T1202 Indirect Command Execution — ATT&CK Technique
Adversaries may abuse utilities that allow for command execution to bypass security restrictions that limit the use of command-line interpreters. Various Windows utilities may be used to execute commands, possibly without invoking cmd. For example, Forfiles, the Program Compatibility Assistant (`pcalua.exe`), components of the Windows Subsystem for Linux (WSL), `Scriptrunner.exe`, as well as other utilities may invoke the execution of programs and commands from a Command and Scripting Interpreter, Run window, or via scripts. Adversaries may also abuse the `ssh.exe` binary to execute malicious commands via the `ProxyCommand` and `LocalCommand` options, which can be invoked via the `-o` flag or by modifying the SSH config file. Adversaries may abuse these features for Stealth, specifically to perform arbitrary execution while subverting detections and/or mitigation controls (such as Group Policy) that limit/prevent the usage of cmd or file extensions more commonly associated with malicious payloads.
Detection coverage (46)
- Arbitrary Command Execution Using WSL medium
- Diagnostic Library Sdiageng.DLL Loaded By Msdt.EXE high
- Troubleshooting Pack Cmdlet Execution medium
- Indirect Command Execution From Script File Via Bash.EXE medium
- Indirect Inline Command Execution Via Bash.EXE medium
- Uncommon Child Process Of BgInfo.EXE medium
- Suspicious Child Process Of BgInfo.EXE high
- Potentially Suspicious Child Processes Spawned by ConHost high
- Uncommon Child Process Of Conhost.EXE medium
- Potential Arbitrary File Download Via Cmdl32.EXE medium
- Suspicious High IntegrityLevel Conhost Legacy Option informational
- Findstr Launching .lnk File medium
- Potential Arbitrary Command Execution Via FTP.EXE medium
- Suspicious ZipExec Execution medium
- Renamed FTP.EXE Execution medium
- Suspicious Runscripthelper.exe medium
- Potential Arbitrary Command Execution Using Msdt.EXE high
- Suspicious Cabinet File Execution Via Msdt.EXE medium
- Potentially Suspicious Office Document Executed From Trusted Location high
- Potential Arbitrary DLL Load Using Winword medium
- Potential Arbitrary File Download Using Office Application high
- Suspicious Remote Child Process From Outlook high
- Outlook EnableUnsafeClientMailRules Setting Enabled high
- Renamed CURL.EXE Execution medium
- Renamed PAExec Execution high
- Renamed ZOHO Dctask64 Execution high
- Renamed PingCastle Binary Execution high
- Renamed NirCmd.EXE Execution high
- Suspicious Splwow64 Without Params high
- Rundll32 Execution Without CommandLine Parameters high
- Uncommon Child Process Of Setres.EXE high
- Indirect Command Execution via SFTP ProxyCommand medium
- Suspicious Service Binary Directory high
- Potential Binary Impersonating Sysinternals Tools medium
- Proxy Execution via Vshadow medium
- Potentially Suspicious Child Process Of VsCode medium
- WSL Kali-Linux Usage high
- Windows Binary Executed From WSL medium
- WSL Child Process Anomaly medium
- Custom File Open Handler Executes PowerShell high
- Microsoft Intune Device Health Scripts
- Microsoft Intune Mobile Apps
- Windows Indirect Command Execution Via forfiles
- Windows Indirect Command Execution Via Series Of Forfiles
- Windows Indirect Command Execution Via pcalua
- Windows RunMRU Command Execution