Windows Network Sniffing Tool Executed: endpointEndpointNoneversion:1
The following analytic detects the execution of common network sniffing tools on Windows systems, including Wireshark, WinPcap, tcpdump, and similar utilities.
This activity is significant because attackers use packet capture tools to intercept and analyze network traffic, enabling credential theft, sensitive data harvesting, and reconnaissance of internal network communications.
While these tools have legitimate administrative uses, their presence in unexpected environments may indicate an adversary conducting man-in-the-middle attacks or exfiltrating sensitive information traversing the network.
If confirmed malicious, this could lead to the exposure of credentials, session tokens, and confidential data, facilitating lateral movement and further compromise of the environment.
Windows Dir Piped to Findstr Activity: endpointEndpointNoneversion:1
The following analytic detects the execution of the `dir` command piped to `findstr` on Windows systems.
This technique is commonly used by attackers during the reconnaissance phase to enumerate files, directories, or sensitive data by filtering directory listings for specific strings or patterns.
While this command combination can have legitimate administrative uses, adversaries frequently leverage it to locate credentials, configuration files, or other high-value targets on a compromised system.
If confirmed malicious, this activity could indicate an attacker is actively mapping the file system in preparation for data exfiltration, lateral movement, or further exploitation.
Unusually Long Command Line - MLTK: endpointEndpoint2026-03-10version:9
The following analytic identifies unusually long command lines executed on hosts, which may indicate malicious activity. It leverages the Machine Learning Toolkit (MLTK) to detect command lines with lengths that deviate from the norm for a given user. This is significant for a SOC as unusually long command lines can be a sign of obfuscation or complex malicious scripts. If confirmed malicious, this activity could allow attackers to execute sophisticated commands, potentially leading to unauthorized access, data exfiltration, or further compromise of the system.
Linux Ghostscript Exploitation: endpointEndpointNoneversion:2
The following analytic detects exploitation of Ghostscript causing command execution.
This can be used by attackers to abuse file conversion services or embedded LibreOffice documents.
Potentially malicious code on commandline: endpointEndpoint2026-03-10version:7
The following analytic detects potentially malicious command lines using a pretrained machine learning text classifier. It identifies unusual keyword combinations in command lines, such as "streamreader," "webclient," "mutex," "function," and "computehash," which are often associated with adversarial PowerShell code execution for C2 communication. This detection leverages data from Endpoint Detection and Response (EDR) agents, focusing on command lines longer than 200 characters. This activity is significant as it can indicate an attempt to execute malicious scripts, potentially leading to unauthorized code execution, data exfiltration, or further system compromise.
Detect suspicious processnames using pretrained model in DSDL: endpointEndpoint2026-03-10version:9
The following analytic identifies suspicious process names using a pre-trained Deep Learning model. It leverages Endpoint Detection and Response (EDR) telemetry to analyze process names and predict their likelihood of being malicious. The model, a character-level Recurrent Neural Network (RNN), classifies process names as benign or suspicious based on a threshold score of 0.5. This detection is significant as it helps identify malware, such as TrickBot, which often uses randomly generated filenames to evade detection. If confirmed malicious, this activity could indicate the presence of malware capable of propagating across the network and executing harmful actions.
First time seen command line argument: endpointEndpoint2024-11-14version:8
This search looks for command-line arguments that use a `/c` parameter to execute a command that has not previously been seen.
System Processes Run From Unexpected Locations: endpointEndpointNoneversion:17
The following analytic identifies system processes running from unexpected locations outside of paths such as `C:\Windows\System32\` or `C:\Windows\SysWOW64`. It leverages data from Endpoint Detection and Response (EDR) agents, focusing on process paths, names, and hashes. This activity is significant as it may indicate a malicious process attempting to masquerade as a legitimate system process. If confirmed malicious, this behavior could allow an attacker to execute code, escalate privileges, or maintain persistence within the environment, posing a significant security risk.
Windows For Loop Usage Within Cmd.exe To Execute Commands: endpointEndpointNoneversion:1
The following analytic identifies the use of a `for /f` loop with the `delims=` option within `cmd.exe`, a technique commonly used to parse and extract data from the output of other commands.
Adversaries and malicious scripts leverage this pattern to programmatically process command output for discovery, data extraction, or execution purposes while evading simpler detection logic.
Detect Use of cmd exe to Launch Script Interpreters: endpointEndpointNoneversion:16
The following detects the execution of cscript.exe or wscript.exe processes spawned by cmd.exe, leveraging Endpoint Detection and Response (EDR) telemetry mapped to the Endpoint data model, with additional contextual filtering to improve fidelity and reduce false positives.
It focuses on executions originating from user-writable directories such as Users, AppData, Temp, and Downloads, which are commonly abused by attackers to stage and execute malicious scripts, while excluding trusted system paths like C:\Windows\System32\ and C:\Program Files\ that are typically associated with legitimate activity.
The detection also filters out service accounts (e.g., accounts ending with $ or known naming conventions) to minimize noise from automated processes and incorporates command-line context to better assess script execution patterns and identify potentially suspicious behavior.
Unusually Long Command Line: endpointEndpointNoneversion:14
The following analytic detects unusually long command lines, which may indicate malicious activity. It leverages data from Endpoint Detection and Response (EDR) agents, focusing on the length of command lines executed on hosts. This behavior is significant because attackers often use obfuscated or complex command lines to evade detection and execute malicious payloads. If confirmed malicious, this activity could lead to data theft, ransomware deployment, or further system compromise. Analysts should investigate the source and content of the command line, inspect relevant artifacts, and review concurrent processes to identify potential threats.
Detect Prohibited Applications Spawning cmd exe: endpointEndpointNoneversion:16
The following analytic detects executions of cmd.exe spawned by processes that are commonly abused by attackers and do not typically launch cmd.exe. It leverages data from Endpoint Detection and Response (EDR) agents, focusing on process GUID, process name, parent process, and command-line executions. This activity is significant because it may indicate an attempt to execute unauthorized commands or scripts, often a precursor to further malicious actions. If confirmed malicious, this behavior could lead to unauthorized code execution, privilege escalation, or persistence within the environment.