Windows: Process executions matching Greenbug espionage tool indicators
Alerts on Windows process creation with command-line patterns matching PowerShell execution-policy bypass and reverse-shell related tooling.
- Product
- windows
- Category
- process_creation
- Author
- Florian Roth (Nextron Systems) (SigmaHQ), DRL 1.1
- Published
- 2020-05-20
- Updated
- 2026-07-31
ATT&CK techniques
Execution → C2Recon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
Exfiltration
Impact
What it detects
This rule flags Windows process creations where the executable path and command-line arguments match indicators associated with the Greenbug espionage campaign reported by Symantec. The behavior matters because it can reveal attacker tooling used for execution, payload staging, and command-and-control activity. Telemetry relies on Windows process creation events with Image paths and CommandLine content.
Reporting behind it
Changelog
v5- v5Candidate ingested via manual entry.2026-07-31
- v3Candidate ingested via manual entry.2026-07-31
- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: "Windows: Process executions matching Greenbug espionage tool indicators"
id: c9f339ee-c4b0-4191-a9a6-42d8e46ee07d
status: test
description: This rule flags Windows process creations where the executable path and command-line arguments match indicators associated with the Greenbug espionage campaign reported by Symantec. The behavior matters because it can reveal attacker tooling used for execution, payload staging, and command-and-control activity. Telemetry relies on Windows process creation events with Image paths and CommandLine content.
references:
- https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/greenbug-espionage-telco-south-asia
- https://github.com/SigmaHQ/sigma/blob/master/rules-emerging-threats/2020/TA/Greenbug/proc_creation_win_apt_greenbug_may20.yml
author: Florian Roth (Nextron Systems), Huntrule Team
date: 2020-05-20
modified: 2023-03-09
tags:
- attack.stealth
- attack.g0049
- attack.execution
- attack.t1059.001
- attack.command-and-control
- attack.t1105
- attack.t1036.005
- detection.emerging-threats
logsource:
category: process_creation
product: windows
detection:
selection_img:
Image|endswith:
- :\ProgramData\adobe\Adobe.exe
- :\ProgramData\oracle\local.exe
- \revshell.exe
- \infopagesbackup\ncat.exe
- :\ProgramData\comms\comms.exe
selection_msf:
CommandLine|contains|all:
- -ExecutionPolicy Bypass -File
- \msf.ps1
selection_ncat:
CommandLine|contains|all:
- infopagesbackup
- \ncat
- -e cmd.exe
selection_powershell:
CommandLine|contains:
- system.Data.SqlClient.SqlDataAdapter($cmd); [void]$da.fill
- -nop -w hidden -c $k=new-object
- "[Net.CredentialCache]::DefaultCredentials;IEX "
- " -nop -w hidden -c $m=new-object net.webclient;$m"
- -noninteractive -executionpolicy bypass whoami
- -noninteractive -executionpolicy bypass netstat -a
selection_other:
CommandLine|contains: L3NlcnZlcj1
condition: 1 of selection_*
falsepositives:
- Unlikely
level: critical
license: DRL-1.1
related:
- id: 3711eee4-a808-4849-8a14-faf733da3612
type: derived