Windows Process Creation: Recon Data Export via Command Prompt Redirection

Alerts when recon-related Windows utilities are launched with command-line output redirected to temp locations.

FreeReviewedSigma · Medium · v1
Product
windows
Category
process_creation
Author
frack113 (SigmaHQ), DRL 1.1
Published
2021-07-30
Updated
2026-07-30

ATT&CK techniques

Collection
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule flags Windows process creation where the spawned executable matches common data-recon utilities (tree.com, WMIC.exe, doskey.exe, sc.exe) and the parent command line includes output redirection to %TEMP% or %TMP%. Attackers often export or stage collected information for later use, and leveraging command-line redirection helps conceal where output is written and facilitates automated collection. Telemetry relies on process creation events including the image path, original filename, and the parent command line contents.

Related detections7 linkedT1119 — drag to rearrange
Suspicious LameHug Staging Directory and Info File Creation on Windows
Suspicious Recursive Credential and Wallet Search Written to Temp Inventory File
Malicious Shai-Hulud Data Exfiltration Script Execution via Process Creation
Linux File Events: Malicious GitHub Workflow File Creation (shai-hulud-workflow*.yml/yaml)
Windows PowerShell Recon via Export-Oriented Commands in Script Block Logging
PowerShell Script Block Collection of Documents via Recursive Get-ChildItem
Windows Process Creation: Automated Document and Directory Discovery via dir and findstr
Windows Process Creation: Recon Data Export via Command Prompt Redirection
Pivot detection · T1119 · 7 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.