1200KM / detection
T1202 Indirect Command Execution — Detection Rules
Detection workspace for T1202 Indirect Command Execution: 39 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- Diagnostic Library Sdiageng.DLL Loaded By Msdt.EXE · test · high · {"category":"image_load","product":"windows"}
- Troubleshooting Pack Cmdlet Execution · test · medium · {"product":"windows","category":"ps_script","definition":"Requirements: Script Block Logging must be enabled"}
- Indirect Inline Command Execution Via Bash.EXE · test · medium · {"category":"process_creation","product":"windows"}
- Indirect Command Execution From Script File Via Bash.EXE · test · medium · {"category":"process_creation","product":"windows"}
- Suspicious Child Process Of BgInfo.EXE · test · high · {"category":"process_creation","product":"windows"}
- Uncommon Child Process Of BgInfo.EXE · test · medium · {"category":"process_creation","product":"windows"}
- Potential Arbitrary File Download Via Cmdl32.EXE · test · medium · {"category":"process_creation","product":"windows"}
- Suspicious High IntegrityLevel Conhost Legacy Option · test · informational · {"product":"windows","category":"process_creation"}
- Uncommon Child Process Of Conhost.EXE · test · medium · {"category":"process_creation","product":"windows"}
- Potentially Suspicious Child Processes Spawned by ConHost · experimental · high · {"category":"process_creation","product":"windows"}
- Findstr Launching .lnk File · test · medium · {"category":"process_creation","product":"windows"}
- Potential Arbitrary Command Execution Via FTP.EXE · test · medium · {"category":"process_creation","product":"windows"}
- Suspicious ZipExec Execution · test · medium · {"category":"process_creation","product":"windows"}
- Suspicious Runscripthelper.exe · test · medium · {"category":"process_creation","product":"windows"}
- Potential Arbitrary Command Execution Using Msdt.EXE · test · high · {"category":"process_creation","product":"windows"}
- Suspicious Cabinet File Execution Via Msdt.EXE · test · medium · {"category":"process_creation","product":"windows"}
- Potential Arbitrary File Download Using Office Application · test · high · {"category":"process_creation","product":"windows"}
- Potentially Suspicious Office Document Executed From Trusted Location · test · high · {"category":"process_creation","product":"windows"}
- Outlook EnableUnsafeClientMailRules Setting Enabled · test · high · {"category":"process_creation","product":"windows"}
- Suspicious Remote Child Process From Outlook · test · high · {"category":"process_creation","product":"windows"}
- Potential Arbitrary DLL Load Using Winword · test · medium · {"category":"process_creation","product":"windows"}
- Renamed CURL.EXE Execution · test · medium · {"category":"process_creation","product":"windows"}
- Renamed ZOHO Dctask64 Execution · test · high · {"category":"process_creation","product":"windows"}
- Renamed FTP.EXE Execution · test · medium · {"category":"process_creation","product":"windows"}
- Renamed NirCmd.EXE Execution · test · high · {"category":"process_creation","product":"windows"}
- Renamed PAExec Execution · test · high · {"category":"process_creation","product":"windows"}
- Renamed PingCastle Binary Execution · test · high · {"category":"process_creation","product":"windows"}
- Rundll32 Execution Without CommandLine Parameters · test · high · {"category":"process_creation","product":"windows"}
- Uncommon Child Process Of Setres.EXE · test · high · {"category":"process_creation","product":"windows"}
- Indirect Command Execution via SFTP ProxyCommand · experimental · medium · {"category":"process_creation","product":"windows"}
- Suspicious Splwow64 Without Params · test · high · {"category":"process_creation","product":"windows"}
- Suspicious Service Binary Directory · test · high · {"category":"process_creation","product":"windows"}
- Potential Binary Impersonating Sysinternals Tools · test · medium · {"category":"process_creation","product":"windows"}
- Potentially Suspicious Child Process Of VsCode · test · medium · {"category":"process_creation","product":"windows"}
- Proxy Execution via Vshadow · experimental · medium · {"product":"windows","category":"process_creation"}
- WSL Child Process Anomaly · test · medium · {"category":"process_creation","product":"windows"}
- WSL Kali-Linux Usage · experimental · high · {"category":"process_creation","product":"windows"}
- Windows Binary Executed From WSL · test · medium · {"category":"process_creation","product":"windows"}
- Custom File Open Handler Executes PowerShell · test · high · {"category":"registry_set","product":"windows"}
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0200 Indirect Command Execution – Windows utility abuse behavior chain
AN0576 Analytic 0576
Cause→effect chain: (1) A user or service launches an indirection utility (e.g., forfiles.exe, pcalua.exe, wsl.exe, scriptrunner.exe, ssh.exe with -o ProxyCommand/LocalCommand). (2) That utility spawns a secondary program/command (PowerShell, cmd, msiexec, regsvr32, curl, arbitrary EXE) and/or opens outbound network connections. (3) Optional precursor modification of SSH config to persist LocalCommand/ProxyCommand. Correlate process creation, command/script content, file access to %USERPROFILE%\.ssh\config, and network connections from the utility or its child.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.