Recon Command Output Piped To Findstr.EXE

 Original Source: [Sigma source]
Title: Recon Command Output Piped To Findstr.EXE
Status: test
Description:Detects the execution of a potential recon command where the results are piped to "findstr". This is meant to trigger on inline calls of "cmd.exe" via the "/c" or "/k" for example. Attackers often time use this technique to extract specific information they require in their reconnaissance phase.
References:
  -https://github.com/redcanaryco/atomic-red-team/blob/02cb591f75064ffe1e0df9ac3ed5972a2e491c97/atomics/T1057/T1057.md#atomic-test-6---discover-specific-process---tasklist
  -https://www.hhs.gov/sites/default/files/manage-engine-vulnerability-sector-alert-tlpclear.pdf
  -https://www.trendmicro.com/en_us/research/22/d/spring4shell-exploited-to-deploy-cryptocurrency-miners.html
Author: Nasreddine Bencherchali (Nextron Systems), frack113
Date: 2023-07-06
modified:2025-10-08
Tags:
  • -'attack.discovery'
  • -'attack.t1057'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection:
    CommandLine|contains:
      -'ipconfig*|*find'
      -'net*|*find'
      -'netstat*|*find'
      -'ping*|*find'
      -'systeminfo*|*find'
      -'tasklist*|*find'
      -'whoami*|*find'

  filter_optional_xampp:
    CommandLine|contains|all:
      -'cmd.exe /c TASKLIST /V |'
      -'FIND /I'
      -'\xampp\'
      -'\catalina_start.bat'

  condition:selection and not 1 of filter_optional_*
Falsepositives:
  -Unknown
Level: medium