Windows: Curl.exe Insecure Proxy/DOH Transfer Flags

Flags curl.exe with --proxy-insecure and/or --doh-insecure during Windows process execution.

FreeReviewedSigma · Medium · v2
Product
windows
Category
process_creation
Author
Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2023-07-27
Updated
2026-07-31

What it detects

This rule identifies process executions where curl.exe is run with insecure settings for proxy or DNS-over-HTTPS (DOH) transfers. Attackers may use these flags to bypass standard certificate and proxy validation, weakening transport security and enabling interception or redirection. It relies on Windows process creation telemetry, matching curl.exe by image/original filename and looking for the specific command-line options associated with insecure proxy or DOH behavior.

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.