Windows Non-Browser Process Communicating with Notion API

Alerts when a non-browser Windows process connects to api.notion.com, excluding common browsers and the Notion desktop app.

FreeUnreviewedSigmalowv1
title: Windows Non-Browser Process Communicating with Notion API
id: a32bc2b1-cf12-4353-9a6a-d50ea55a22d0
status: test
description: This rule flags network connections to the Notion API endpoint (api.notion.com) when the initiating process is not one of the explicitly allowed browser executables and is not Notion.exe located under the Notion application path. Attackers may use legitimate web APIs for command-and-control or data exchange from non-browser tooling. It relies on Windows network connection telemetry that includes the destination hostname and the connecting process image path.
references:
  - https://github.com/mttaggart/OffensiveNotion
  - https://medium.com/@huskyhacks.mk/we-put-a-c2-in-your-notetaking-app-offensivenotion-3e933bace332
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/network_connection/net_connection_win_domain_notion_api_susp_communication.yml
author: Gavin Knapp, Huntrule Team
date: 2023-05-03
tags:
  - attack.command-and-control
  - attack.t1102
logsource:
  product: windows
  category: network_connection
detection:
  selection:
    DestinationHostname|contains: api.notion.com
  filter_main_notion:
    Image|endswith: \AppData\Local\Programs\Notion\Notion.exe
  filter_main_brave:
    Image|endswith: \brave.exe
  filter_main_chrome:
    Image:
      - C:\Program Files\Google\Chrome\Application\chrome.exe
      - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
  filter_main_firefox:
    Image:
      - C:\Program Files\Mozilla Firefox\firefox.exe
      - C:\Program Files (x86)\Mozilla Firefox\firefox.exe
  filter_main_ie:
    Image:
      - C:\Program Files (x86)\Internet Explorer\iexplore.exe
      - C:\Program Files\Internet Explorer\iexplore.exe
  filter_main_maxthon:
    Image|endswith: \maxthon.exe
  filter_main_edge_1:
    - Image|startswith: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\
    - Image|endswith: \WindowsApps\MicrosoftEdge.exe
    - Image:
        - C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
        - C:\Program Files\Microsoft\Edge\Application\msedge.exe
  filter_main_edge_2:
    Image|startswith:
      - C:\Program Files (x86)\Microsoft\EdgeCore\
      - C:\Program Files\Microsoft\EdgeCore\
    Image|endswith:
      - \msedge.exe
      - \msedgewebview2.exe
  filter_main_opera:
    Image|endswith: \opera.exe
  filter_main_safari:
    Image|endswith: \safari.exe
  filter_main_seamonkey:
    Image|endswith: \seamonkey.exe
  filter_main_vivaldi:
    Image|endswith: \vivaldi.exe
  filter_main_whale:
    Image|endswith: \whale.exe
  condition: selection and not 1 of filter_main_*
falsepositives:
  - Legitimate applications communicating with the "api.notion.com" endpoint that are not already in the exclusion list. The desktop and browser applications do not appear to be using the API by default unless integrations are configured.
level: low
license: DRL-1.1
related:
  - id: 7e9cf7b6-e827-11ed-a05b-15959c120003
    type: derived

What it detects

This rule flags network connections to the Notion API endpoint (api.notion.com) when the initiating process is not one of the explicitly allowed browser executables and is not Notion.exe located under the Notion application path. Attackers may use legitimate web APIs for command-and-control or data exchange from non-browser tooling. It relies on Windows network connection telemetry that includes the destination hostname and the connecting process image path.

Known false positives

  • Legitimate applications communicating with the "api.notion.com" endpoint that are not already in the exclusion list. The desktop and browser applications do not appear to be using the API by default unless integrations are configured.

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.