Windows Process Execution of Tor or Tor Browser (tor.exe / Firefox-based)

Flags Windows execution of tor.exe or Tor Browser’s bundled Firefox from the expected installation path.

FreeReviewedSigma · High · v2
Product
windows
Category
process_creation
Author
frack113 (SigmaHQ), DRL 1.1
Published
2022-02-20
Updated
2026-07-31

ATT&CK techniques

C2
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. Exfiltration

  13. Impact

What it detects

This rule matches Windows process creation events where the executable indicates Tor (tor.exe) or the Tor Browser (Tor Browser\Browser\firefox.exe). Attackers may use Tor to anonymize infrastructure and blend into normal network activity while communicating via onion routing. The detection relies on process creation telemetry, specifically the process image path/name fields and related metadata.

Related detections2 linkedT1090.003 — drag to rearrange
Windows DNS Client Query for .onion and Tor-related Domains
Windows Sysmon DNS Query to .onion or Tor Gateway Domains
Windows Process Execution of Tor or Tor Browser (tor.exe / Firefox-based)
Pivot detection · T1090.003 · 2 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.