Windows Process Command-Line Containing Unicode Right-to-Left Override (U+202E)

Alerts on Windows process launches with command lines containing Unicode U+202E to support right-to-left text obfuscation.

FreeReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
Micah Babinski, @micahbabinski, Swachchhanda Shrawan Poudel (Nextron Systems), Luc Génaux (SigmaHQ), DRL 1.1
Published
2023-02-15
Updated
2026-07-30

ATT&CK techniques

Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule flags Windows process creation events whose command line contains the Unicode Right-to-Left Override character (U+202E) or its textual representation. Attackers may use this character to obfuscate filenames or content and mislead users by changing the displayed text order. The detection relies on process creation telemetry with access to the full command line string.

Related detections2 linkedT1036.002 — drag to rearrange
Windows MMC Executes Files with RLO-Reversed Extensions in Process Command Line
Windows File Event: Detect RTLO Filename Extension Spoofing
Windows Process Command-Line Containing Unicode Right-to-Left Override (U+202E)
Pivot detection · T1036.002 · 2 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.