Windows: Suspicious Qemu execution with low-memory and network-tunneling flags
Alerts on Windows Qemu command lines using low -m values plus -netdev/connect= and -nographic.
- Product
- windows
- Category
- process_creation
- Author
- Muhammad Faisal (@faisalusuf), Hunter Juhan (@threatHNTR) (SigmaHQ), DRL 1.1
- Published
- 2024-06-03
- Updated
- 2026-07-30
ATT&CK techniques
C2Recon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
Exfiltration
Impact
What it detects
This rule flags Qemu process creation on Windows when the command line includes low-memory VM settings and key network-related options such as -netdev with connect= and nographic. These parameters can indicate attempts to use Qemu for non-interactive operation and network access, which is commonly associated with attacker-controlled tunneling or proxy behavior. It relies on Windows process creation telemetry, matching specific substrings within the process command line.
Reporting behind it
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: "Windows: Suspicious Qemu execution with low-memory and network-tunneling flags"
id: 58d89fe2-6ad3-4859-976a-5b80e9f7a8aa
status: test
description: This rule flags Qemu process creation on Windows when the command line includes low-memory VM settings and key network-related options such as -netdev with connect= and nographic. These parameters can indicate attempts to use Qemu for non-interactive operation and network access, which is commonly associated with attacker-controlled tunneling or proxy behavior. It relies on Windows process creation telemetry, matching specific substrings within the process command line.
references:
- https://securelist.com/network-tunneling-with-qemu/111803/
- https://www.qemu.org/docs/master/system/invocation.html#hxtool-5
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_qemu_suspicious_execution.yml
author: Muhammad Faisal (@faisalusuf), Hunter Juhan (@threatHNTR), Huntrule Team
date: 2024-06-03
tags:
- attack.command-and-control
- attack.t1090
- attack.t1572
logsource:
category: process_creation
product: windows
detection:
selection:
CommandLine|contains:
- -m 1M
- -m 2M
- -m 3M
CommandLine|contains|all:
- restrict=off
- "-netdev "
- connect=
- -nographic
filter_main_normal_usecase:
CommandLine|contains:
- " -cdrom "
- " type=virt "
- " -blockdev "
condition: selection and not 1 of filter_main_*
falsepositives:
- Unknown
level: medium
license: DRL-1.1
related:
- id: 5fc297ae-25b6-488a-8f25-cc12ac29b744
type: derived