Windows MSSQL xp_cmdshell Command Execution via Application Event 33205

Alerts when SQL Server xp_cmdshell is invoked to execute commands, using Windows application EventID 33205 data.

FreeReviewedSigma · High · v2
Product
windows
Service
application
Author
Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2022-07-12
Updated
2026-07-31

What it detects

This rule identifies use of the MSSQL xp_cmdshell stored procedure by matching application log events with EventID 33205 that contain an EXEC statement targeting object_name xp_cmdshell. xp_cmdshell is a common post-exploitation mechanism because it enables SQL Server to execute operating system commands from within the database context. It relies on Windows application logging that includes MSSQL audit events carrying the xp_cmdshell and EXEC details.

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.