Windows SFTP.exe Indirect Command Execution via ProxyCommand
Flags SFTP.exe executions that include ProxyCommand=, indicating potential indirect command execution.
- Product
- windows
- Category
- process_creation
- Author
- Swachchhanda Shrawan Poudel (Nextron Systems) (SigmaHQ), DRL 1.1
- Published
- 2026-04-27
- Updated
- 2026-07-30
ATT&CK techniques
Defense EvasionRecon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule identifies process creation events where SFTP.exe is invoked with the ProxyCommand= parameter, indicating indirect command execution behavior. Attackers may use this legitimate Windows utility to launch commands in a way that can help evade simpler controls and confuse command auditing. The detection relies on Windows process creation telemetry, matching the executable path ending in sftp.exe and a CommandLine containing ProxyCommand=.
Reporting behind it
- lolbas-project.github.iohttps://lolbas-project.github.io/lolbas/Binaries/Sftp/
- news.sophos.comhttps://news.sophos.com/en-us/2025/05/09/lumma-stealer-coming-and-going/
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_sftp_proxy_command_execution.yml
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: Windows SFTP.exe Indirect Command Execution via ProxyCommand
id: 50fac045-96f7-4695-854f-2bb4bc61a745
status: experimental
description: This rule identifies process creation events where SFTP.exe is invoked with the ProxyCommand= parameter, indicating indirect command execution behavior. Attackers may use this legitimate Windows utility to launch commands in a way that can help evade simpler controls and confuse command auditing. The detection relies on Windows process creation telemetry, matching the executable path ending in sftp.exe and a CommandLine containing ProxyCommand=.
references:
- https://lolbas-project.github.io/lolbas/Binaries/Sftp/
- https://news.sophos.com/en-us/2025/05/09/lumma-stealer-coming-and-going/
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_sftp_proxy_command_execution.yml
author: Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule Team
date: 2026-04-27
tags:
- attack.stealth
- attack.t1202
logsource:
category: process_creation
product: windows
detection:
selection:
Image|endswith: \sftp.exe
CommandLine|contains: ProxyCommand=
condition: selection
falsepositives:
- Legitimate use of SFTP with proxy commands for administration or networking tasks
level: medium
regression_tests_path: regression_data/rules/windows/process_creation/proc_creation_win_lolbin_sftp_indirect_cmd_execution/info.yml
license: DRL-1.1
related:
- id: 762bb580-79b4-40f4-8b9e-9349ce1710f4
type: derived