Windows netsh Trace Start Command Execution

Flags netsh.exe launched with "trace" and "start", commonly used to begin a network trace capture on Windows.

FreeUnreviewedSigmamediumv1
title: Windows netsh Trace Start Command Execution
id: 4eb7d324-a865-491a-b8a8-ffa4a8023ddf
status: test
description: This rule identifies process creation of netsh.exe where the command line includes both the keywords "trace" and "start", indicating a network trace capture is being initiated. Attackers can use built-in Windows tooling like netsh to collect network activity for discovery or investigation without installing additional software. The detection relies on Windows process creation telemetry, matching the process image/original filename and the presence of the specified command-line terms.
references:
  - https://blogs.msdn.microsoft.com/canberrapfe/2012/03/30/capture-a-network-trace-without-installing-anything-capture-a-network-trace-of-a-reboot/
  - https://klausjochem.me/2016/02/03/netsh-the-cyber-attackers-tool-of-choice/
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_netsh_packet_capture.yml
author: Kutepov Anton, oscd.community, Huntrule Team
date: 2019-10-24
modified: 2023-02-13
tags:
  - attack.discovery
  - attack.credential-access
  - attack.t1040
logsource:
  category: process_creation
  product: windows
detection:
  selection_img:
    - Image|endswith: \netsh.exe
    - OriginalFileName: netsh.exe
  selection_cli:
    CommandLine|contains|all:
      - trace
      - start
  condition: all of selection_*
falsepositives:
  - Legitimate administration activity
level: medium
license: DRL-1.1
related:
  - id: d3c3861d-c504-4c77-ba55-224ba82d0118
    type: derived

What it detects

This rule identifies process creation of netsh.exe where the command line includes both the keywords "trace" and "start", indicating a network trace capture is being initiated. Attackers can use built-in Windows tooling like netsh to collect network activity for discovery or investigation without installing additional software. The detection relies on Windows process creation telemetry, matching the process image/original filename and the presence of the specified command-line terms.

Known false positives

  • Legitimate administration activity

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.