Windows Process Creation: Automated Document and Directory Discovery via dir and findstr

Flags Windows commands combining recursive dir listing, FINDSTR usage, and document-type targeting in one execution.

FreeReviewedSigma · Medium · v1
Product
windows
Category
process_creation
Author
frack113 (SigmaHQ), DRL 1.1
Published
2021-07-28
Updated
2026-07-30

ATT&CK techniques

Cred Access → Collection
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Discovery

  9. Lateral Movement

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule identifies Windows process creation events where the command line targets common document file types (.doc/.docx/.xls/.xlsx/.ppt/.pptx/.rtf/.pdf/.txt) and includes recursive, bare directory listing parameters. It also flags commands running FINDSTR.EXE with specific switches used to enumerate or extract matching strings from files. This matters because these scripted collection behaviors help attackers rapidly identify and harvest internal content without interactive user activity, relying on Windows process creation telemetry and command-line contents.

Related detections9 linkedT1552.001 — drag to rearrange
Suspicious Recursive Credential and Wallet Search Written to Temp Inventory File
Linux File Events: Malicious GitHub Workflow File Creation (shai-hulud-workflow*.yml/yaml)
Suspicious DNS Exfiltration to azurestaticprovider Backdoor Domain
Suspicious Azure Key Vault Access Policy Modification
Suspicious UAT-10608 Hidden Credential Harvesting Script Execution via nohup
Suspicious Access to Cloud and Database Credential Files via Process
Suspicious Credential Exfiltration to webhook.site (via dns_query)
Suspicious LameHug Staging Directory and Info File Creation on Windows
Suspicious Shai-Hulud Worm Stager Execution from Temp (via process_creation)
Windows Process Creation: Automated Document and Directory Discovery via dir and findstr
Pivot detection · T1552.001 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.