kevmap

Techniques › T1202

T1202 Indirect Command Execution

stealth — Windows · attack.mitre.org · JSON

1
MITRE detection strategy
1
analytics
40
Sigma rules tagged attack.t1202
9
KEV CVEs mapped here
<p>Adversaries may abuse utilities that allow for command execution to bypass security restrictions that limit the use of command-line interpreters. Various Windows utilities may be used to execute commands, possibly without invoking cmd. For example, Forfiles, the Program Compatibility Assistant (pcalua.exe), components of the Windows Subsystem for Linux (WSL), Scriptrunner.exe, as well as other utilities may invoke the execution of programs and commands from a Command and Scripting Interpreter, Run window, or via scripts. Adversaries may also abuse the ssh.exe binary to execute malicious commands via the ProxyCommand and LocalCommand options, which can be invoked via the -o flag or by modifying the SSH config file.</p><p>Adversaries may abuse these features for Stealth, specifically to perform arbitrary execution while subverting detections and/or mitigation controls (such as Group Policy) that limit/prevent the usage of cmd or file extensions more commonly associated with malicious payloads.</p>

KEV CVEs mapped to this technique · CTID Mappings Explorer

CVEVendor / productMapping typeStateAdded
CVE-2024-24919Check Point Quantum Security Gateways exploitation technique Mapped2024-05-30
CVE-2023-40044Progress WS_FTP Server secondary impact Mapped2023-10-05
CVE-2023-32315Ignite Realtime Openfire exploitation technique Mapped2023-08-24
CVE-2022-29464WSO2 Multiple Products primary impact Mapped2022-04-25
CVE-2013-0629Adobe ColdFusion primary impact Mapped2022-03-07
CVE-2019-3398Atlassian Confluence Server and Data Center exploitation technique Mapped2021-11-03
CVE-2019-3396Atlassian Confluence Server and Data Server secondary impact Mapped2021-11-03
CVE-2020-3452Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) exploitation technique Mapped2021-11-03
CVE-2018-0296Cisco Adaptive Security Appliance (ASA) exploitation technique Mapped2021-11-03

Detection strategy · ATT&CK Enterprise v19.2

Sigma rules · SigmaHQ da9bb07d64, tag attack.t1202

Author: Nasreddine Bencherchali (Nextron Systems) · 2022-06-21 · logsource: product=windows category=ps_script · 03409c93-a7c7-49ba-9a4c-a00badf2a153
Detects execution of "TroubleshootingPack" cmdlets to leverage CVE-2022-30190 or action similar to "msdt" lolbin (as described in LOLBAS)
Techniques: T1202
Author: Victor Sergeev, oscd.community · 2020-10-09 (modified 2024-04-23) · logsource: product=windows category=process_creation · 06b401f4-107c-4ff9-947f-9ec1e7649f1e
Detects execution of "ftp.exe" script with the "-s" or "/s" flag and any child processes ran by "ftp.exe".
Techniques: T1059T1202
Author: Florian Roth (Nextron Systems) · 2021-05-27 (modified 2023-08-31) · logsource: product=windows category=process_creation · 1775e15e-b61b-4d14-a1a3-80981298085a
Detects suspicious start of rundll32.exe without any parameters as found in CobaltStrike beacon activity
Techniques: T1202
Author: Florian Roth (Nextron Systems) · 2021-08-23 (modified 2022-12-25) · logsource: product=windows category=process_creation · 1f1a8509-2cbb-44f5-8751-8e1571518ce2
Detects suspicious Splwow64.exe process without any command line parameters
Techniques: T1202
Author: Nasreddine Bencherchali (Nextron Systems) · 2023-01-23 (modified 2023-08-15) · logsource: product=windows category=process_creation · 2267fe65-0681-42ad-9a6d-46553d3f3480
Detects uncommon or suspicious child processes spawning from a WSL process. This could indicate an attempt to evade parent/child relationship detections or persistence attempts via cron using WSL
Techniques: T1218T1202
Author: Nasreddine Bencherchali (Nextron Systems), X__Junior (Nextron Systems) · 2024-01-11 · logsource: product=windows category=process_creation · 2433a154-bb3d-42e4-86c3-a26bdac91c45
Detects the execution of a renamed "PingCastle" binary based on the PE metadata fields.
Techniques: T1059T1202
Author: Nasreddine Bencherchali (Nextron Systems) · 2022-05-29 (modified 2024-03-13) · logsource: product=windows category=process_creation · 258fc8ce-8352-443a-9120-8a11e4857fa5
Detects processes leveraging the "ms-msdt" handler or the "msdt.exe" binary to execute arbitrary commands as seen in the follina (CVE-2022-30190) vulnerability
Techniques: T1202
Author: X__Junior (Nextron Systems) · 2024-03-11 · logsource: product=windows category=process_creation · 264982dc-dbad-4dce-b707-1e0d3e0f73d9
Detects the execution of a renamed "NirCmd.exe" binary based on the PE metadata fields.
Techniques: T1059T1202
Author: Victor Sergeev, oscd.community · 2020-10-09 (modified 2023-02-03) · logsource: product=windows category=process_creation · 277a4393-446c-449a-b0ed-7fdc7795244c
Detects the execution of a renamed "ftp.exe" binary based on the PE metadata fields
Techniques: T1059T1202
Author: Nasreddine Bencherchali (Nextron Systems) · 2023-08-15 · logsource: product=windows category=process_creation · 2d22a514-e024-4428-9dba-41505bd63a5b
Detects execution of Microsoft bash launcher without any flags to execute the content of a bash script directly. This can be used to potentially bypass defenses and execute Linux or Windows-based binaries directly via bash.
Techniques: T1202
Author: frack113 · 2022-12-09 (modified 2024-12-01) · logsource: product=windows category=process_creation · 3037d961-21e9-4732-b27a-637bcc7bf539
ForceV1 asks for information directly from the kernel space. Conhost connects to the console application. High IntegrityLevel means the process is running with elevated privileges, such as an Administrator context.
Techniques: T1202
Author: Trent Liffick · 2020-05-01 (modified 2024-01-15) · logsource: product=windows category=process_creation · 33339be3-148b-4e16-af56-ad16ec6c7e7b
Detects usage of findstr to identify and execute a lnk file as seen within the HHS redirect attack
Author: Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems) · 2020-01-28 (modified 2025-01-22) · logsource: product=windows category=process_creation · 340a090b-c4e9-412e-bb36-b4b16fe96f9b
Detects a renamed "dctask64.exe" execution, a signed binary by ZOHO Corporation part of ManageEngine Endpoint Central. This binary can be abused for DLL injection, arbitrary command and process execution.
Author: Nasreddine Bencherchali (Nextron Systems), Beyu Denis, oscd.community · 2022-05-17 (modified 2023-06-22) · logsource: product=windows category=process_creation · 4ae3e30b-b03f-43aa-87e3-b622f4048eed
Detects potential arbitrary file download using a Microsoft Office application
Techniques: T1202
Author: Markus Neis, Nasreddine Bencherchali (Nextron Systems) · 2018-12-27 (modified 2023-02-09) · logsource: product=windows category=process_creation · 55f0a3a1-846e-40eb-8273-677371b8d912
Detects an attacker trying to enable the outlook security setting "EnableUnsafeClientMailRules" which allows outlook to run applications or execute macros
Techniques: T1059T1202
Author: Nasreddine Bencherchali (Nextron Systems) · 2023-01-26 (modified 2023-10-25) · logsource: product=windows category=process_creation · 5a3164f2-b373-4152-93cf-090b13c12d27
Detects uncommon or suspicious child processes spawning from a VsCode "code.exe" process. This could indicate an attempt of persistence via VsCode tasks or terminal profiles.
Techniques: T1218T1202
Author: frack113 · 2021-11-24 (modified 2023-08-15) · logsource: product=windows category=process_creation · 5edc2273-c26f-406c-83f3-f4d948e740dd
Detects execution of Microsoft bash launcher with the "-c" flag. This can be used to potentially bypass defenses and execute Linux or Windows-based binaries directly via bash.
Techniques: T1202
WSL Kali-Linux Usage highexperimental
Author: Swachchhanda Shrawan Poudel (Nextron Systems) · 2025-10-10 · logsource: product=windows category=process_creation · 6f1a11aa-4b8a-4b7f-9e13-4d3e4ff0e0d4
Detects the use of Kali Linux through Windows Subsystem for Linux
Techniques: T1202
Author: CD_R0M_ · 2022-06-11 (modified 2023-08-17) · logsource: product=windows category=registry_set · 7530b96f-ad8e-431d-a04d-ac85cc461fdc
Detects the abuse of custom file open handler, executing powershell
Techniques: T1202
Author: X__Junior (Nextron Systems) · 2023-09-11 (modified 2023-10-12) · logsource: product=windows category=process_creation · 7530cd3d-7671-43e3-b209-976966f6ea48
Detects the execution of a renamed "CURL.exe" binary based on the PE metadata fields
Techniques: T1059T1202
Author: Swachchhanda Shrawan Poudel (Nextron Systems) · 2026-04-27 · logsource: product=windows category=process_creation · 762bb580-79b4-40f4-8b9e-9349ce1710f4
Detects the use of SFTP.exe to execute commands indirectly via ProxyCommand parameter. Threat actors were seen leveraging this legitimate Windows binary to bypass security controls and execute arbitrary commands while evading detection.
Techniques: T1202
Author: frack113, Swachchhanda Shrawan Poudel (Nextron Systems) · 2021-12-20 (modified 2025-04-12) · logsource: product=windows category=process_creation · 7cce6fc8-a07f-4d84-a53e-96e1879843c9
Detects binaries that use the same name as legitimate sysinternals tools to evade detection. This rule looks for the execution of binaries that are named similarly to Sysinternals tools. Adversary may rename their malicious tools as legitimate Sysinternals tools to evade detection.
Author: omkar72 · 2020-10-25 (modified 2023-12-11) · logsource: product=windows category=process_creation · 7dc2dedd-7603-461a-bc13-15803d132355
Detects uncommon "conhost" child processes. This could be a sign of "conhost" usage as a LOLBIN or potential process injection activity.
Techniques: T1202
Author: Nasreddine Bencherchali (Nextron Systems) · 2023-08-16 · logsource: product=windows category=process_creation · 811f459f-9231-45d4-959a-0266c6311987
Detects suspicious child processes of "BgInfo.exe" which could be a sign of potential abuse of the binary to proxy execution via external VBScript
Author: @gott_cyber, Nasreddine Bencherchali (Nextron Systems) · 2022-12-11 (modified 2024-06-26) · logsource: product=windows category=process_creation · 835e75bf-4bfd-47a4-b8a6-b766cac8bcb7
Detects uncommon child process of Setres.EXE. Setres.EXE is a Windows server only process and tool that can be used to set the screen resolution. It can potentially be abused in order to launch any arbitrary file with a name containing the word "choice" from the current execution path.
Techniques: T1218T1202
Author: Florian Roth (Nextron Systems) · 2021-03-09 (modified 2022-10-09) · logsource: product=windows category=process_creation · 883faa95-175a-4e22-8181-e5761aeb373c
Detects a service binary running in a suspicious directory
Techniques: T1202
Author: frack113 · 2021-11-07 (modified 2022-12-25) · logsource: product=windows category=process_creation · 90dcf730-1b71-4ae7-9ffc-6fcf62bd0132
ZipExec is a Proof-of-Concept (POC) tool to wrap binary-based tools into a password-protected zip file.
Techniques: T1218T1202
Author: Nasreddine Bencherchali (Nextron Systems), Beyu Denis, oscd.community · 2019-10-26 (modified 2023-08-16) · logsource: product=windows category=process_creation · aaf46cdc-934e-4284-b329-34aa701e3771
Detects uncommon child processes of "BgInfo.exe" which could be a sign of potential abuse of the binary to proxy execution via external VBScript
Author: Florian Roth (Nextron Systems), Jason Lynch · 2021-05-22 (modified 2024-11-23) · logsource: product=windows category=process_creation · c4e49831-1496-40cf-8ce1-b53f942b02f9
Detects execution of renamed version of PAExec. Often used by attackers
Techniques: T1202
Proxy Execution via Vshadow mediumexperimental
Author: David Faiss · 2025-05-26 · logsource: product=windows category=process_creation · d7c75059-2901-4578-b209-8837fd31c6a8
Detects the invocation of vshadow.exe with the -exec parameter that executes a specified script or command after the shadow copies are created but before the VShadow tool exits. VShadow is a command-line tool that you can use to create and manage volume shadow copies. While legitimate backup or administrative scripts may use this flag, attackers can leverage this parameter to proxy the execution of malware.
Techniques: T1202
Author: Nasreddine Bencherchali (Nextron Systems), GossiTheDog, frack113 · 2022-06-21 (modified 2024-03-13) · logsource: product=windows category=process_creation · dc4576d4-7467-424f-9eee-fd2b02855fe0
Detects execution of msdt.exe using the "cab" flag which could indicates suspicious diagcab files with embedded answer files leveraging CVE-2022-30190
Techniques: T1202
Author: oscd.community, Zach Stanford @svch0st, Nasreddine Bencherchali (Nextron Systems) · 2020-10-05 (modified 2023-04-12) · logsource: product=windows category=process_creation · dec44ca7-61ad-493c-bfd7-8819c5faa09b
Detects potential abuse of Windows Subsystem for Linux (WSL) binary as a Living of the Land binary in order to execute arbitrary Linux or Windows commands.
Techniques: T1218T1202
Author: Swachchhanda Shrawan Poudel (Nextron Systems) · 2025-02-05 · logsource: product=windows category=process_creation · dfa03a09-8b92-4d83-8e74-f72839b1c407
Detects suspicious child processes related to Windows Shell utilities spawned by `conhost.exe`, which could indicate malicious activity using trusted system components.
Techniques: T1202T1218
Author: Markus Neis, Nasreddine Bencherchali (Nextron Systems) · 2018-12-27 (modified 2023-02-09) · logsource: product=windows category=process_creation · e212d415-0e93-435f-9e1a-f29005bb4723
Detects a suspicious child process spawning from Outlook where the image is located in a remote location (SMB/WebDav shares).
Techniques: T1059T1202
Author: Greg (rule) · 2022-06-17 (modified 2023-02-17) · logsource: product=windows category=image_load · ec8c4047-fad9-416a-8c81-0f479353d7f6
Detects both of CVE-2022-30190 (Follina) and DogWalk vulnerabilities exploiting msdt.exe binary to load the "sdiageng.dll" library
Techniques: T1202
CVE tags: CVE-2022-30190
Author: Victor Sergeev, oscd.community · 2020-10-09 (modified 2022-07-11) · logsource: product=windows category=process_creation · eca49c87-8a75-4f13-9c73-a5a29e845f03
Detects execution of powershell scripts via Runscripthelper.exe
Techniques: T1059T1202
Author: Nasreddine Bencherchali (Nextron Systems) · 2023-02-14 · logsource: product=windows category=process_creation · ed825c86-c009-4014-b413-b76003e33d35
Detects the execution of Windows binaries from within a WSL instance. This could be used to masquerade parent-child relationships
Techniques: T1202
Author: frack113 · 2021-11-03 (modified 2024-04-22) · logsource: product=windows category=process_creation · f37aba28-a9e6-4045-882c-d5004043b337
Detects execution of Cmdl32 with the "/vpn" and "/lan" flags. Attackers can abuse this utility in order to download arbitrary files via a configuration file. Inspect the location and the content of the file passed as an argument in order to determine if it is suspicious.
Techniques: T1218T1202
Author: Victor Sergeev, oscd.community · 2020-10-09 (modified 2023-03-29) · logsource: product=windows category=process_creation · f7375e28-5c14-432f-b8d1-1db26c832df3
Detects potential DLL sideloading using the Microsoft Office winword process via the '/l' flag.
Techniques: T1202
Author: Nasreddine Bencherchali (Nextron Systems) · 2023-06-21 (modified 2023-10-18) · logsource: product=windows category=process_creation · f99abdf0-6283-4e71-bd2b-b5c048a94743
Detects the execution of an Office application that points to a document that is located in a trusted location. Attackers often used this to avoid macro security and execute their malicious code.
Techniques: T1202