Windows Process Execution of JavaScript via Node.exe
Alerts when node.exe starts a process with a .js argument on Windows, which may indicate suspicious script execution.
FreeUnreviewedSigmalowv1
windows-process-execution-of-javascript-via-node-exe-ba3874b9
title: Windows Process Execution of JavaScript via Node.exe
id: e0ca41c4-85ea-4d14-8f7e-b770e2cbd76e
status: experimental
description: This rule flags Windows process executions where a node.exe binary associated with Node.js is launched with a command line containing a .js argument. Running JavaScript from Node.js is common in development, but it can also be used to execute attacker-supplied scripts disguised as legitimate activity. The detection relies on process creation telemetry, including the process image filename and command-line content. It may produce false positives in environments where Node.js script execution is expected.
references:
- https://www.microsoft.com/en-us/security/blog/2025/04/15/threat-actors-misuse-node-js-to-deliver-malware-and-other-malicious-payloads/
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_security_susp_node_js_execution.yml
author: Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule Team
date: 2025-04-21
tags:
- attack.execution
- attack.t1059.007
logsource:
category: process_creation
product: windows
detection:
selection_img:
- Image|endswith: \node.exe
- OriginalFileName: node.exe
- Product: Node.js
selection_cmd:
CommandLine|contains: .js
condition: all of selection_*
falsepositives:
- Legitimate use of node.exe to execute JavaScript or JSC files on your environment
level: low
license: DRL-1.1
related:
- id: ba3874b9-0fae-465f-836c-eb5d071a1789
type: derived
What it detects
This rule flags Windows process executions where a node.exe binary associated with Node.js is launched with a command line containing a .js argument. Running JavaScript from Node.js is common in development, but it can also be used to execute attacker-supplied scripts disguised as legitimate activity. The detection relies on process creation telemetry, including the process image filename and command-line content. It may produce false positives in environments where Node.js script execution is expected.
Known false positives
- Legitimate use of node.exe to execute JavaScript or JSC files on your environment
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.