Windows node.exe Execution with -e/--eval and suspicious child process usage
Alerts on node.exe started with -e/--eval and command-line indicators of child_process and net.socket connect activity.
- Product
- windows
- Category
- process_creation
- Author
- Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
- Published
- 2022-09-09
- Updated
- 2026-07-30
ATT&CK techniques
Execution → Defense EvasionRecon
Resource Dev
Initial Access
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule flags process creation events where node.exe is launched from a path ending in \node.exe with command-line usage of either " -e " or " --eval ". It further looks for abuse patterns consistent with spawning child_process and establishing outbound connectivity via net.socket connect sequences. This matters because Node.js inline evaluation can be used to run arbitrary attacker-supplied JavaScript, often leading to follow-on payload execution such as reverse shells. The detection relies on Windows process creation telemetry including the image path and full command line arguments.
Reporting behind it
- blog.talosintelligence.comhttp://blog.talosintelligence.com/2022/09/lazarus-three-rats.html
- sprocketsecurity.comhttps://www.sprocketsecurity.com/resources/crossing-the-log4j-horizon-a-vulnerability-with-no-return
- rapid7.comhttps://www.rapid7.com/blog/post/2022/01/18/active-exploitation-of-vmware-horizon-servers/
- nodejs.orghttps://nodejs.org/api/cli.html
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_node_abuse.yml
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: Windows node.exe Execution with -e/--eval and suspicious child process usage
id: 1dfd2279-aadc-4bdb-a894-1661ee6bfb99
status: test
description: This rule flags process creation events where node.exe is launched from a path ending in \node.exe with command-line usage of either " -e " or " --eval ". It further looks for abuse patterns consistent with spawning child_process and establishing outbound connectivity via net.socket connect sequences. This matters because Node.js inline evaluation can be used to run arbitrary attacker-supplied JavaScript, often leading to follow-on payload execution such as reverse shells. The detection relies on Windows process creation telemetry including the image path and full command line arguments.
references:
- http://blog.talosintelligence.com/2022/09/lazarus-three-rats.html
- https://www.sprocketsecurity.com/resources/crossing-the-log4j-horizon-a-vulnerability-with-no-return
- https://www.rapid7.com/blog/post/2022/01/18/active-exploitation-of-vmware-horizon-servers/
- https://nodejs.org/api/cli.html
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_node_abuse.yml
author: Nasreddine Bencherchali (Nextron Systems), Huntrule Team
date: 2022-09-09
modified: 2023-02-03
tags:
- attack.execution
- attack.stealth
- attack.t1127
logsource:
category: process_creation
product: windows
detection:
selection_main:
Image|endswith: \node.exe
CommandLine|contains:
- " -e "
- " --eval "
selection_action_reverse_shell:
CommandLine|contains|all:
- .exec(
- net.socket
- .connect
- child_process
condition: selection_main and 1 of selection_action_*
falsepositives:
- Unlikely
level: high
license: DRL-1.1
related:
- id: 6640f31c-01ad-49b5-beb5-83498a5cd8bd
type: derived