Windows curl.exe Downloads from File-Sharing Domains with Suspicious Output Extensions

Alerts on curl.exe downloading files over HTTP from file-sharing/content hosting domains, based on process command-line and executable context.

FreeReviewedSigma · High · v2
Product
windows
Category
process_creation
Author
Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2023-05-05
Updated
2026-07-31

What it detects

This rule identifies Windows process executions of curl.exe where the command line references common file-sharing or paste/download hosting domains and includes HTTP usage. It further filters for curl output or remote-name flags and targets downloaded content types by matching command-line arguments that end with executable, script, DLL, and related extensions. This behavior matters because attackers often use curl to retrieve and stage payloads from public hosting services, and the rule relies on Windows process creation telemetry including the image name and full command line.

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.