Windows Process Creation: GoAnywhere child command execution indicating possible MFT exploitation

Flags Windows process trees where GoAnywhere Tomcat spawns suspicious cmd/PowerShell command lines consistent with exploitation activity.

FreeReviewedSigma · High · v5
Product
windows
Category
process_creation
Author
MSFT (idea), Swachchhanda Shrawan Poudel (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2025-10-07
Updated
2026-07-31

ATT&CK techniques

Initial Access → Persistence
  1. Recon

  2. Resource Dev

  3. Priv Esc

  4. Defense Evasion

  5. Cred Access

  6. Discovery

  7. Lateral Movement

  8. Collection

  9. C2

  10. Exfiltration

  11. Impact

What it detects

This rule flags suspicious command execution spawned by child processes of the GoAnywhere Managed File Transfer (MFT) Tomcat process. It matters because exploitation or post-exploitation activity may run discovery and credential/command-and-control related commands via PowerShell and common Windows utilities. The detection relies on Windows process creation telemetry, including parent/child image paths, command-line arguments, and process relationships.

Related detections9 linkedT1059.001 — drag to rearrange
Suspicious SharePoint Worker Process Spawning Command Interpreter via ToolShell
Malicious ActiveMQ Exploitation Java Spawning PowerShell Downloader (via process_creation)
Suspicious Cleo Autorun Health Check File Drop (via file_event)
Obfuscated IIS Worker Spawning Encoded PowerShell after SharePoint ToolShell (via process_creation)
Malicious WSUS Service Spawning Command Shell via Remote Code Execution
Malicious PowerShell Spawned by IIS Worker Process via OWASSRF Exchange Exploitation (via process_creation)
Suspicious Child Process Spawned From Java Following Web Exploitation
Suspicious IIS Worker Process Spawning Encoded PowerShell via Gladinet Exploitation
MSSQL Server Process Spawning Command Shell via xp_cmdshell
Windows Process Creation: GoAnywhere child command execution indicating possible MFT exploitation
Pivot detection · T1059.001 · 9 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.