Skip to content

[New Rule] Unusual Commandshell Parent Process #201

@Samirbous

Description

@Samirbous

Description

Identifies a suspicious parent child process relationship with cmd.exe descending from unusual process. This may indicate an interactive shell activity from within an injected or hollowed process. Below an example where a cmd is spawned from default Google service:

image.

Required Info

  • Eventing Sources:
  • Target Operating Systems:
  • Platforms
  • Target ECS Version: x.x.x
  • New fields required in ECS for this?
  • Related issues or PRs

Optional Info

  • References:

Example Data

Metadata

Metadata

Assignees

Labels

Type

No type
No fields configured for issues without a type.

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions