Windows Process Creation: Cobalt Strike command strings entered in cmd.exe

Flags cmd.exe executions whose command lines include known Cobalt Strike command terms.

FreeUnreviewedSigmahighv1
title: "Windows Process Creation: Cobalt Strike command strings entered in cmd.exe"
id: ecab74d6-a567-426b-91fb-4ff6a1f5203f
related:
  - id: 4f154fb6-27d1-4813-a759-78b93e0b9c48
    type: similar
  - id: 647c7b9e-d784-4fda-b9a0-45c565a7b729
    type: derived
status: test
description: This rule identifies Windows processes where cmd.exe is launched with command lines containing common Cobalt Strike command strings. Accidental or otherwise, these artifacts are a strong indicator of operator use of offensive tooling and potential interactive abuse. The detection relies on process creation telemetry, specifically the Image ending in \cmd.exe and matching command-line substrings such as psinject, spawnas, getsystem, and execute-assembly.
references:
  - https://hstechdocs.helpsystems.com/manuals/cobaltstrike/current/userguide/content/cobalt-4-5-user-guide.pdf
  - https://thedfirreport.com/2021/10/04/bazarloader-and-the-conti-leaks/
  - https://thedfirreport.com/2022/06/16/sans-ransomware-summit-2022-can-you-detect-this/
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_hktl_cobaltstrike_bloopers_cmd.yml
author: _pete_0, TheDFIRReport, Huntrule Team
date: 2022-05-06
modified: 2023-01-30
tags:
  - attack.execution
  - attack.t1059.003
  - stp.1u
logsource:
  category: process_creation
  product: windows
detection:
  selection_img:
    - OriginalFileName: Cmd.Exe
    - Image|endswith: \cmd.exe
  selection_cli:
    CommandLine|startswith:
      - "cmd "
      - cmd.exe
      - c:\windows\system32\cmd.exe
    CommandLine|contains:
      - psinject
      - spawnas
      - make_token
      - remote-exec
      - rev2self
      - dcsync
      - logonpasswords
      - execute-assembly
      - getsystem
  condition: all of selection_*
falsepositives:
  - Unknown
level: high
license: DRL-1.1

What it detects

This rule identifies Windows processes where cmd.exe is launched with command lines containing common Cobalt Strike command strings. Accidental or otherwise, these artifacts are a strong indicator of operator use of offensive tooling and potential interactive abuse. The detection relies on process creation telemetry, specifically the Image ending in \cmd.exe and matching command-line substrings such as psinject, spawnas, getsystem, and execute-assembly.

Known false positives

  • Unknown

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.