial-access
- attack.t1190
- attack.execution
- attack.t1059.001
- attack.persistence
- attack.t1133
- detection.emerging-threats
- cve.2025-10035
logsource:
category: process_creation
product: windows
detection:
selection_parent:
ParentImage|contains: \GoAnywhere\tomcat\
selection_powershell_img:
Image|endswith:
- \powershell.exe
- \powershell_ise.exe
- \pwsh.exe
selection_powershell_cmd:
- CommandLine|contains|all:
- IEX
- enc
- Hidden
- bypass
- CommandLine|re:
- net\s+user
- net\s+group
- query\s+session
- CommandLine|contains:
- whoami
- systeminfo
- dsquery
- localgroup administrators
- nltest
- samaccountname=
- adscredentials
- o365accountconfiguration
- .DownloadString(
- .DownloadFile(
- FromBase64String(
- System.IO.Compression
- System.IO.MemoryStream
- curl
selection_child_cmd:
Image|endswith: \cmd.exe
CommandLine|contains:
- powershell
- whoami
- net.exe
- net1.exe
- rundll32
- quser
- nltest
- curl
selection_child_others:
CommandLine|contains:
- bitsadmin
- certutil
- mshta
- cscript
- wscript
condition: selection_parent and (all of selection_powershell_* or 1 of selection_child_*)
falsepositives:
- Legitimate administrative scripts or built-in GoAnywhere functions could potentially trigger this rule. Tuning may be required based on normal activity in your environment.
level: high
license: DRL-1.1
related:
- id: 6c76b3d0-afe4-4870-9443-ffe6773c5fef
type: derived
What it detects
This rule identifies potentially malicious post-exploitation behavior by looking for GoAnywhere Tomcat processes spawning suspicious child command executions. It matches child processes such as cmd.exe along with command lines referencing common recon and download/execution patterns, including PowerShell flags indicative of obfuscated or hidden execution. The detection relies on Windows process creation telemetry, using parent/child image paths and command-line content patterns to flag behavior consistent with active exploitation and subsequent attacker tooling.
Known false positives
- Legitimate administrative scripts or built-in GoAnywhere functions could potentially trigger this rule. Tuning may be required based on normal activity in your environment.
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.