Windows Non-Browser Process Communicating with Notion API
Alerts when a non-browser Windows process connects to api.notion.com, excluding common browsers and the Notion desktop app.
FreeUnreviewedSigmalowv1
windows-non-browser-process-communicating-with-notion-api-7e9cf7b6
title: Windows Non-Browser Process Communicating with Notion API
id: a32bc2b1-cf12-4353-9a6a-d50ea55a22d0
status: test
description: This rule flags network connections to the Notion API endpoint (api.notion.com) when the initiating process is not one of the explicitly allowed browser executables and is not Notion.exe located under the Notion application path. Attackers may use legitimate web APIs for command-and-control or data exchange from non-browser tooling. It relies on Windows network connection telemetry that includes the destination hostname and the connecting process image path.
references:
- https://github.com/mttaggart/OffensiveNotion
- https://medium.com/@huskyhacks.mk/we-put-a-c2-in-your-notetaking-app-offensivenotion-3e933bace332
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/network_connection/net_connection_win_domain_notion_api_susp_communication.yml
author: Gavin Knapp, Huntrule Team
date: 2023-05-03
tags:
- attack.command-and-control
- attack.t1102
logsource:
product: windows
category: network_connection
detection:
selection:
DestinationHostname|contains: api.notion.com
filter_main_notion:
Image|endswith: \AppData\Local\Programs\Notion\Notion.exe
filter_main_brave:
Image|endswith: \brave.exe
filter_main_chrome:
Image:
- C:\Program Files\Google\Chrome\Application\chrome.exe
- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
filter_main_firefox:
Image:
- C:\Program Files\Mozilla Firefox\firefox.exe
- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
filter_main_ie:
Image:
- C:\Program Files (x86)\Internet Explorer\iexplore.exe
- C:\Program Files\Internet Explorer\iexplore.exe
filter_main_maxthon:
Image|endswith: \maxthon.exe
filter_main_edge_1:
- Image|startswith: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\
- Image|endswith: \WindowsApps\MicrosoftEdge.exe
- Image:
- C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
- C:\Program Files\Microsoft\Edge\Application\msedge.exe
filter_main_edge_2:
Image|startswith:
- C:\Program Files (x86)\Microsoft\EdgeCore\
- C:\Program Files\Microsoft\EdgeCore\
Image|endswith:
- \msedge.exe
- \msedgewebview2.exe
filter_main_opera:
Image|endswith: \opera.exe
filter_main_safari:
Image|endswith: \safari.exe
filter_main_seamonkey:
Image|endswith: \seamonkey.exe
filter_main_vivaldi:
Image|endswith: \vivaldi.exe
filter_main_whale:
Image|endswith: \whale.exe
condition: selection and not 1 of filter_main_*
falsepositives:
- Legitimate applications communicating with the "api.notion.com" endpoint that are not already in the exclusion list. The desktop and browser applications do not appear to be using the API by default unless integrations are configured.
level: low
license: DRL-1.1
related:
- id: 7e9cf7b6-e827-11ed-a05b-15959c120003
type: derived
What it detects
This rule flags network connections to the Notion API endpoint (api.notion.com) when the initiating process is not one of the explicitly allowed browser executables and is not Notion.exe located under the Notion application path. Attackers may use legitimate web APIs for command-and-control or data exchange from non-browser tooling. It relies on Windows network connection telemetry that includes the destination hostname and the connecting process image path.
Known false positives
- Legitimate applications communicating with the "api.notion.com" endpoint that are not already in the exclusion list. The desktop and browser applications do not appear to be using the API by default unless integrations are configured.
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.