Windows process command lines matching May 2020 Turla ComRAT command patterns

Triggers on Windows command lines matching a set of Turla-related indicators documented by ESET (May 2020).

FreeReviewedSigma · Critical · v5
Product
windows
Category
process_creation
Author
Florian Roth (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2020-05-26
Updated
2026-07-31

ATT&CK techniques

Execution → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Cred Access

  5. Discovery

  6. Lateral Movement

  7. Collection

  8. C2

  9. Exfiltration

  10. Impact

What it detects

This rule identifies Windows process creations where the command line matches specific Turla group ComRAT-related command patterns described in the referenced ESET report. Attackers may use these command invocations to execute follow-on actions, including execution and persistence techniques. It relies on process creation telemetry with command-line data and matches either exact substrings or a defined regular expression pattern in the CommandLine field.

Related detections9 linkedT1059.001 — drag to rearrange
Windows Security: checkadmin.exe TargetUserName starting with Administr (Event ID 4799)
Suspicious PowerShell Invoke-Expression with Replace Obfuscation
Malicious Emmenhtal JavaScript Loader Spawning Encoded PowerShell
Suspicious Python Interpreter Launching Encoded PowerShell via subprocess
Suspicious PS1Bot PowerShell Payload Written to ProgramData (via file_event)
Suspicious Scheduled Task Running PowerShell Every Minute (via process_creation)
Malicious Non-Interactive Encoded PowerShell Stager (via process_creation)
Suspicious Hidden PowerShell Executing Substring of Dropped File
PowerShell Encoded or Download-Cradle Command Line (via process_creation)
Windows process command lines matching May 2020 Turla ComRAT command patterns
Pivot detection · T1059.001 · 9 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.