LOLBAS With Network Traffic: networkEndpoint2026-04-15version:17
The following analytic identifies the use of Living Off the Land Binaries and Scripts (LOLBAS) with network traffic. It leverages data from the Network Traffic data model to detect when native Windows binaries, often abused by adversaries, initiate network connections. This activity is significant as LOLBAS are frequently used to download malicious payloads, enabling lateral movement, command-and-control, or data exfiltration. If confirmed malicious, this behavior could allow attackers to execute arbitrary code, escalate privileges, or maintain persistence within the environment, posing a severe threat to organizational security.
Windows Content Copied from Browser was Executed: endpointEndpointNoneversion:1
The following analytic correlates modifications to the Windows RunMRU registry key with clipboard content
changes initiated by browsers. It aims to detect ClickFix scenarios in which commands copied
from a browser are subsequently executed on the Windows system through the Run dialog box.
Windows Finger.exe Connecting to a Remote Host: endpointEndpointNoneversion:1
The following analytic identifies the `finger.exe` utility being spawned with a command line containing an `@` character, indicating a remote host/server was specified.
The Finger protocol utility is largely obsolete in modern environments and has been abused by adversaries as a living-off-the-land binary (LOLBIN) to retrieve encoded payloads or establish covert command-and-control communication with an attacker-controlled finger server.
This behavior is uncommon in legitimate enterprise usage and warrants investigation.
Windows RunMRU Command Execution: endpointEndpointNoneversion:11
The following analytic detects modifications to the Windows RunMRU registry key, which stores a history of commands executed through the Run dialog box (Windows+R). It leverages Endpoint Detection and Response (EDR) telemetry to monitor registry events targeting this key. This activity is significant as malware often uses the Run dialog to execute malicious commands while attempting to appear legitimate. If confirmed malicious, this could indicate an attacker using indirect command execution techniques for defense evasion or persistence. The detection excludes MRUList value changes to focus on actual command entries.
Windows For Loop Usage Within Cmd.exe To Execute Commands: endpointEndpointNoneversion:1
The following analytic identifies the use of a `for /f` loop with the `delims=` option within `cmd.exe`, a technique commonly used to parse and extract data from the output of other commands.
Adversaries and malicious scripts leverage this pattern to programmatically process command output for discovery, data extraction, or execution purposes while evading simpler detection logic.
LOLBAS Network Connection On Uncommon Port: networkEndpointNoneversion:1
The following analytic identifies Living Off the Land Binaries and Scripts (LOLBAS) that can legitimately initiate public network connections but are communicating over uncommon destination ports.
It leverages the Network Traffic data model and applies per-binary common-port exclusions to reduce false positives while preserving suspicious non-standard communication.
This behavior may indicate payload download, command-and-control, proxy execution, or attempts to blend malicious traffic into trusted Windows binaries.
Join this detection with the Process Execution events to provide context and avoid false positives.
Windows Node.exe Executing JS Script In Immediate Folder: endpointEndpointNoneversion:1
The following analytic identifies `node.exe` directly executing a single `.js` script located in the same directory it was launched from, where that directory is an unusual location such as a user profile, PerfLogs, ProgramData, or Temp folder.
Legitimate Node.js application, module, and package manager directories are excluded.
This pattern is commonly associated with malware loaders and second-stage payloads that leverage the Node.js runtime to execute JavaScript outside of a typical development or application context.
Windows Process Accessing IronLanguages Repository On GitHub: endpointEndpointNoneversion:1
The following analytic identifies a process command line referencing the IronLanguages GitHub repository, which hosts .NET implementation of popular scripting engines.
Adversaries have downloaded these .NET implementations to avoid getting detected by security controls while executing their payloads.
This activity is uncommon in typical enterprise environments outside of software development contexts.
LOLBAS Rare Network Connection: networkEndpointNoneversion:1
The following analytic identifies public network connections initiated by Living Off the Land Binaries and Scripts (LOLBAS) that rarely require direct outbound network access.
It leverages the Network Traffic data model and focuses on native Windows binaries where any public destination should be investigated and explicitly approved.
This activity may indicate proxy execution, process injection, payload download, command-and-control, or other abuse of trusted binaries to evade security controls.
Keep in mind that some of these binaries, such as Netsh.exe, Gpscript.exe, Wmic.exe, etc., will occasionally communicate with public network resources to perform their intended function.
Exclude said processes from the detection if they are too noisy for your environment.
Join this detection with the Process Execution events to provide context and avoid false positives.
Windows PowerShell FakeCAPTCHA Clipboard Execution: endpointEndpointNoneversion:9
This detection identifies potential FakeCAPTCHA/ClickFix clipboard hijacking campaigns by looking for PowerShell execution with hidden window parameters and distinctive strings related to fake CAPTCHA verification. These campaigns use social engineering to trick users into pasting malicious PowerShell commands from their clipboard, typically delivering information stealers or remote access trojans.