Windows Process Creation: Grixba Reconnaissance Tool Command-Line Parameter Combination

Alerts on Windows command lines containing Grixba-like mode/input/scan parameter combinations during reconnaissance.

FreeReviewedSigma · High · v5
Product
windows
Category
process_creation
Author
yxinmiracle, Swachchhanda Shrawan Poudel (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2025-11-26
Updated
2026-07-31

ATT&CK techniques

Recon → Discovery
  1. Resource Dev

  2. Initial Access

  3. Execution

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule flags Windows process creation events where the command line includes specific flag patterns for mode (-m/-mode) and input (-i/-input), along with scan indicators and associated input options. Such structured command-line usage can indicate automated reconnaissance or data collection staging by malware. It relies on process_creation telemetry with full command-line arguments to match the defined parameter combinations.

Related detections9 linkedT1046 — drag to rearrange
Possible Host Port Scan from Single Source Address (via network_connection)
Suspicious Fscan Internal Network Scanner Execution (via process_creation)
Possible Network Service Scanning via Nmap or Masscan (via process_creation)
Malicious Anonymous Login - Domain Specified (via security)
Suspicious Network Scanning Tool Execution
Malicious RDP Discovery Performed on Multiple Hosts (via rdp)
Malicious Anonymous Access Performed to Multiple Targets (via security)
Malicious Network Login Performed to Multiple Targets (via security)
Suspicious SoftPerfect Network Scanner Execution for Discovery
Windows Process Creation: Grixba Reconnaissance Tool Command-Line Parameter Combination
Pivot detection · T1046 · 9 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.