Potential CommandLine Path Traversal Via Cmd.EXE

 Original Source: [Sigma source]
Title: Potential CommandLine Path Traversal Via Cmd.EXE
Status: test
Description:Detects potential path traversal attempt via cmd.exe. Could indicate possible command/argument confusion/hijacking
References:
  -https://hackingiscool.pl/cmdhijack-command-argument-confusion-with-path-traversal-in-cmd-exe/
  -https://twitter.com/Oddvarmoe/status/1270633613449723905
Author: xknow @xknow_infosec, Tim Shelton
Date: 2020-06-11
modified:2023-03-06
Tags:
  • -'attack.execution'
  • -'attack.t1059.003'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_img:
ParentImage|endswith:'\cmd.exe' Image|endswith:'\cmd.exe' OriginalFileName:'cmd.exe'   selection_flags:
    - ParentCommandLine|contains:
      - '/c'
      - '/k'
      - '/r'
    - CommandLine|contains:
      - '/c'
      - '/k'
      - '/r'
  selection_path_traversal:
ParentCommandLine:'/../../' CommandLine|contains:'/../../'   filter_java:
    CommandLine|contains: '\Tasktop\keycloak\bin\/../../jre\bin\java'
  condition:all of selection_* and not 1 of filter_*
Falsepositives:
  -Java tools are known to produce false-positive when loading libraries
Level: high