Windows Process Creation: Hydra Password Bruteforce Command-Line Parameters

Alerts when Windows process command lines include Hydra -u/-p parameters with USER/PASS placeholders.

FreeReviewedSigma · High · v2
Product
windows
Category
process_creation
Author
Vasiliy Burov (SigmaHQ), DRL 1.1
Published
2020-10-05
Updated
2026-07-31

ATT&CK techniques

Cred Access
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule flags Windows process executions whose command line includes Hydra-style password guessing parameters. Attackers rely on tools like Hydra to automate credential brute forcing by supplying target usernames and passwords via command-line options. The detection depends on process creation telemetry and string matching within the spawned process CommandLine fields for the expected option patterns and caret-wrapped placeholders.

Related detections9 linkedT1110 — drag to rearrange
Malicious SQL Server - Brutforce Enumeration with Non Existing Users - Login (via application)
Malicious Brutforce Enumeration with Non Existing Users - Login (via security)
Malicious Brutforce Enumeration on Windows OpenSSH Server with Non Existing User (via security)
Malicious Brutforce on Windows OpenSSH Server with Valid Users (via security)
Malicious RDP Discovery Performed on Multiple Hosts (via rdp)
Suspicious Bruteforce via Password Reset (via security)
Possible SonicWall Credential Testing via userLogin Endpoint
Malicious Brutforce Enumeration with Unexisting Users - Kerberos (via security)
Suspicious JumpCloud Password Brute Force Followed by Success
Windows Process Creation: Hydra Password Bruteforce Command-Line Parameters
Pivot detection · T1110 · 9 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.