1686750232, search_name="ESCU - Windows ClipBoard Data via Get-ClipBoard - Rule", Computer="ar-win-dc.attackrange.local", EventCode="4104", ScriptBlockText="Get-Clipboard", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1115\"],\"nist\":[\"DE.AE\"]}", annotations._all="T1115", annotations._all="Prestige Ransomware", annotations._all="DE.AE", annotations._all="CIS 10", annotations._all="Exploitation", annotations._all="Windows Post-Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1115", annotations.nist="DE.AE", count="1", firstTime="2023-06-14T13:33:20", info_max_time="1686750000.000000000", info_min_time="1686749400.000000000", info_search_time="1686750230.068561000", lastTime="2023-06-14T13:33:20", risk_message="powershell script Get-Clipboard execute Get-Clipboard commandlet in $dest$", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="25.0", savedsearch_description="The following analytic identifies a powershell script command to retrieve clipboard data. This technique was seen in several post exploitation tools like WINPEAS to steal sensitive information that was saved in clipboard. Using the Get-Clipboard powershell commandlet, adversaries can be able collect data stored in clipboard that might be a copied user name, password or other sensitive information.", user_id="'S-1-5-21-647039874-1738661239-2692048096-500'" 1686749992, search_name="ESCU - Processes launching netsh - Rule", analyticstories="Azorult", analyticstories="DHS Report TA18-074A", analyticstories="Disabling Security Tools", analyticstories="Netsh Abuse", annotations="{\"analytic_story\":[\"Netsh Abuse\",\"Disabling Security Tools\",\"DHS Report TA18-074A\",\"Azorult\"],\"cis20\":[\"CIS 10\"],\"confidence\":70,\"impact\":20,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1562.004\",\"T1562\"],\"nist\":[\"DE.AE\"]}", annotations._all="Azorult", annotations._all="T1562", annotations._all="DE.AE", annotations._all="Exploitation", annotations._all="Disabling Security Tools", annotations._all="CIS 10", annotations._all="DHS Report TA18-074A", annotations._all="T1562.004", annotations._all="Netsh Abuse", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Netsh Abuse", annotations.analytic_story="Disabling Security Tools", annotations.analytic_story="DHS Report TA18-074A", annotations.analytic_story="Azorult", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1562.004", annotations.mitre_attack="T1562", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:56", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749988.156603000", lastTime="2023-06-14T13:28:56", original_file_name="netsh.exe", parent_process="C:\\Windows\\system32\\cmd.exe /c netsh wlan show profiles | find \"Profile \"", parent_process_name="cmd.exe", process="netsh wlan show profiles", process_name="netsh.exe", risk_message="A process netsh.exe has launched netsh with command-line netsh wlan show profiles on ar-win-dc.attackrange.local.", risk_object="Administrator", risk_object_type="user", risk_score="14.0", savedsearch_description="This search looks for processes launching netsh.exe. Netsh is a command-line scripting utility that allows you to, either locally or remotely, display or modify the network configuration of a computer that is currently running. Netsh can be used as a persistence proxy technique to execute a helper DLL when netsh.exe is executed. In this search, we are looking for processes spawned by netsh.exe and executing commands via the command line.", user="Administrator" 1686749992, search_name="ESCU - Processes launching netsh - Rule", analyticstories="Azorult", analyticstories="DHS Report TA18-074A", analyticstories="Disabling Security Tools", analyticstories="Netsh Abuse", annotations="{\"analytic_story\":[\"Netsh Abuse\",\"Disabling Security Tools\",\"DHS Report TA18-074A\",\"Azorult\"],\"cis20\":[\"CIS 10\"],\"confidence\":70,\"impact\":20,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1562.004\",\"T1562\"],\"nist\":[\"DE.AE\"]}", annotations._all="Azorult", annotations._all="T1562", annotations._all="DE.AE", annotations._all="Exploitation", annotations._all="Disabling Security Tools", annotations._all="CIS 10", annotations._all="DHS Report TA18-074A", annotations._all="T1562.004", annotations._all="Netsh Abuse", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Netsh Abuse", annotations.analytic_story="Disabling Security Tools", annotations.analytic_story="DHS Report TA18-074A", annotations.analytic_story="Azorult", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1562.004", annotations.mitre_attack="T1562", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:56", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749988.156603000", lastTime="2023-06-14T13:28:56", original_file_name="netsh.exe", parent_process="C:\\Windows\\system32\\cmd.exe /c netsh wlan show profiles | find \"Profile \"", parent_process_name="cmd.exe", process="netsh wlan show profiles", process_name="netsh.exe", risk_message="A process netsh.exe has launched netsh with command-line netsh wlan show profiles on ar-win-dc.attackrange.local.", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="14.0", savedsearch_description="This search looks for processes launching netsh.exe. Netsh is a command-line scripting utility that allows you to, either locally or remotely, display or modify the network configuration of a computer that is currently running. Netsh can be used as a persistence proxy technique to execute a helper DLL when netsh.exe is executed. In this search, we are looking for processes spawned by netsh.exe and executing commands via the command line.", user="Administrator" 1686749992, search_name="ESCU - Processes launching netsh - Rule", analyticstories="Azorult", analyticstories="DHS Report TA18-074A", analyticstories="Disabling Security Tools", analyticstories="Netsh Abuse", annotations="{\"analytic_story\":[\"Netsh Abuse\",\"Disabling Security Tools\",\"DHS Report TA18-074A\",\"Azorult\"],\"cis20\":[\"CIS 10\"],\"confidence\":70,\"impact\":20,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1562.004\",\"T1562\"],\"nist\":[\"DE.AE\"]}", annotations._all="Azorult", annotations._all="T1562", annotations._all="DE.AE", annotations._all="Exploitation", annotations._all="Disabling Security Tools", annotations._all="CIS 10", annotations._all="DHS Report TA18-074A", annotations._all="T1562.004", annotations._all="Netsh Abuse", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Netsh Abuse", annotations.analytic_story="Disabling Security Tools", annotations.analytic_story="DHS Report TA18-074A", annotations.analytic_story="Azorult", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1562.004", annotations.mitre_attack="T1562", annotations.nist="DE.AE", count="3", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:55", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749988.156603000", lastTime="2023-06-14T13:28:56", original_file_name="unknown", parent_process="C:\\Windows\\System32\\cmd.exe", parent_process_name="cmd.exe", process="C:\\Windows\\System32\\netsh.exe firewall show config", process="C:\\Windows\\System32\\netsh.exe firewall show state", process="C:\\Windows\\System32\\netsh.exe wlan show profiles", process_name="netsh.exe", risk_message="A process netsh.exe has launched netsh with command-line C:\\Windows\\System32\\netsh.exe firewall show config C:\\Windows\\System32\\netsh.exe firewall show state C:\\Windows\\System32\\netsh.exe wlan show profiles on ar-win-dc.attackrange.local.", risk_object="Administrator", risk_object_type="user", risk_score="14.0", savedsearch_description="This search looks for processes launching netsh.exe. Netsh is a command-line scripting utility that allows you to, either locally or remotely, display or modify the network configuration of a computer that is currently running. Netsh can be used as a persistence proxy technique to execute a helper DLL when netsh.exe is executed. In this search, we are looking for processes spawned by netsh.exe and executing commands via the command line.", user="Administrator" 1686749992, search_name="ESCU - Processes launching netsh - Rule", analyticstories="Azorult", analyticstories="DHS Report TA18-074A", analyticstories="Disabling Security Tools", analyticstories="Netsh Abuse", annotations="{\"analytic_story\":[\"Netsh Abuse\",\"Disabling Security Tools\",\"DHS Report TA18-074A\",\"Azorult\"],\"cis20\":[\"CIS 10\"],\"confidence\":70,\"impact\":20,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1562.004\",\"T1562\"],\"nist\":[\"DE.AE\"]}", annotations._all="Azorult", annotations._all="T1562", annotations._all="DE.AE", annotations._all="Exploitation", annotations._all="Disabling Security Tools", annotations._all="CIS 10", annotations._all="DHS Report TA18-074A", annotations._all="T1562.004", annotations._all="Netsh Abuse", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Netsh Abuse", annotations.analytic_story="Disabling Security Tools", annotations.analytic_story="DHS Report TA18-074A", annotations.analytic_story="Azorult", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1562.004", annotations.mitre_attack="T1562", annotations.nist="DE.AE", count="3", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:55", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749988.156603000", lastTime="2023-06-14T13:28:56", original_file_name="unknown", parent_process="C:\\Windows\\System32\\cmd.exe", parent_process_name="cmd.exe", process="C:\\Windows\\System32\\netsh.exe firewall show config", process="C:\\Windows\\System32\\netsh.exe firewall show state", process="C:\\Windows\\System32\\netsh.exe wlan show profiles", process_name="netsh.exe", risk_message="A process netsh.exe has launched netsh with command-line C:\\Windows\\System32\\netsh.exe firewall show config C:\\Windows\\System32\\netsh.exe firewall show state C:\\Windows\\System32\\netsh.exe wlan show profiles on ar-win-dc.attackrange.local.", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="14.0", savedsearch_description="This search looks for processes launching netsh.exe. Netsh is a command-line scripting utility that allows you to, either locally or remotely, display or modify the network configuration of a computer that is currently running. Netsh can be used as a persistence proxy technique to execute a helper DLL when netsh.exe is executed. In this search, we are looking for processes spawned by netsh.exe and executing commands via the command line.", user="Administrator" 1686749992, search_name="ESCU - Processes launching netsh - Rule", analyticstories="Azorult", analyticstories="DHS Report TA18-074A", analyticstories="Disabling Security Tools", analyticstories="Netsh Abuse", annotations="{\"analytic_story\":[\"Netsh Abuse\",\"Disabling Security Tools\",\"DHS Report TA18-074A\",\"Azorult\"],\"cis20\":[\"CIS 10\"],\"confidence\":70,\"impact\":20,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1562.004\",\"T1562\"],\"nist\":[\"DE.AE\"]}", annotations._all="Azorult", annotations._all="T1562", annotations._all="DE.AE", annotations._all="Exploitation", annotations._all="Disabling Security Tools", annotations._all="CIS 10", annotations._all="DHS Report TA18-074A", annotations._all="T1562.004", annotations._all="Netsh Abuse", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Netsh Abuse", annotations.analytic_story="Disabling Security Tools", annotations.analytic_story="DHS Report TA18-074A", annotations.analytic_story="Azorult", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1562.004", annotations.mitre_attack="T1562", annotations.nist="DE.AE", count="2", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:55", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749988.156603000", lastTime="2023-06-14T13:28:55", original_file_name="netsh.exe", parent_process="\"cmd.exe\" /s /k pushd \"C:\\Temp\"", parent_process_name="cmd.exe", process="netsh firewall show config", process="netsh firewall show state", process_name="netsh.exe", risk_message="A process netsh.exe has launched netsh with command-line netsh firewall show config netsh firewall show state on ar-win-dc.attackrange.local.", risk_object="Administrator", risk_object_type="user", risk_score="14.0", savedsearch_description="This search looks for processes launching netsh.exe. Netsh is a command-line scripting utility that allows you to, either locally or remotely, display or modify the network configuration of a computer that is currently running. Netsh can be used as a persistence proxy technique to execute a helper DLL when netsh.exe is executed. In this search, we are looking for processes spawned by netsh.exe and executing commands via the command line.", user="Administrator" 1686749992, search_name="ESCU - Processes launching netsh - Rule", analyticstories="Azorult", analyticstories="DHS Report TA18-074A", analyticstories="Disabling Security Tools", analyticstories="Netsh Abuse", annotations="{\"analytic_story\":[\"Netsh Abuse\",\"Disabling Security Tools\",\"DHS Report TA18-074A\",\"Azorult\"],\"cis20\":[\"CIS 10\"],\"confidence\":70,\"impact\":20,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1562.004\",\"T1562\"],\"nist\":[\"DE.AE\"]}", annotations._all="Azorult", annotations._all="T1562", annotations._all="DE.AE", annotations._all="Exploitation", annotations._all="Disabling Security Tools", annotations._all="CIS 10", annotations._all="DHS Report TA18-074A", annotations._all="T1562.004", annotations._all="Netsh Abuse", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Netsh Abuse", annotations.analytic_story="Disabling Security Tools", annotations.analytic_story="DHS Report TA18-074A", annotations.analytic_story="Azorult", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1562.004", annotations.mitre_attack="T1562", annotations.nist="DE.AE", count="2", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:55", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749988.156603000", lastTime="2023-06-14T13:28:55", original_file_name="netsh.exe", parent_process="\"cmd.exe\" /s /k pushd \"C:\\Temp\"", parent_process_name="cmd.exe", process="netsh firewall show config", process="netsh firewall show state", process_name="netsh.exe", risk_message="A process netsh.exe has launched netsh with command-line netsh firewall show config netsh firewall show state on ar-win-dc.attackrange.local.", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="14.0", savedsearch_description="This search looks for processes launching netsh.exe. Netsh is a command-line scripting utility that allows you to, either locally or remotely, display or modify the network configuration of a computer that is currently running. Netsh can be used as a persistence proxy technique to execute a helper DLL when netsh.exe is executed. In this search, we are looking for processes spawned by netsh.exe and executing commands via the command line.", user="Administrator" 1686749933, search_name="ESCU - Windows ClipBoard Data via Get-ClipBoard - Rule", Computer="ar-win-dc.attackrange.local", EventCode="4104", ScriptBlockText="Get-Clipboard", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1115\"],\"nist\":[\"DE.AE\"]}", annotations._all="CIS 10", annotations._all="T1115", annotations._all="DE.AE", annotations._all="Windows Post-Exploitation", annotations._all="Exploitation", annotations._all="Prestige Ransomware", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1115", annotations.nist="DE.AE", count="2", firstTime="2023-06-14T13:28:59", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749930.031081000", lastTime="2023-06-14T13:33:20", risk_message="powershell script Get-Clipboard execute Get-Clipboard commandlet in $dest$", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="25.0", savedsearch_description="The following analytic identifies a powershell script command to retrieve clipboard data. This technique was seen in several post exploitation tools like WINPEAS to steal sensitive information that was saved in clipboard. Using the Get-Clipboard powershell commandlet, adversaries can be able collect data stored in clipboard that might be a copied user name, password or other sensitive information.", user_id="'S-1-5-21-647039874-1738661239-2692048096-500'" 1686749927, search_name="ESCU - Windows Private Keys Discovery - Rule", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1552.004\",\"T1552\"],\"nist\":[\"DE.AE\"]}", annotations._all="T1552.004", annotations._all="T1552", annotations._all="DE.AE", annotations._all="CIS 10", annotations._all="Windows Post-Exploitation", annotations._all="Prestige Ransomware", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1552.004", annotations.mitre_attack="T1552", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:29:27", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749919.706195000", lastTime="2023-06-14T13:29:27", original_file_name="unknown", parent_process="C:\\Windows\\System32\\cmd.exe", parent_process_guid="null", parent_process_name="cmd.exe", process="C:\\Windows\\system32\\cmd.exe /S /D /c\" dir /s/b /A:-D RDCMan.settings == *.rdg == SCClient.exe == *_history == .sudo_as_admin_successful == .profile == *bashrc == httpd.conf == *.plan == .htpasswd == .git-credentials == *.rhosts == hosts.equiv == Dockerfile == docker-compose.yml == appcmd.exe == TypedURLs == TypedURLsTime == History == Bookmarks == Cookies == \"Login Data\" == places.sqlite == key3.db == key4.db == credentials == credentials.db == access_tokens.db == accessTokens.json == legacy_credentials == azureProfile.json == unattend.txt == access.log == error.log == *.gpg == *.pgp == *config*.php == elasticsearch.y*ml == kibana.y*ml == *.p12 == *.der == *.csr == *.cer == known_hosts == id_rsa == id_dsa == *.ovpn == anaconda-ks.cfg == hostapd.conf == rsyncd.conf == cesi.conf == supervisord.conf == tomcat-users.xml == *.kdbx == KeePass.config == Ntds.dit == SAM == SYSTEM == FreeSSHDservice.ini == sysprep.inf == sysprep.xml == unattend.xml == unattended.xml == *vnc*.ini == *vnc*.c*nf* == *vnc*.txt == *vnc*.xml == groups.xml == services.xml == scheduledtasks.xml == printers.xml == drives.xml == datasources.xml == php.ini == https.conf == https-xampp.conf == httpd.conf == my.ini == my.cnf == access.log == error.log == server.xml == SiteList.xml == ConsoleHost_history.txt == setupinfo == setupinfo.bak 2>nul\"", process_guid="null", process_id="0x1908", process_name="cmd.exe", risk_message="a process with commandline C:\\Windows\\system32\\cmd.exe /S /D /c\" dir /s/b /A:-D RDCMan.settings == *.rdg == SCClient.exe == *_history == .sudo_as_admin_successful == .profile == *bashrc == httpd.conf == *.plan == .htpasswd == .git-credentials == *.rhosts == hosts.equiv == Dockerfile == docker-compose.yml == appcmd.exe == TypedURLs == TypedURLsTime == History == Bookmarks == Cookies == \"Login Data\" == places.sqlite == key3.db == key4.db == credentials == credentials.db == access_tokens.db == accessTokens.json == legacy_credentials == azureProfile.json == unattend.txt == access.log == error.log == *.gpg == *.pgp == *config*.php == elasticsearch.y*ml == kibana.y*ml == *.p12 == *.der == *.csr == *.cer == known_hosts == id_rsa == id_dsa == *.ovpn == anaconda-ks.cfg == hostapd.conf == rsyncd.conf == cesi.conf == supervisord.conf == tomcat-users.xml == *.kdbx == KeePass.config == Ntds.dit == SAM == SYSTEM == FreeSSHDservice.ini == sysprep.inf == sysprep.xml == unattend.xml == unattended.xml == *vnc*.ini == *vnc*.c*nf* == *vnc*.txt == *vnc*.xml == groups.xml == services.xml == scheduledtasks.xml == printers.xml == drives.xml == datasources.xml == php.ini == https.conf == https-xampp.conf == httpd.conf == my.ini == my.cnf == access.log == error.log == server.xml == SiteList.xml == ConsoleHost_history.txt == setupinfo == setupinfo.bak 2>nul\" that can retrieve information related to private keys in ar-win-dc.attackrange.local", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="25.0", savedsearch_description="The following analytic identifies a process command line that retrieves information related to private keys files. This technique was seen in several post exploitation tools like winpeas that are being used by Ransomware Prestige to search for private key certificates on the compromised host for insecurely stored credentials. This files can be used by adversaries to gain privileges, persistence or remote service authentication to collect more sensitive information. Some private keys required password for operation, so in this case adversaries may need to have that passphrase either via keylogging or brute force attack.", user="Administrator" 1686749927, search_name="ESCU - Windows Private Keys Discovery - Rule", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1552.004\",\"T1552\"],\"nist\":[\"DE.AE\"]}", annotations._all="T1552.004", annotations._all="T1552", annotations._all="DE.AE", annotations._all="CIS 10", annotations._all="Windows Post-Exploitation", annotations._all="Prestige Ransomware", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1552.004", annotations.mitre_attack="T1552", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:29:27", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749919.706195000", lastTime="2023-06-14T13:29:27", original_file_name="Cmd.Exe", parent_process="\"cmd.exe\" /s /k pushd \"C:\\Temp\"", parent_process_guid="{953948C6-BA8E-6489-C200-00000000F902}", parent_process_name="cmd.exe", process="C:\\Windows\\system32\\cmd.exe /S /D /c\" dir /s/b /A:-D RDCMan.settings == *.rdg == SCClient.exe == *_history == .sudo_as_admin_successful == .profile == *bashrc == httpd.conf == *.plan == .htpasswd == .git-credentials == *.rhosts == hosts.equiv == Dockerfile == docker-compose.yml == appcmd.exe == TypedURLs == TypedURLsTime == History == Bookmarks == Cookies == \"Login Data\" == places.sqlite == key3.db == key4.db == credentials == credentials.db == access_tokens.db == accessTokens.json == legacy_credentials == azureProfile.json == unattend.txt == access.log == error.log == *.gpg == *.pgp == *config*.php == elasticsearch.y*ml == kibana.y*ml == *.p12 == *.der == *.csr == *.cer == known_hosts == id_rsa == id_dsa == *.ovpn == anaconda-ks.cfg == hostapd.conf == rsyncd.conf == cesi.conf == supervisord.conf == tomcat-users.xml == *.kdbx == KeePass.config == Ntds.dit == SAM == SYSTEM == FreeSSHDservice.ini == sysprep.inf == sysprep.xml == unattend.xml == unattended.xml == *vnc*.ini == *vnc*.c*nf* == *vnc*.txt == *vnc*.xml == groups.xml == services.xml == scheduledtasks.xml == printers.xml == drives.xml == datasources.xml == php.ini == https.conf == https-xampp.conf == httpd.conf == my.ini == my.cnf == access.log == error.log == server.xml == SiteList.xml == ConsoleHost_history.txt == setupinfo == setupinfo.bak 2>nul\"", process_guid="{953948C6-C0B7-6489-CB18-00000000F902}", process_id="6408", process_name="cmd.exe", risk_message="a process with commandline C:\\Windows\\system32\\cmd.exe /S /D /c\" dir /s/b /A:-D RDCMan.settings == *.rdg == SCClient.exe == *_history == .sudo_as_admin_successful == .profile == *bashrc == httpd.conf == *.plan == .htpasswd == .git-credentials == *.rhosts == hosts.equiv == Dockerfile == docker-compose.yml == appcmd.exe == TypedURLs == TypedURLsTime == History == Bookmarks == Cookies == \"Login Data\" == places.sqlite == key3.db == key4.db == credentials == credentials.db == access_tokens.db == accessTokens.json == legacy_credentials == azureProfile.json == unattend.txt == access.log == error.log == *.gpg == *.pgp == *config*.php == elasticsearch.y*ml == kibana.y*ml == *.p12 == *.der == *.csr == *.cer == known_hosts == id_rsa == id_dsa == *.ovpn == anaconda-ks.cfg == hostapd.conf == rsyncd.conf == cesi.conf == supervisord.conf == tomcat-users.xml == *.kdbx == KeePass.config == Ntds.dit == SAM == SYSTEM == FreeSSHDservice.ini == sysprep.inf == sysprep.xml == unattend.xml == unattended.xml == *vnc*.ini == *vnc*.c*nf* == *vnc*.txt == *vnc*.xml == groups.xml == services.xml == scheduledtasks.xml == printers.xml == drives.xml == datasources.xml == php.ini == https.conf == https-xampp.conf == httpd.conf == my.ini == my.cnf == access.log == error.log == server.xml == SiteList.xml == ConsoleHost_history.txt == setupinfo == setupinfo.bak 2>nul\" that can retrieve information related to private keys in ar-win-dc.attackrange.local", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="25.0", savedsearch_description="The following analytic identifies a process command line that retrieves information related to private keys files. This technique was seen in several post exploitation tools like winpeas that are being used by Ransomware Prestige to search for private key certificates on the compromised host for insecurely stored credentials. This files can be used by adversaries to gain privileges, persistence or remote service authentication to collect more sensitive information. Some private keys required password for operation, so in this case adversaries may need to have that passphrase either via keylogging or brute force attack.", user="Administrator" 1686749905, search_name="ESCU - Windows Security Support Provider Reg Query - Rule", analyticstories="Prestige Ransomware", analyticstories="Sneaky Active Directory Persistence Tricks", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\",\"Sneaky Active Directory Persistence Tricks\"],\"cis20\":[\"CIS 10\"],\"confidence\":30,\"impact\":30,\"kill_chain_phases\":[\"Installation\",\"Exploitation\"],\"mitre_attack\":[\"T1547.005\",\"T1547\"],\"nist\":[\"DE.AE\"]}", annotations._all="T1547", annotations._all="DE.AE", annotations._all="T1547.005", annotations._all="Prestige Ransomware", annotations._all="CIS 10", annotations._all="Installation", annotations._all="Sneaky Active Directory Persistence Tricks", annotations._all="Exploitation", annotations._all="Windows Post-Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.analytic_story="Sneaky Active Directory Persistence Tricks", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1547.005", annotations.mitre_attack="T1547", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:50", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749900.116488000", lastTime="2023-06-14T13:28:50", original_file_name="unknown", parent_process="C:\\Windows\\System32\\cmd.exe", parent_process_guid="null", parent_process_name="cmd.exe", process="C:\\Windows\\System32\\reg.exe QUERY \"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\LSA\" /v RunAsPPL", process_guid="null", process_id="0xed4", process_name="reg.exe", risk_message="process with reg query command line C:\\Windows\\System32\\reg.exe QUERY \"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\LSA\" /v RunAsPPL in ar-win-dc.attackrange.local", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="9.0", savedsearch_description="The following analytic identifies a process command line related to the discovery of possible Security Support Providers in the registry. This technique is being abused by adversaries or post exploitation tools like winpeas to gather LSA protection and configuration in the registry in the targeted host. This registry entry can contain several information related to LSA that validates users for local and remote sign-ins and enforces local security policies. Understanding LSA protection may give a good information in accessing LSA content in memory which is commonly attack by adversaries and tool like mimikatz to scrape password hashes or clear plain text passwords.", user="Administrator" 1686749905, search_name="ESCU - Windows Security Support Provider Reg Query - Rule", analyticstories="Prestige Ransomware", analyticstories="Sneaky Active Directory Persistence Tricks", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\",\"Sneaky Active Directory Persistence Tricks\"],\"cis20\":[\"CIS 10\"],\"confidence\":30,\"impact\":30,\"kill_chain_phases\":[\"Installation\",\"Exploitation\"],\"mitre_attack\":[\"T1547.005\",\"T1547\"],\"nist\":[\"DE.AE\"]}", annotations._all="T1547", annotations._all="DE.AE", annotations._all="T1547.005", annotations._all="Prestige Ransomware", annotations._all="CIS 10", annotations._all="Installation", annotations._all="Sneaky Active Directory Persistence Tricks", annotations._all="Exploitation", annotations._all="Windows Post-Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.analytic_story="Sneaky Active Directory Persistence Tricks", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1547.005", annotations.mitre_attack="T1547", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:50", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749900.116488000", lastTime="2023-06-14T13:28:50", original_file_name="unknown", parent_process="C:\\Windows\\System32\\cmd.exe", parent_process_guid="null", parent_process_name="cmd.exe", process="C:\\Windows\\System32\\reg.exe QUERY \"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\LSA\" /v LsaCfgFlags", process_guid="null", process_id="0x6e8", process_name="reg.exe", risk_message="process with reg query command line C:\\Windows\\System32\\reg.exe QUERY \"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\LSA\" /v LsaCfgFlags in ar-win-dc.attackrange.local", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="9.0", savedsearch_description="The following analytic identifies a process command line related to the discovery of possible Security Support Providers in the registry. This technique is being abused by adversaries or post exploitation tools like winpeas to gather LSA protection and configuration in the registry in the targeted host. This registry entry can contain several information related to LSA that validates users for local and remote sign-ins and enforces local security policies. Understanding LSA protection may give a good information in accessing LSA content in memory which is commonly attack by adversaries and tool like mimikatz to scrape password hashes or clear plain text passwords.", user="Administrator" 1686749905, search_name="ESCU - Windows Security Support Provider Reg Query - Rule", analyticstories="Prestige Ransomware", analyticstories="Sneaky Active Directory Persistence Tricks", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\",\"Sneaky Active Directory Persistence Tricks\"],\"cis20\":[\"CIS 10\"],\"confidence\":30,\"impact\":30,\"kill_chain_phases\":[\"Installation\",\"Exploitation\"],\"mitre_attack\":[\"T1547.005\",\"T1547\"],\"nist\":[\"DE.AE\"]}", annotations._all="T1547", annotations._all="DE.AE", annotations._all="T1547.005", annotations._all="Prestige Ransomware", annotations._all="CIS 10", annotations._all="Installation", annotations._all="Sneaky Active Directory Persistence Tricks", annotations._all="Exploitation", annotations._all="Windows Post-Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.analytic_story="Sneaky Active Directory Persistence Tricks", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1547.005", annotations.mitre_attack="T1547", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:50", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749900.116488000", lastTime="2023-06-14T13:28:50", original_file_name="reg.exe", parent_process="\"cmd.exe\" /s /k pushd \"C:\\Temp\"", parent_process_guid="{953948C6-BA8E-6489-C200-00000000F902}", parent_process_name="cmd.exe", process="REG QUERY \"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\LSA\" /v RunAsPPL", process_guid="{953948C6-C092-6489-270E-00000000F902}", process_id="3796", process_name="reg.exe", risk_message="process with reg query command line REG QUERY \"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\LSA\" /v RunAsPPL in ar-win-dc.attackrange.local", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="9.0", savedsearch_description="The following analytic identifies a process command line related to the discovery of possible Security Support Providers in the registry. This technique is being abused by adversaries or post exploitation tools like winpeas to gather LSA protection and configuration in the registry in the targeted host. This registry entry can contain several information related to LSA that validates users for local and remote sign-ins and enforces local security policies. Understanding LSA protection may give a good information in accessing LSA content in memory which is commonly attack by adversaries and tool like mimikatz to scrape password hashes or clear plain text passwords.", user="Administrator" 1686749905, search_name="ESCU - Windows Security Support Provider Reg Query - Rule", analyticstories="Prestige Ransomware", analyticstories="Sneaky Active Directory Persistence Tricks", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\",\"Sneaky Active Directory Persistence Tricks\"],\"cis20\":[\"CIS 10\"],\"confidence\":30,\"impact\":30,\"kill_chain_phases\":[\"Installation\",\"Exploitation\"],\"mitre_attack\":[\"T1547.005\",\"T1547\"],\"nist\":[\"DE.AE\"]}", annotations._all="T1547", annotations._all="DE.AE", annotations._all="T1547.005", annotations._all="Prestige Ransomware", annotations._all="CIS 10", annotations._all="Installation", annotations._all="Sneaky Active Directory Persistence Tricks", annotations._all="Exploitation", annotations._all="Windows Post-Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.analytic_story="Sneaky Active Directory Persistence Tricks", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1547.005", annotations.mitre_attack="T1547", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:50", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749900.116488000", lastTime="2023-06-14T13:28:50", original_file_name="reg.exe", parent_process="\"cmd.exe\" /s /k pushd \"C:\\Temp\"", parent_process_guid="{953948C6-BA8E-6489-C200-00000000F902}", parent_process_name="cmd.exe", process="REG QUERY \"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\LSA\" /v LsaCfgFlags", process_guid="{953948C6-C092-6489-2B0E-00000000F902}", process_id="1768", process_name="reg.exe", risk_message="process with reg query command line REG QUERY \"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\LSA\" /v LsaCfgFlags in ar-win-dc.attackrange.local", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="9.0", savedsearch_description="The following analytic identifies a process command line related to the discovery of possible Security Support Providers in the registry. This technique is being abused by adversaries or post exploitation tools like winpeas to gather LSA protection and configuration in the registry in the targeted host. This registry entry can contain several information related to LSA that validates users for local and remote sign-ins and enforces local security policies. Understanding LSA protection may give a good information in accessing LSA content in memory which is commonly attack by adversaries and tool like mimikatz to scrape password hashes or clear plain text passwords.", user="Administrator" 1686749869, search_name="ESCU - Create or delete windows shares using net exe - Rule", analyticstories="CISA AA22-277A", analyticstories="Hidden Cobra Malware", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Hidden Cobra Malware\",\"CISA AA22-277A\",\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1070\",\"T1070.005\"],\"nist\":[\"DE.CM\"]}", annotations._all="T1070", annotations._all="Prestige Ransomware", annotations._all="CIS 10", annotations._all="T1070.005", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="Hidden Cobra Malware", annotations._all="Windows Post-Exploitation", annotations._all="CISA AA22-277A", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Hidden Cobra Malware", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1070", annotations.mitre_attack="T1070.005", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:54", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749864.126226000", lastTime="2023-06-14T13:28:54", original_file_name="net.exe", parent_process="\"cmd.exe\" /s /k pushd \"C:\\Temp\"", process="net share", process_name="net.exe", risk_message="An instance of $parent_process_name$ spawning net.exe was identified on endpoint ar-win-dc.attackrange.local by user Administrator enumerating Windows file shares.", risk_object="net.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="This search looks for the creation or deletion of hidden shares using net.exe.", user="Administrator" 1686749869, search_name="ESCU - Create or delete windows shares using net exe - Rule", analyticstories="CISA AA22-277A", analyticstories="Hidden Cobra Malware", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Hidden Cobra Malware\",\"CISA AA22-277A\",\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1070\",\"T1070.005\"],\"nist\":[\"DE.CM\"]}", annotations._all="T1070", annotations._all="Prestige Ransomware", annotations._all="CIS 10", annotations._all="T1070.005", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="Hidden Cobra Malware", annotations._all="Windows Post-Exploitation", annotations._all="CISA AA22-277A", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Hidden Cobra Malware", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1070", annotations.mitre_attack="T1070.005", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:54", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749864.126226000", lastTime="2023-06-14T13:28:54", original_file_name="net.exe", parent_process="\"cmd.exe\" /s /k pushd \"C:\\Temp\"", process="net share", process_name="net.exe", risk_message="An instance of $parent_process_name$ spawning net.exe was identified on endpoint ar-win-dc.attackrange.local by user Administrator enumerating Windows file shares.", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="25.0", savedsearch_description="This search looks for the creation or deletion of hidden shares using net.exe.", user="Administrator" 1686749869, search_name="ESCU - Create or delete windows shares using net exe - Rule", analyticstories="CISA AA22-277A", analyticstories="Hidden Cobra Malware", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Hidden Cobra Malware\",\"CISA AA22-277A\",\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1070\",\"T1070.005\"],\"nist\":[\"DE.CM\"]}", annotations._all="T1070", annotations._all="Prestige Ransomware", annotations._all="CIS 10", annotations._all="T1070.005", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="Hidden Cobra Malware", annotations._all="Windows Post-Exploitation", annotations._all="CISA AA22-277A", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Hidden Cobra Malware", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1070", annotations.mitre_attack="T1070.005", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:54", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749864.126226000", lastTime="2023-06-14T13:28:54", original_file_name="net.exe", parent_process="\"cmd.exe\" /s /k pushd \"C:\\Temp\"", process="net share", process_name="net.exe", risk_message="An instance of $parent_process_name$ spawning net.exe was identified on endpoint ar-win-dc.attackrange.local by user Administrator enumerating Windows file shares.", risk_object="Administrator", risk_object_type="user", risk_score="25.0", savedsearch_description="This search looks for the creation or deletion of hidden shares using net.exe.", user="Administrator" 1686749869, search_name="ESCU - Create or delete windows shares using net exe - Rule", analyticstories="CISA AA22-277A", analyticstories="Hidden Cobra Malware", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Hidden Cobra Malware\",\"CISA AA22-277A\",\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1070\",\"T1070.005\"],\"nist\":[\"DE.CM\"]}", annotations._all="T1070", annotations._all="Prestige Ransomware", annotations._all="CIS 10", annotations._all="T1070.005", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="Hidden Cobra Malware", annotations._all="Windows Post-Exploitation", annotations._all="CISA AA22-277A", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Hidden Cobra Malware", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1070", annotations.mitre_attack="T1070.005", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:54", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749864.126226000", lastTime="2023-06-14T13:28:54", original_file_name="unknown", parent_process="C:\\Windows\\System32\\net.exe", process="C:\\Windows\\system32\\net1 share", process_name="net1.exe", risk_message="An instance of $parent_process_name$ spawning net1.exe was identified on endpoint ar-win-dc.attackrange.local by user Administrator enumerating Windows file shares.", risk_object="net1.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="This search looks for the creation or deletion of hidden shares using net.exe.", user="Administrator" 1686749869, search_name="ESCU - Create or delete windows shares using net exe - Rule", analyticstories="CISA AA22-277A", analyticstories="Hidden Cobra Malware", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Hidden Cobra Malware\",\"CISA AA22-277A\",\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1070\",\"T1070.005\"],\"nist\":[\"DE.CM\"]}", annotations._all="T1070", annotations._all="Prestige Ransomware", annotations._all="CIS 10", annotations._all="T1070.005", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="Hidden Cobra Malware", annotations._all="Windows Post-Exploitation", annotations._all="CISA AA22-277A", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Hidden Cobra Malware", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1070", annotations.mitre_attack="T1070.005", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:54", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749864.126226000", lastTime="2023-06-14T13:28:54", original_file_name="unknown", parent_process="C:\\Windows\\System32\\net.exe", process="C:\\Windows\\system32\\net1 share", process_name="net1.exe", risk_message="An instance of $parent_process_name$ spawning net1.exe was identified on endpoint ar-win-dc.attackrange.local by user Administrator enumerating Windows file shares.", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="25.0", savedsearch_description="This search looks for the creation or deletion of hidden shares using net.exe.", user="Administrator" 1686749869, search_name="ESCU - Create or delete windows shares using net exe - Rule", analyticstories="CISA AA22-277A", analyticstories="Hidden Cobra Malware", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Hidden Cobra Malware\",\"CISA AA22-277A\",\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1070\",\"T1070.005\"],\"nist\":[\"DE.CM\"]}", annotations._all="T1070", annotations._all="Prestige Ransomware", annotations._all="CIS 10", annotations._all="T1070.005", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="Hidden Cobra Malware", annotations._all="Windows Post-Exploitation", annotations._all="CISA AA22-277A", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Hidden Cobra Malware", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1070", annotations.mitre_attack="T1070.005", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:54", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749864.126226000", lastTime="2023-06-14T13:28:54", original_file_name="unknown", parent_process="C:\\Windows\\System32\\net.exe", process="C:\\Windows\\system32\\net1 share", process_name="net1.exe", risk_message="An instance of $parent_process_name$ spawning net1.exe was identified on endpoint ar-win-dc.attackrange.local by user Administrator enumerating Windows file shares.", risk_object="Administrator", risk_object_type="user", risk_score="25.0", savedsearch_description="This search looks for the creation or deletion of hidden shares using net.exe.", user="Administrator" 1686749869, search_name="ESCU - Create or delete windows shares using net exe - Rule", analyticstories="CISA AA22-277A", analyticstories="Hidden Cobra Malware", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Hidden Cobra Malware\",\"CISA AA22-277A\",\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1070\",\"T1070.005\"],\"nist\":[\"DE.CM\"]}", annotations._all="T1070", annotations._all="Prestige Ransomware", annotations._all="CIS 10", annotations._all="T1070.005", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="Hidden Cobra Malware", annotations._all="Windows Post-Exploitation", annotations._all="CISA AA22-277A", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Hidden Cobra Malware", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1070", annotations.mitre_attack="T1070.005", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:54", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749864.126226000", lastTime="2023-06-14T13:28:54", original_file_name="net1.exe", parent_process="net share", process="C:\\Windows\\system32\\net1 share", process_name="net1.exe", risk_message="An instance of $parent_process_name$ spawning net1.exe was identified on endpoint ar-win-dc.attackrange.local by user Administrator enumerating Windows file shares.", risk_object="net1.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="This search looks for the creation or deletion of hidden shares using net.exe.", user="Administrator" 1686749869, search_name="ESCU - Create or delete windows shares using net exe - Rule", analyticstories="CISA AA22-277A", analyticstories="Hidden Cobra Malware", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Hidden Cobra Malware\",\"CISA AA22-277A\",\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1070\",\"T1070.005\"],\"nist\":[\"DE.CM\"]}", annotations._all="T1070", annotations._all="Prestige Ransomware", annotations._all="CIS 10", annotations._all="T1070.005", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="Hidden Cobra Malware", annotations._all="Windows Post-Exploitation", annotations._all="CISA AA22-277A", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Hidden Cobra Malware", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1070", annotations.mitre_attack="T1070.005", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:54", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749864.126226000", lastTime="2023-06-14T13:28:54", original_file_name="net1.exe", parent_process="net share", process="C:\\Windows\\system32\\net1 share", process_name="net1.exe", risk_message="An instance of $parent_process_name$ spawning net1.exe was identified on endpoint ar-win-dc.attackrange.local by user Administrator enumerating Windows file shares.", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="25.0", savedsearch_description="This search looks for the creation or deletion of hidden shares using net.exe.", user="Administrator" 1686749869, search_name="ESCU - Create or delete windows shares using net exe - Rule", analyticstories="CISA AA22-277A", analyticstories="Hidden Cobra Malware", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Hidden Cobra Malware\",\"CISA AA22-277A\",\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1070\",\"T1070.005\"],\"nist\":[\"DE.CM\"]}", annotations._all="T1070", annotations._all="Prestige Ransomware", annotations._all="CIS 10", annotations._all="T1070.005", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="Hidden Cobra Malware", annotations._all="Windows Post-Exploitation", annotations._all="CISA AA22-277A", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Hidden Cobra Malware", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1070", annotations.mitre_attack="T1070.005", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:54", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749864.126226000", lastTime="2023-06-14T13:28:54", original_file_name="net1.exe", parent_process="net share", process="C:\\Windows\\system32\\net1 share", process_name="net1.exe", risk_message="An instance of $parent_process_name$ spawning net1.exe was identified on endpoint ar-win-dc.attackrange.local by user Administrator enumerating Windows file shares.", risk_object="Administrator", risk_object_type="user", risk_score="25.0", savedsearch_description="This search looks for the creation or deletion of hidden shares using net.exe.", user="Administrator" 1686749869, search_name="ESCU - Create or delete windows shares using net exe - Rule", analyticstories="CISA AA22-277A", analyticstories="Hidden Cobra Malware", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Hidden Cobra Malware\",\"CISA AA22-277A\",\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1070\",\"T1070.005\"],\"nist\":[\"DE.CM\"]}", annotations._all="T1070", annotations._all="Prestige Ransomware", annotations._all="CIS 10", annotations._all="T1070.005", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="Hidden Cobra Malware", annotations._all="Windows Post-Exploitation", annotations._all="CISA AA22-277A", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Hidden Cobra Malware", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1070", annotations.mitre_attack="T1070.005", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:54", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749864.126226000", lastTime="2023-06-14T13:28:54", original_file_name="unknown", parent_process="C:\\Windows\\System32\\cmd.exe", process="C:\\Windows\\System32\\net.exe share", process_name="net.exe", risk_message="An instance of $parent_process_name$ spawning net.exe was identified on endpoint ar-win-dc.attackrange.local by user Administrator enumerating Windows file shares.", risk_object="net.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="This search looks for the creation or deletion of hidden shares using net.exe.", user="Administrator" 1686749869, search_name="ESCU - Create or delete windows shares using net exe - Rule", analyticstories="CISA AA22-277A", analyticstories="Hidden Cobra Malware", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Hidden Cobra Malware\",\"CISA AA22-277A\",\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1070\",\"T1070.005\"],\"nist\":[\"DE.CM\"]}", annotations._all="T1070", annotations._all="Prestige Ransomware", annotations._all="CIS 10", annotations._all="T1070.005", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="Hidden Cobra Malware", annotations._all="Windows Post-Exploitation", annotations._all="CISA AA22-277A", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Hidden Cobra Malware", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1070", annotations.mitre_attack="T1070.005", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:54", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749864.126226000", lastTime="2023-06-14T13:28:54", original_file_name="unknown", parent_process="C:\\Windows\\System32\\cmd.exe", process="C:\\Windows\\System32\\net.exe share", process_name="net.exe", risk_message="An instance of $parent_process_name$ spawning net.exe was identified on endpoint ar-win-dc.attackrange.local by user Administrator enumerating Windows file shares.", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="25.0", savedsearch_description="This search looks for the creation or deletion of hidden shares using net.exe.", user="Administrator" 1686749869, search_name="ESCU - Create or delete windows shares using net exe - Rule", analyticstories="CISA AA22-277A", analyticstories="Hidden Cobra Malware", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Hidden Cobra Malware\",\"CISA AA22-277A\",\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1070\",\"T1070.005\"],\"nist\":[\"DE.CM\"]}", annotations._all="T1070", annotations._all="Prestige Ransomware", annotations._all="CIS 10", annotations._all="T1070.005", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="Hidden Cobra Malware", annotations._all="Windows Post-Exploitation", annotations._all="CISA AA22-277A", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Hidden Cobra Malware", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1070", annotations.mitre_attack="T1070.005", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:54", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749864.126226000", lastTime="2023-06-14T13:28:54", original_file_name="unknown", parent_process="C:\\Windows\\System32\\cmd.exe", process="C:\\Windows\\System32\\net.exe share", process_name="net.exe", risk_message="An instance of $parent_process_name$ spawning net.exe was identified on endpoint ar-win-dc.attackrange.local by user Administrator enumerating Windows file shares.", risk_object="Administrator", risk_object_type="user", risk_score="25.0", savedsearch_description="This search looks for the creation or deletion of hidden shares using net.exe.", user="Administrator" 1686749340, search_name="ESCU - Excessive Usage Of Cacls App - Rule", orig_time="1686749340", analyticstories="Azorult", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", analyticstories="XMRig", annotations="{\"analytic_story\":[\"XMRig\",\"Azorult\",\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":100,\"impact\":80,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1222\"],\"nist\":[\"DE.AE\"]}", annotations._all="Azorult", annotations._all="Prestige Ransomware", annotations._all="Windows Post-Exploitation", annotations._all="Exploitation", annotations._all="DE.AE", annotations._all="T1222", annotations._all="CIS 10", annotations._all="XMRig", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="XMRig", annotations.analytic_story="Azorult", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1222", annotations.nist="DE.AE", count="26", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:29:00", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749861.767759000", lastTime="2023-06-14T13:29:23", parent_process="C:\\Windows\\System32\\cmd.exe", parent_process_name="cmd.exe", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files (x86)\\Mozilla Maintenance Service\\maintenanceservice.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Amazon\\XenTools\\LiteAgent.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Amazon\\cfn-bootstrap\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Amazon\\cfn-bootstrap\\winhup.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Aurora-Agent\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Aurora-Agent\\aurora-agent.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Git\\cmd\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\ProgramData\\chocolatey\\bin\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Python311\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Python311\\Scripts\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Users\\Administrator\\AppData\\Local\\Microsoft\\WindowsApps\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\SMSvcHost.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\SysWow64\\perfhost.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\System32\\Wbem\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\servicing\\TrustedInstaller.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\sysmon64.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\system32\"", process="C:\\Windows\\System32\\icacls.exe \"c:\\Program Files\\ansible\\sysmon\"", process="C:\\Windows\\System32\\icacls.exe C:\\Windows\\ADWS\\Microsoft.ActiveDirectory.WebServices.exe", process="C:\\Windows\\System32\\icacls.exe C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\SMSvcHost.exe", process="C:\\Windows\\System32\\icacls.exe C:\\Windows\\SysWow64\\perfhost.exe", process="C:\\Windows\\System32\\icacls.exe C:\\Windows\\servicing\\TrustedInstaller.exe", process="C:\\Windows\\System32\\icacls.exe C:\\Windows\\sysmon64.exe", process_id="0x10f4", process_id="0x1128", process_id="0x11f4", process_id="0x12e8", process_id="0x1368", process_id="0x1390", process_id="0x14c0", process_id="0x162c", process_id="0x165c", process_id="0x17cc", process_id="0x18b4", process_id="0x1a54", process_id="0x1a5c", process_id="0x1b00", process_id="0x1b6c", process_id="0x1b7c", process_id="0x1be0", process_id="0x1e4", process_id="0x6a0", process_id="0x784", process_id="0x7d4", process_id="0x998", process_id="0x9a4", process_id="0xe00", process_name="icacls.exe", risk_message="An excessive amount of icacls.exe was executed on ar-win-dc.attackrange.local attempting to modify permissions.", risk_object="icacls.exe", risk_object_type="other", risk_score="80.0", savedsearch_description="The following analytic identifies excessive usage of `cacls.exe`, `xcacls.exe` or `icacls.exe` application to change file or folder permission. This behavior is commonly seen where the adversary attempts to impair some users from deleting or accessing its malware components or artifact from the compromised system.", user="Administrator" 1686749340, search_name="ESCU - Excessive Usage Of Cacls App - Rule", orig_time="1686749340", analyticstories="Azorult", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", analyticstories="XMRig", annotations="{\"analytic_story\":[\"XMRig\",\"Azorult\",\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":100,\"impact\":80,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1222\"],\"nist\":[\"DE.AE\"]}", annotations._all="Azorult", annotations._all="Prestige Ransomware", annotations._all="Windows Post-Exploitation", annotations._all="Exploitation", annotations._all="DE.AE", annotations._all="T1222", annotations._all="CIS 10", annotations._all="XMRig", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="XMRig", annotations.analytic_story="Azorult", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1222", annotations.nist="DE.AE", count="26", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:29:00", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749861.767759000", lastTime="2023-06-14T13:29:23", parent_process="C:\\Windows\\System32\\cmd.exe", parent_process_name="cmd.exe", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files (x86)\\Mozilla Maintenance Service\\maintenanceservice.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Amazon\\XenTools\\LiteAgent.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Amazon\\cfn-bootstrap\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Amazon\\cfn-bootstrap\\winhup.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Aurora-Agent\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Aurora-Agent\\aurora-agent.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Git\\cmd\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\ProgramData\\chocolatey\\bin\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Python311\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Python311\\Scripts\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Users\\Administrator\\AppData\\Local\\Microsoft\\WindowsApps\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\SMSvcHost.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\SysWow64\\perfhost.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\System32\\Wbem\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\servicing\\TrustedInstaller.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\sysmon64.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\system32\"", process="C:\\Windows\\System32\\icacls.exe \"c:\\Program Files\\ansible\\sysmon\"", process="C:\\Windows\\System32\\icacls.exe C:\\Windows\\ADWS\\Microsoft.ActiveDirectory.WebServices.exe", process="C:\\Windows\\System32\\icacls.exe C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\SMSvcHost.exe", process="C:\\Windows\\System32\\icacls.exe C:\\Windows\\SysWow64\\perfhost.exe", process="C:\\Windows\\System32\\icacls.exe C:\\Windows\\servicing\\TrustedInstaller.exe", process="C:\\Windows\\System32\\icacls.exe C:\\Windows\\sysmon64.exe", process_id="0x10f4", process_id="0x1128", process_id="0x11f4", process_id="0x12e8", process_id="0x1368", process_id="0x1390", process_id="0x14c0", process_id="0x162c", process_id="0x165c", process_id="0x17cc", process_id="0x18b4", process_id="0x1a54", process_id="0x1a5c", process_id="0x1b00", process_id="0x1b6c", process_id="0x1b7c", process_id="0x1be0", process_id="0x1e4", process_id="0x6a0", process_id="0x784", process_id="0x7d4", process_id="0x998", process_id="0x9a4", process_id="0xe00", process_name="icacls.exe", risk_message="An excessive amount of icacls.exe was executed on ar-win-dc.attackrange.local attempting to modify permissions.", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="80.0", savedsearch_description="The following analytic identifies excessive usage of `cacls.exe`, `xcacls.exe` or `icacls.exe` application to change file or folder permission. This behavior is commonly seen where the adversary attempts to impair some users from deleting or accessing its malware components or artifact from the compromised system.", user="Administrator" 1686749280, search_name="ESCU - Excessive Usage Of Cacls App - Rule", orig_time="1686749280", analyticstories="Azorult", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", analyticstories="XMRig", annotations="{\"analytic_story\":[\"XMRig\",\"Azorult\",\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":100,\"impact\":80,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1222\"],\"nist\":[\"DE.AE\"]}", annotations._all="Azorult", annotations._all="Prestige Ransomware", annotations._all="Windows Post-Exploitation", annotations._all="Exploitation", annotations._all="DE.AE", annotations._all="T1222", annotations._all="CIS 10", annotations._all="XMRig", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="XMRig", annotations.analytic_story="Azorult", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1222", annotations.nist="DE.AE", count="62", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:52", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749861.767759000", lastTime="2023-06-14T13:28:59", parent_process="C:\\Windows\\System32\\cmd.exe", parent_process_name="cmd.exe", process="C:\\Windows\\System32\\icacls.exe \"C:\\Documents and Settings\\Administrator\\Start Menu\\Programs\\Startup\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Documents and Settings\\Administrator\\Start Menu\\Programs\\Startup\\*\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\*\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Amazon\\SSM\\\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Amazon\\SSM\\amazon-ssm-agent.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Amazon\\SSM\\ssm-agent-worker.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Aurora-Agent\\\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Aurora-Agent\\aurora-agent.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Aurora-Agent\\tools\\\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Aurora-Agent\\tools\\aurora-dashboard.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Mozilla Firefox\\\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Mozilla Firefox\\firefox.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Notepad++\\\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Notepad++\\notepad++.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\*\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Users\\Administrator\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Users\\Administrator\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\*\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\ADWS\\Microsoft.ActiveDirectory.WebServices.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\ADWS\\\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\Explorer.EXE\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\SystemApps\\Microsoft.Windows.Cortana_cw5n1h2txyewy\\SearchUI.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\SystemApps\\Microsoft.Windows.Cortana_cw5n1h2txyewy\\\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\SystemApps\\ShellExperienceHost_cw5n1h2txyewy\\ShellExperienceHost.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\SystemApps\\ShellExperienceHost_cw5n1h2txyewy\\\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\WinSxS\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.5771_none_7ee250a22208ec93\\\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\servicing\\TrustedInstaller.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\servicing\\\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\sysmon64.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\winsxs\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.5771_none_7ee250a22208ec93\\TiWorker.exe\"", process_id="0x1020", process_id="0x104c", process_id="0x10ac", process_id="0x1138", process_id="0x1160", process_id="0x1164", process_id="0x120", process_id="0x1260", process_id="0x12d0", process_id="0x1394", process_id="0x13c0", process_id="0x13dc", process_id="0x1478", process_id="0x14d0", process_id="0x1618", process_id="0x1630", process_id="0x1674", process_id="0x16d0", process_id="0x16f0", process_id="0x1780", process_id="0x17c8", process_id="0x17cc", process_id="0x1844", process_id="0x1870", process_id="0x1904", process_id="0x1924", process_id="0x198c", process_id="0x199c", process_id="0x19fc", process_id="0x1a04", process_id="0x1a28", process_id="0x1a2c", process_id="0x1a30", process_id="0x1a5c", process_id="0x1a6c", process_id="0x1a70", process_id="0x1a88", process_id="0x1b34", process_id="0x1b68", process_id="0x1be0", process_id="0x214", process_id="0x230", process_id="0x408", process_id="0x434", process_id="0x66c", process_id="0x694", process_id="0x6a8", process_id="0x8e0", process_id="0x8ec", process_id="0xb90", process_id="0xc28", process_id="0xc40", process_id="0xc98", process_id="0xd98", process_id="0xe00", process_id="0xe84", process_id="0xf28", process_name="icacls.exe", risk_message="An excessive amount of icacls.exe was executed on ar-win-dc.attackrange.local attempting to modify permissions.", risk_object="icacls.exe", risk_object_type="other", risk_score="80.0", savedsearch_description="The following analytic identifies excessive usage of `cacls.exe`, `xcacls.exe` or `icacls.exe` application to change file or folder permission. This behavior is commonly seen where the adversary attempts to impair some users from deleting or accessing its malware components or artifact from the compromised system.", user="Administrator" 1686749280, search_name="ESCU - Excessive Usage Of Cacls App - Rule", orig_time="1686749280", analyticstories="Azorult", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", analyticstories="XMRig", annotations="{\"analytic_story\":[\"XMRig\",\"Azorult\",\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":100,\"impact\":80,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1222\"],\"nist\":[\"DE.AE\"]}", annotations._all="Azorult", annotations._all="Prestige Ransomware", annotations._all="Windows Post-Exploitation", annotations._all="Exploitation", annotations._all="DE.AE", annotations._all="T1222", annotations._all="CIS 10", annotations._all="XMRig", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="XMRig", annotations.analytic_story="Azorult", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1222", annotations.nist="DE.AE", count="62", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:52", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749861.767759000", lastTime="2023-06-14T13:28:59", parent_process="C:\\Windows\\System32\\cmd.exe", parent_process_name="cmd.exe", process="C:\\Windows\\System32\\icacls.exe \"C:\\Documents and Settings\\Administrator\\Start Menu\\Programs\\Startup\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Documents and Settings\\Administrator\\Start Menu\\Programs\\Startup\\*\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\*\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Amazon\\SSM\\\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Amazon\\SSM\\amazon-ssm-agent.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Amazon\\SSM\\ssm-agent-worker.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Aurora-Agent\\\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Aurora-Agent\\aurora-agent.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Aurora-Agent\\tools\\\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Aurora-Agent\\tools\\aurora-dashboard.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Mozilla Firefox\\\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Mozilla Firefox\\firefox.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Notepad++\\\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Notepad++\\notepad++.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\*\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Users\\Administrator\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Users\\Administrator\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\*\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\ADWS\\Microsoft.ActiveDirectory.WebServices.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\ADWS\\\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\Explorer.EXE\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\SystemApps\\Microsoft.Windows.Cortana_cw5n1h2txyewy\\SearchUI.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\SystemApps\\Microsoft.Windows.Cortana_cw5n1h2txyewy\\\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\SystemApps\\ShellExperienceHost_cw5n1h2txyewy\\ShellExperienceHost.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\SystemApps\\ShellExperienceHost_cw5n1h2txyewy\\\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\WinSxS\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.5771_none_7ee250a22208ec93\\\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\servicing\\TrustedInstaller.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\servicing\\\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\sysmon64.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\winsxs\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.5771_none_7ee250a22208ec93\\TiWorker.exe\"", process_id="0x1020", process_id="0x104c", process_id="0x10ac", process_id="0x1138", process_id="0x1160", process_id="0x1164", process_id="0x120", process_id="0x1260", process_id="0x12d0", process_id="0x1394", process_id="0x13c0", process_id="0x13dc", process_id="0x1478", process_id="0x14d0", process_id="0x1618", process_id="0x1630", process_id="0x1674", process_id="0x16d0", process_id="0x16f0", process_id="0x1780", process_id="0x17c8", process_id="0x17cc", process_id="0x1844", process_id="0x1870", process_id="0x1904", process_id="0x1924", process_id="0x198c", process_id="0x199c", process_id="0x19fc", process_id="0x1a04", process_id="0x1a28", process_id="0x1a2c", process_id="0x1a30", process_id="0x1a5c", process_id="0x1a6c", process_id="0x1a70", process_id="0x1a88", process_id="0x1b34", process_id="0x1b68", process_id="0x1be0", process_id="0x214", process_id="0x230", process_id="0x408", process_id="0x434", process_id="0x66c", process_id="0x694", process_id="0x6a8", process_id="0x8e0", process_id="0x8ec", process_id="0xb90", process_id="0xc28", process_id="0xc40", process_id="0xc98", process_id="0xd98", process_id="0xe00", process_id="0xe84", process_id="0xf28", process_name="icacls.exe", risk_message="An excessive amount of icacls.exe was executed on ar-win-dc.attackrange.local attempting to modify permissions.", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="80.0", savedsearch_description="The following analytic identifies excessive usage of `cacls.exe`, `xcacls.exe` or `icacls.exe` application to change file or folder permission. This behavior is commonly seen where the adversary attempts to impair some users from deleting or accessing its malware components or artifact from the compromised system.", user="Administrator" 1686749340, search_name="ESCU - Excessive Usage Of Cacls App - Rule", orig_time="1686749340", analyticstories="Azorult", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", analyticstories="XMRig", annotations="{\"analytic_story\":[\"XMRig\",\"Azorult\",\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":100,\"impact\":80,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1222\"],\"nist\":[\"DE.AE\"]}", annotations._all="Azorult", annotations._all="Prestige Ransomware", annotations._all="Windows Post-Exploitation", annotations._all="Exploitation", annotations._all="DE.AE", annotations._all="T1222", annotations._all="CIS 10", annotations._all="XMRig", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="XMRig", annotations.analytic_story="Azorult", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1222", annotations.nist="DE.AE", count="14", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:29:00", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749861.767759000", lastTime="2023-06-14T13:29:22", parent_process="\"cmd.exe\" /s /k pushd \"C:\\Temp\"", parent_process_name="cmd.exe", process="icacls C:\\Windows\\ADWS\\Microsoft.ActiveDirectory.WebServices.exe", process="icacls C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\SMSvcHost.exe", process="icacls C:\\Windows\\SysWow64\\perfhost.exe", process="icacls C:\\Windows\\servicing\\TrustedInstaller.exe", process="icacls C:\\Windows\\sysmon64.exe", process="icacls \"C:\\Program Files (x86)\\Mozilla Maintenance Service\\maintenanceservice.exe\"", process="icacls \"C:\\Program Files\\Amazon\\XenTools\\LiteAgent.exe\"", process="icacls \"C:\\Program Files\\Amazon\\cfn-bootstrap\\winhup.exe\"", process="icacls \"C:\\Program Files\\Aurora-Agent\\aurora-agent.exe\"", process="icacls \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\"", process="icacls \"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\SMSvcHost.exe\"", process="icacls \"C:\\Windows\\SysWow64\\perfhost.exe\"", process="icacls \"C:\\Windows\\servicing\\TrustedInstaller.exe\"", process="icacls \"C:\\Windows\\sysmon64.exe\"", process_id="1696", process_id="2468", process_id="3584", process_id="4340", process_id="4596", process_id="484", process_id="4840", process_id="4968", process_id="5008", process_id="5312", process_id="5676", process_id="5724", process_id="6912", process_id="7136", process_name="icacls.exe", risk_message="An excessive amount of icacls.exe was executed on ar-win-dc.attackrange.local attempting to modify permissions.", risk_object="icacls.exe", risk_object_type="other", risk_score="80.0", savedsearch_description="The following analytic identifies excessive usage of `cacls.exe`, `xcacls.exe` or `icacls.exe` application to change file or folder permission. This behavior is commonly seen where the adversary attempts to impair some users from deleting or accessing its malware components or artifact from the compromised system.", user="Administrator" 1686749340, search_name="ESCU - Excessive Usage Of Cacls App - Rule", orig_time="1686749340", analyticstories="Azorult", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", analyticstories="XMRig", annotations="{\"analytic_story\":[\"XMRig\",\"Azorult\",\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":100,\"impact\":80,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1222\"],\"nist\":[\"DE.AE\"]}", annotations._all="Azorult", annotations._all="Prestige Ransomware", annotations._all="Windows Post-Exploitation", annotations._all="Exploitation", annotations._all="DE.AE", annotations._all="T1222", annotations._all="CIS 10", annotations._all="XMRig", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="XMRig", annotations.analytic_story="Azorult", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1222", annotations.nist="DE.AE", count="14", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:29:00", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749861.767759000", lastTime="2023-06-14T13:29:22", parent_process="\"cmd.exe\" /s /k pushd \"C:\\Temp\"", parent_process_name="cmd.exe", process="icacls C:\\Windows\\ADWS\\Microsoft.ActiveDirectory.WebServices.exe", process="icacls C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\SMSvcHost.exe", process="icacls C:\\Windows\\SysWow64\\perfhost.exe", process="icacls C:\\Windows\\servicing\\TrustedInstaller.exe", process="icacls C:\\Windows\\sysmon64.exe", process="icacls \"C:\\Program Files (x86)\\Mozilla Maintenance Service\\maintenanceservice.exe\"", process="icacls \"C:\\Program Files\\Amazon\\XenTools\\LiteAgent.exe\"", process="icacls \"C:\\Program Files\\Amazon\\cfn-bootstrap\\winhup.exe\"", process="icacls \"C:\\Program Files\\Aurora-Agent\\aurora-agent.exe\"", process="icacls \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\"", process="icacls \"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\SMSvcHost.exe\"", process="icacls \"C:\\Windows\\SysWow64\\perfhost.exe\"", process="icacls \"C:\\Windows\\servicing\\TrustedInstaller.exe\"", process="icacls \"C:\\Windows\\sysmon64.exe\"", process_id="1696", process_id="2468", process_id="3584", process_id="4340", process_id="4596", process_id="484", process_id="4840", process_id="4968", process_id="5008", process_id="5312", process_id="5676", process_id="5724", process_id="6912", process_id="7136", process_name="icacls.exe", risk_message="An excessive amount of icacls.exe was executed on ar-win-dc.attackrange.local attempting to modify permissions.", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="80.0", savedsearch_description="The following analytic identifies excessive usage of `cacls.exe`, `xcacls.exe` or `icacls.exe` application to change file or folder permission. This behavior is commonly seen where the adversary attempts to impair some users from deleting or accessing its malware components or artifact from the compromised system.", user="Administrator" 1686749280, search_name="ESCU - Excessive Usage Of Cacls App - Rule", orig_time="1686749280", analyticstories="Azorult", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", analyticstories="XMRig", annotations="{\"analytic_story\":[\"XMRig\",\"Azorult\",\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":100,\"impact\":80,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1222\"],\"nist\":[\"DE.AE\"]}", annotations._all="Azorult", annotations._all="Prestige Ransomware", annotations._all="Windows Post-Exploitation", annotations._all="Exploitation", annotations._all="DE.AE", annotations._all="T1222", annotations._all="CIS 10", annotations._all="XMRig", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="XMRig", annotations.analytic_story="Azorult", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1222", annotations.nist="DE.AE", count="62", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:52", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749861.767759000", lastTime="2023-06-14T13:28:59", parent_process="\"cmd.exe\" /s /k pushd \"C:\\Temp\"", parent_process_name="cmd.exe", process="icacls \"C:\\Documents and Settings\\Administrator\\Start Menu\\Programs\\Startup\"", process="icacls \"C:\\Documents and Settings\\Administrator\\Start Menu\\Programs\\Startup\\*\"", process="icacls \"C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\"", process="icacls \"C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\*\"", process="icacls \"C:\\Program Files\\Amazon\\SSM\\\\\"", process="icacls \"C:\\Program Files\\Amazon\\SSM\\amazon-ssm-agent.exe\"", process="icacls \"C:\\Program Files\\Amazon\\SSM\\ssm-agent-worker.exe\"", process="icacls \"C:\\Program Files\\Aurora-Agent\\\\\"", process="icacls \"C:\\Program Files\\Aurora-Agent\\aurora-agent.exe\"", process="icacls \"C:\\Program Files\\Aurora-Agent\\tools\\\\\"", process="icacls \"C:\\Program Files\\Aurora-Agent\\tools\\aurora-dashboard.exe\"", process="icacls \"C:\\Program Files\\Mozilla Firefox\\\\\"", process="icacls \"C:\\Program Files\\Mozilla Firefox\\firefox.exe\"", process="icacls \"C:\\Program Files\\Notepad++\\\\\"", process="icacls \"C:\\Program Files\\Notepad++\\notepad++.exe\"", process="icacls \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\\\\"", process="icacls \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\"", process="icacls \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe\"", process="icacls \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\"", process="icacls \"C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\"", process="icacls \"C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\*\"", process="icacls \"C:\\Users\\Administrator\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\"", process="icacls \"C:\\Users\\Administrator\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\*\"", process="icacls \"C:\\Windows\\ADWS\\Microsoft.ActiveDirectory.WebServices.exe\"", process="icacls \"C:\\Windows\\ADWS\\\\\"", process="icacls \"C:\\Windows\\Explorer.EXE\"", process="icacls \"C:\\Windows\\SystemApps\\Microsoft.Windows.Cortana_cw5n1h2txyewy\\SearchUI.exe\"", process="icacls \"C:\\Windows\\SystemApps\\Microsoft.Windows.Cortana_cw5n1h2txyewy\\\\\"", process="icacls \"C:\\Windows\\SystemApps\\ShellExperienceHost_cw5n1h2txyewy\\ShellExperienceHost.exe\"", process="icacls \"C:\\Windows\\SystemApps\\ShellExperienceHost_cw5n1h2txyewy\\\\\"", process="icacls \"C:\\Windows\\WinSxS\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.5771_none_7ee250a22208ec93\\\\\"", process="icacls \"C:\\Windows\\\\\"", process="icacls \"C:\\Windows\\servicing\\TrustedInstaller.exe\"", process="icacls \"C:\\Windows\\servicing\\\\\"", process="icacls \"C:\\Windows\\sysmon64.exe\"", process="icacls \"C:\\Windows\\winsxs\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.5771_none_7ee250a22208ec93\\TiWorker.exe\"", process_id="1032", process_id="1076", process_id="1644", process_id="1684", process_id="1704", process_id="2272", process_id="2284", process_id="288", process_id="2960", process_id="3112", process_id="3136", process_id="3224", process_id="3480", process_id="3584", process_id="3716", process_id="3880", process_id="4128", process_id="4172", process_id="4268", process_id="4408", process_id="4448", process_id="4452", process_id="4704", process_id="4816", process_id="5012", process_id="5056", process_id="5084", process_id="5240", process_id="532", process_id="5328", process_id="560", process_id="5656", process_id="5680", process_id="5748", process_id="5840", process_id="5872", process_id="6016", process_id="6088", process_id="6092", process_id="6212", process_id="6256", process_id="6404", process_id="6436", process_id="6540", process_id="6556", process_id="6652", process_id="6660", process_id="6696", process_id="6700", process_id="6704", process_id="6748", process_id="6764", process_id="6768", process_id="6792", process_id="6964", process_id="7016", process_id="7136", process_name="icacls.exe", risk_message="An excessive amount of icacls.exe was executed on ar-win-dc.attackrange.local attempting to modify permissions.", risk_object="icacls.exe", risk_object_type="other", risk_score="80.0", savedsearch_description="The following analytic identifies excessive usage of `cacls.exe`, `xcacls.exe` or `icacls.exe` application to change file or folder permission. This behavior is commonly seen where the adversary attempts to impair some users from deleting or accessing its malware components or artifact from the compromised system.", user="Administrator" 1686749280, search_name="ESCU - Excessive Usage Of Cacls App - Rule", orig_time="1686749280", analyticstories="Azorult", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", analyticstories="XMRig", annotations="{\"analytic_story\":[\"XMRig\",\"Azorult\",\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":100,\"impact\":80,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1222\"],\"nist\":[\"DE.AE\"]}", annotations._all="Azorult", annotations._all="Prestige Ransomware", annotations._all="Windows Post-Exploitation", annotations._all="Exploitation", annotations._all="DE.AE", annotations._all="T1222", annotations._all="CIS 10", annotations._all="XMRig", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="XMRig", annotations.analytic_story="Azorult", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1222", annotations.nist="DE.AE", count="62", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:52", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749861.767759000", lastTime="2023-06-14T13:28:59", parent_process="\"cmd.exe\" /s /k pushd \"C:\\Temp\"", parent_process_name="cmd.exe", process="icacls \"C:\\Documents and Settings\\Administrator\\Start Menu\\Programs\\Startup\"", process="icacls \"C:\\Documents and Settings\\Administrator\\Start Menu\\Programs\\Startup\\*\"", process="icacls \"C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\"", process="icacls \"C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\*\"", process="icacls \"C:\\Program Files\\Amazon\\SSM\\\\\"", process="icacls \"C:\\Program Files\\Amazon\\SSM\\amazon-ssm-agent.exe\"", process="icacls \"C:\\Program Files\\Amazon\\SSM\\ssm-agent-worker.exe\"", process="icacls \"C:\\Program Files\\Aurora-Agent\\\\\"", process="icacls \"C:\\Program Files\\Aurora-Agent\\aurora-agent.exe\"", process="icacls \"C:\\Program Files\\Aurora-Agent\\tools\\\\\"", process="icacls \"C:\\Program Files\\Aurora-Agent\\tools\\aurora-dashboard.exe\"", process="icacls \"C:\\Program Files\\Mozilla Firefox\\\\\"", process="icacls \"C:\\Program Files\\Mozilla Firefox\\firefox.exe\"", process="icacls \"C:\\Program Files\\Notepad++\\\\\"", process="icacls \"C:\\Program Files\\Notepad++\\notepad++.exe\"", process="icacls \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\\\\"", process="icacls \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\"", process="icacls \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe\"", process="icacls \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\"", process="icacls \"C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\"", process="icacls \"C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\*\"", process="icacls \"C:\\Users\\Administrator\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\"", process="icacls \"C:\\Users\\Administrator\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\*\"", process="icacls \"C:\\Windows\\ADWS\\Microsoft.ActiveDirectory.WebServices.exe\"", process="icacls \"C:\\Windows\\ADWS\\\\\"", process="icacls \"C:\\Windows\\Explorer.EXE\"", process="icacls \"C:\\Windows\\SystemApps\\Microsoft.Windows.Cortana_cw5n1h2txyewy\\SearchUI.exe\"", process="icacls \"C:\\Windows\\SystemApps\\Microsoft.Windows.Cortana_cw5n1h2txyewy\\\\\"", process="icacls \"C:\\Windows\\SystemApps\\ShellExperienceHost_cw5n1h2txyewy\\ShellExperienceHost.exe\"", process="icacls \"C:\\Windows\\SystemApps\\ShellExperienceHost_cw5n1h2txyewy\\\\\"", process="icacls \"C:\\Windows\\WinSxS\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.5771_none_7ee250a22208ec93\\\\\"", process="icacls \"C:\\Windows\\\\\"", process="icacls \"C:\\Windows\\servicing\\TrustedInstaller.exe\"", process="icacls \"C:\\Windows\\servicing\\\\\"", process="icacls \"C:\\Windows\\sysmon64.exe\"", process="icacls \"C:\\Windows\\winsxs\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.5771_none_7ee250a22208ec93\\TiWorker.exe\"", process_id="1032", process_id="1076", process_id="1644", process_id="1684", process_id="1704", process_id="2272", process_id="2284", process_id="288", process_id="2960", process_id="3112", process_id="3136", process_id="3224", process_id="3480", process_id="3584", process_id="3716", process_id="3880", process_id="4128", process_id="4172", process_id="4268", process_id="4408", process_id="4448", process_id="4452", process_id="4704", process_id="4816", process_id="5012", process_id="5056", process_id="5084", process_id="5240", process_id="532", process_id="5328", process_id="560", process_id="5656", process_id="5680", process_id="5748", process_id="5840", process_id="5872", process_id="6016", process_id="6088", process_id="6092", process_id="6212", process_id="6256", process_id="6404", process_id="6436", process_id="6540", process_id="6556", process_id="6652", process_id="6660", process_id="6696", process_id="6700", process_id="6704", process_id="6748", process_id="6764", process_id="6768", process_id="6792", process_id="6964", process_id="7016", process_id="7136", process_name="icacls.exe", risk_message="An excessive amount of icacls.exe was executed on ar-win-dc.attackrange.local attempting to modify permissions.", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="80.0", savedsearch_description="The following analytic identifies excessive usage of `cacls.exe`, `xcacls.exe` or `icacls.exe` application to change file or folder permission. This behavior is commonly seen where the adversary attempts to impair some users from deleting or accessing its malware components or artifact from the compromised system.", user="Administrator" 1686749848, search_name="ESCU - Windows WMI Process And Service List - Rule", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":20,\"impact\":20,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1047\"],\"nist\":[\"DE.AE\"]}", annotations._all="Windows Post-Exploitation", annotations._all="CIS 10", annotations._all="DE.AE", annotations._all="Installation", annotations._all="T1047", annotations._all="Prestige Ransomware", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1047", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:59", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749842.404621000", lastTime="2023-06-14T13:28:59", original_file_name="wmic.exe", parent_process="cmd.exe /c wmic service list full", parent_process_guid="{953948C6-C09B-6489-C00F-00000000F902}", parent_process_name="cmd.exe", process="wmic service list full", process_guid="{953948C6-C09B-6489-C30F-00000000F902}", process_id="7148", process_name="WMIC.exe", risk_message="wmi command wmic service list full to list processes and services in ar-win-dc.attackrange.local", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="4.0", savedsearch_description="The following analytic identifies suspicious process command line, where WMI is performing an event query looking for running processes or running services. This technique is commonly found where the adversary will identify services and system information on the compromised machine. During triage, review parallel processes within the same timeframe. Review the full script block to identify other related artifacts.", user="Administrator" 1686749848, search_name="ESCU - Windows WMI Process And Service List - Rule", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":20,\"impact\":20,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1047\"],\"nist\":[\"DE.AE\"]}", annotations._all="Windows Post-Exploitation", annotations._all="CIS 10", annotations._all="DE.AE", annotations._all="Installation", annotations._all="T1047", annotations._all="Prestige Ransomware", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1047", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:52", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749842.404621000", lastTime="2023-06-14T13:28:52", original_file_name="wmic.exe", parent_process="C:\\Windows\\system32\\cmd.exe /c wmic process list full|find /i \"executablepath\"|find /i /v \"system32\"|find \":\"", parent_process_guid="{953948C6-C094-6489-D30E-00000000F902}", parent_process_name="cmd.exe", process="wmic process list full", process_guid="{953948C6-C094-6489-D40E-00000000F902}", process_id="5660", process_name="WMIC.exe", risk_message="wmi command wmic process list full to list processes and services in ar-win-dc.attackrange.local", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="4.0", savedsearch_description="The following analytic identifies suspicious process command line, where WMI is performing an event query looking for running processes or running services. This technique is commonly found where the adversary will identify services and system information on the compromised machine. During triage, review parallel processes within the same timeframe. Review the full script block to identify other related artifacts.", user="Administrator" 1686749848, search_name="ESCU - Windows WMI Process And Service List - Rule", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":20,\"impact\":20,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1047\"],\"nist\":[\"DE.AE\"]}", annotations._all="Windows Post-Exploitation", annotations._all="CIS 10", annotations._all="DE.AE", annotations._all="Installation", annotations._all="T1047", annotations._all="Prestige Ransomware", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1047", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:51", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749842.404621000", lastTime="2023-06-14T13:28:51", original_file_name="wmic.exe", parent_process="C:\\Windows\\system32\\cmd.exe /c wmic process list full|find /i \"executablepath\"|find /i /v \"system32\"|find \":\"", parent_process_guid="{953948C6-C093-6489-660E-00000000F902}", parent_process_name="cmd.exe", process="wmic process list full", process_guid="{953948C6-C093-6489-670E-00000000F902}", process_id="4028", process_name="WMIC.exe", risk_message="wmi command wmic process list full to list processes and services in ar-win-dc.attackrange.local", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="4.0", savedsearch_description="The following analytic identifies suspicious process command line, where WMI is performing an event query looking for running processes or running services. This technique is commonly found where the adversary will identify services and system information on the compromised machine. During triage, review parallel processes within the same timeframe. Review the full script block to identify other related artifacts.", user="Administrator" 1686749848, search_name="ESCU - Windows WMI Process And Service List - Rule", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":20,\"impact\":20,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1047\"],\"nist\":[\"DE.AE\"]}", annotations._all="Windows Post-Exploitation", annotations._all="CIS 10", annotations._all="DE.AE", annotations._all="Installation", annotations._all="T1047", annotations._all="Prestige Ransomware", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1047", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:59", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749842.404621000", lastTime="2023-06-14T13:28:59", original_file_name="unknown", parent_process="C:\\Windows\\System32\\cmd.exe", parent_process_guid="null", parent_process_name="cmd.exe", process="C:\\Windows\\System32\\wbem\\WMIC.exe service list full", process_guid="null", process_id="0x1bec", process_name="WMIC.exe", risk_message="wmi command C:\\Windows\\System32\\wbem\\WMIC.exe service list full to list processes and services in ar-win-dc.attackrange.local", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="4.0", savedsearch_description="The following analytic identifies suspicious process command line, where WMI is performing an event query looking for running processes or running services. This technique is commonly found where the adversary will identify services and system information on the compromised machine. During triage, review parallel processes within the same timeframe. Review the full script block to identify other related artifacts.", user="Administrator" 1686749848, search_name="ESCU - Windows WMI Process And Service List - Rule", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":20,\"impact\":20,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1047\"],\"nist\":[\"DE.AE\"]}", annotations._all="Windows Post-Exploitation", annotations._all="CIS 10", annotations._all="DE.AE", annotations._all="Installation", annotations._all="T1047", annotations._all="Prestige Ransomware", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1047", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:51", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749842.404621000", lastTime="2023-06-14T13:28:51", original_file_name="unknown", parent_process="C:\\Windows\\System32\\cmd.exe", parent_process_guid="null", parent_process_name="cmd.exe", process="C:\\Windows\\System32\\wbem\\WMIC.exe process list full", process_guid="null", process_id="0xfbc", process_name="WMIC.exe", risk_message="wmi command C:\\Windows\\System32\\wbem\\WMIC.exe process list full to list processes and services in ar-win-dc.attackrange.local", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="4.0", savedsearch_description="The following analytic identifies suspicious process command line, where WMI is performing an event query looking for running processes or running services. This technique is commonly found where the adversary will identify services and system information on the compromised machine. During triage, review parallel processes within the same timeframe. Review the full script block to identify other related artifacts.", user="Administrator" 1686749848, search_name="ESCU - Windows WMI Process And Service List - Rule", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":20,\"impact\":20,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1047\"],\"nist\":[\"DE.AE\"]}", annotations._all="Windows Post-Exploitation", annotations._all="CIS 10", annotations._all="DE.AE", annotations._all="Installation", annotations._all="T1047", annotations._all="Prestige Ransomware", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1047", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:52", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749842.404621000", lastTime="2023-06-14T13:28:52", original_file_name="unknown", parent_process="C:\\Windows\\System32\\cmd.exe", parent_process_guid="null", parent_process_name="cmd.exe", process="C:\\Windows\\System32\\wbem\\WMIC.exe process list full", process_guid="null", process_id="0x161c", process_name="WMIC.exe", risk_message="wmi command C:\\Windows\\System32\\wbem\\WMIC.exe process list full to list processes and services in ar-win-dc.attackrange.local", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="4.0", savedsearch_description="The following analytic identifies suspicious process command line, where WMI is performing an event query looking for running processes or running services. This technique is commonly found where the adversary will identify services and system information on the compromised machine. During triage, review parallel processes within the same timeframe. Review the full script block to identify other related artifacts.", user="Administrator" 1686749280, search_name="ESCU - Windows Indirect Command Execution Via Series Of Forfiles - Rule", orig_time="1686749280", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":30,\"impact\":30,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.AE\"]}", annotations._all="Windows Post-Exploitation", annotations._all="T1202", annotations._all="Prestige Ransomware", annotations._all="CIS 10", annotations._all="Exploitation", annotations._all="DE.AE", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.AE", count="39", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:50", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749817.299497000", lastTime="2023-06-14T13:28:59", parent_process="C:\\Windows\\System32\\cmd.exe", parent_process_name="cmd.exe", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m ADMINISTRATORS GROUPS\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m ARP\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m AlwaysInstallElevated?\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Audit Settings\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m CURRENT CLIPBOARD\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m CURRENT LOGGED USERS\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m CURRENT SHARES\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m CURRENT USER\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Credential Guard?\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m DATE and TIME\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m DNS CACHE\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m ENVIRONMENT\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m FIREWALL\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m GROUPS\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Hosts file\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m INSTALLED SOFTWARE\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m INTERFACES\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Kerberos Tickets\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m LAPS installed?\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m LSA protection?\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m MOUNTED DISKS\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Number of cached creds\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m PowerShell settings\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m ROUTES\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m RUN AT STARTUP\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m RUNNING PROCESSES\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Registered Anti-Virus(AV)\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Remote Desktop Credentials Manager\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m SERVICE BINARY PERMISSIONS WITH WMIC and ICACLS\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m UAC Settings\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m USED PORTS\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m USERS\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m WDigest?\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m WEF Settings\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m WIFI\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m WSUS\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO.0x1B[32m[*]0x1B[97m BASIC USER INFO\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO.0x1B[32m[*]0x1B[97m NETWORK\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO.0x1B[32m[*]0x1B[97m SERVICE VULNERABILITIES\"", process_name="forfiles.exe", risk_message="excessive forfiles process execution in ar-win-dc.attackrange.local", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="9.0", savedsearch_description="This analytic is developed to detect suspicious excessive usage of forfiles.exe process. This event was seen in post exploitation tool WINPEAS that was used by Ransomware Prestige. Forfiles command lets you run a command on or pass arguments to multiple files. This Windows OS built-in tool being abused to list all files in specific directory or drive.", user="Administrator" 1686749791, search_name="ESCU - Windows Credentials in Registry Reg Query - Rule", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1552.002\",\"T1552\"],\"nist\":[\"DE.AE\"]}", annotations._all="Prestige Ransomware", annotations._all="T1552", annotations._all="DE.AE", annotations._all="CIS 10", annotations._all="Exploitation", annotations._all="T1552.002", annotations._all="Windows Post-Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1552.002", annotations.mitre_attack="T1552", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:29:26", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749784.537440000", lastTime="2023-06-14T13:29:26", original_file_name="unknown", parent_process="C:\\Windows\\System32\\cmd.exe", parent_process_guid="null", parent_process_name="cmd.exe", process="C:\\Windows\\System32\\reg.exe query HKLM\\SYSTEM\\CurrentControlSet\\Services\\SNMP /s", process_guid="null", process_id="0x290", process_name="reg.exe", risk_message="reg query commandline C:\\Windows\\System32\\reg.exe query HKLM\\SYSTEM\\CurrentControlSet\\Services\\SNMP /s in ar-win-dc.attackrange.local", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="25.0", savedsearch_description="The following analytic identifies a process command line related to the discovery of possible password or credentials in the registry. This technique is being abused by adversaries or post exploitation tools like winpeas to steal credentials in the registry in the targeted host. Registry can contain several sensitive information like username and credentials that can be used for privilege escalation, persistence or even in lateral movement. This Anomaly detection can be a good pivot to detect a suspicious process querying a registry related to password or private keys.", user="Administrator" 1686749791, search_name="ESCU - Windows Credentials in Registry Reg Query - Rule", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1552.002\",\"T1552\"],\"nist\":[\"DE.AE\"]}", annotations._all="Prestige Ransomware", annotations._all="T1552", annotations._all="DE.AE", annotations._all="CIS 10", annotations._all="Exploitation", annotations._all="T1552.002", annotations._all="Windows Post-Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1552.002", annotations.mitre_attack="T1552", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:29:26", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749784.537440000", lastTime="2023-06-14T13:29:26", original_file_name="unknown", parent_process="C:\\Windows\\System32\\cmd.exe", parent_process_guid="null", parent_process_name="cmd.exe", process="C:\\Windows\\System32\\reg.exe query HKEY_LOCAL_MACHINE\\SOFTWARE\\RealVNC\\WinVNC4 /v password", process_guid="null", process_id="0x14c0", process_name="reg.exe", risk_message="reg query commandline C:\\Windows\\System32\\reg.exe query HKEY_LOCAL_MACHINE\\SOFTWARE\\RealVNC\\WinVNC4 /v password in ar-win-dc.attackrange.local", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="25.0", savedsearch_description="The following analytic identifies a process command line related to the discovery of possible password or credentials in the registry. This technique is being abused by adversaries or post exploitation tools like winpeas to steal credentials in the registry in the targeted host. Registry can contain several sensitive information like username and credentials that can be used for privilege escalation, persistence or even in lateral movement. This Anomaly detection can be a good pivot to detect a suspicious process querying a registry related to password or private keys.", user="Administrator" 1686749791, search_name="ESCU - Windows Credentials in Registry Reg Query - Rule", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1552.002\",\"T1552\"],\"nist\":[\"DE.AE\"]}", annotations._all="Prestige Ransomware", annotations._all="T1552", annotations._all="DE.AE", annotations._all="CIS 10", annotations._all="Exploitation", annotations._all="T1552.002", annotations._all="Windows Post-Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1552.002", annotations.mitre_attack="T1552", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:29:26", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749784.537440000", lastTime="2023-06-14T13:29:26", original_file_name="unknown", parent_process="C:\\Windows\\System32\\cmd.exe", parent_process_guid="null", parent_process_name="cmd.exe", process="C:\\Windows\\System32\\reg.exe query HKCU\\Software\\TightVNC\\Server", process_guid="null", process_id="0x1248", process_name="reg.exe", risk_message="reg query commandline C:\\Windows\\System32\\reg.exe query HKCU\\Software\\TightVNC\\Server in ar-win-dc.attackrange.local", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="25.0", savedsearch_description="The following analytic identifies a process command line related to the discovery of possible password or credentials in the registry. This technique is being abused by adversaries or post exploitation tools like winpeas to steal credentials in the registry in the targeted host. Registry can contain several sensitive information like username and credentials that can be used for privilege escalation, persistence or even in lateral movement. This Anomaly detection can be a good pivot to detect a suspicious process querying a registry related to password or private keys.", user="Administrator" 1686749791, search_name="ESCU - Windows Credentials in Registry Reg Query - Rule", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1552.002\",\"T1552\"],\"nist\":[\"DE.AE\"]}", annotations._all="Prestige Ransomware", annotations._all="T1552", annotations._all="DE.AE", annotations._all="CIS 10", annotations._all="Exploitation", annotations._all="T1552.002", annotations._all="Windows Post-Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1552.002", annotations.mitre_attack="T1552", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:29:26", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749784.537440000", lastTime="2023-06-14T13:29:26", original_file_name="unknown", parent_process="C:\\Windows\\System32\\cmd.exe", parent_process_guid="null", parent_process_name="cmd.exe", process="C:\\Windows\\System32\\reg.exe query HKCU\\Software\\SimonTatham\\PuTTY\\Sessions /s", process_guid="null", process_id="0x6fc", process_name="reg.exe", risk_message="reg query commandline C:\\Windows\\System32\\reg.exe query HKCU\\Software\\SimonTatham\\PuTTY\\Sessions /s in ar-win-dc.attackrange.local", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="25.0", savedsearch_description="The following analytic identifies a process command line related to the discovery of possible password or credentials in the registry. This technique is being abused by adversaries or post exploitation tools like winpeas to steal credentials in the registry in the targeted host. Registry can contain several sensitive information like username and credentials that can be used for privilege escalation, persistence or even in lateral movement. This Anomaly detection can be a good pivot to detect a suspicious process querying a registry related to password or private keys.", user="Administrator" 1686749791, search_name="ESCU - Windows Credentials in Registry Reg Query - Rule", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1552.002\",\"T1552\"],\"nist\":[\"DE.AE\"]}", annotations._all="Prestige Ransomware", annotations._all="T1552", annotations._all="DE.AE", annotations._all="CIS 10", annotations._all="Exploitation", annotations._all="T1552.002", annotations._all="Windows Post-Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1552.002", annotations.mitre_attack="T1552", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:29:26", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749784.537440000", lastTime="2023-06-14T13:29:26", original_file_name="unknown", parent_process="C:\\Windows\\System32\\cmd.exe", parent_process_guid="null", parent_process_name="cmd.exe", process="C:\\Windows\\System32\\reg.exe query HKCU\\Software\\OpenSSH\\Agent\\Keys /s", process_guid="null", process_id="0xb0c", process_name="reg.exe", risk_message="reg query commandline C:\\Windows\\System32\\reg.exe query HKCU\\Software\\OpenSSH\\Agent\\Keys /s in ar-win-dc.attackrange.local", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="25.0", savedsearch_description="The following analytic identifies a process command line related to the discovery of possible password or credentials in the registry. This technique is being abused by adversaries or post exploitation tools like winpeas to steal credentials in the registry in the targeted host. Registry can contain several sensitive information like username and credentials that can be used for privilege escalation, persistence or even in lateral movement. This Anomaly detection can be a good pivot to detect a suspicious process querying a registry related to password or private keys.", user="Administrator" 1686749791, search_name="ESCU - Windows Credentials in Registry Reg Query - Rule", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1552.002\",\"T1552\"],\"nist\":[\"DE.AE\"]}", annotations._all="Prestige Ransomware", annotations._all="T1552", annotations._all="DE.AE", annotations._all="CIS 10", annotations._all="Exploitation", annotations._all="T1552.002", annotations._all="Windows Post-Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1552.002", annotations.mitre_attack="T1552", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:29:26", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749784.537440000", lastTime="2023-06-14T13:29:26", original_file_name="unknown", parent_process="C:\\Windows\\System32\\cmd.exe", parent_process_guid="null", parent_process_name="cmd.exe", process="C:\\Windows\\System32\\reg.exe query HKCU\\Software\\ORL\\WinVNC3\\Password", process_guid="null", process_id="0x938", process_name="reg.exe", risk_message="reg query commandline C:\\Windows\\System32\\reg.exe query HKCU\\Software\\ORL\\WinVNC3\\Password in ar-win-dc.attackrange.local", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="25.0", savedsearch_description="The following analytic identifies a process command line related to the discovery of possible password or credentials in the registry. This technique is being abused by adversaries or post exploitation tools like winpeas to steal credentials in the registry in the targeted host. Registry can contain several sensitive information like username and credentials that can be used for privilege escalation, persistence or even in lateral movement. This Anomaly detection can be a good pivot to detect a suspicious process querying a registry related to password or private keys.", user="Administrator" 1686749791, search_name="ESCU - Windows Credentials in Registry Reg Query - Rule", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1552.002\",\"T1552\"],\"nist\":[\"DE.AE\"]}", annotations._all="Prestige Ransomware", annotations._all="T1552", annotations._all="DE.AE", annotations._all="CIS 10", annotations._all="Exploitation", annotations._all="T1552.002", annotations._all="Windows Post-Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1552.002", annotations.mitre_attack="T1552", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:29:26", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749784.537440000", lastTime="2023-06-14T13:29:26", original_file_name="reg.exe", parent_process="\"cmd.exe\" /s /k pushd \"C:\\Temp\"", parent_process_guid="{953948C6-BA8E-6489-C200-00000000F902}", parent_process_name="cmd.exe", process="reg query HKLM\\SYSTEM\\CurrentControlSet\\Services\\SNMP /s", process_guid="{953948C6-C0B6-6489-C718-00000000F902}", process_id="656", process_name="reg.exe", risk_message="reg query commandline reg query HKLM\\SYSTEM\\CurrentControlSet\\Services\\SNMP /s in ar-win-dc.attackrange.local", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="25.0", savedsearch_description="The following analytic identifies a process command line related to the discovery of possible password or credentials in the registry. This technique is being abused by adversaries or post exploitation tools like winpeas to steal credentials in the registry in the targeted host. Registry can contain several sensitive information like username and credentials that can be used for privilege escalation, persistence or even in lateral movement. This Anomaly detection can be a good pivot to detect a suspicious process querying a registry related to password or private keys.", user="Administrator" 1686749791, search_name="ESCU - Windows Credentials in Registry Reg Query - Rule", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1552.002\",\"T1552\"],\"nist\":[\"DE.AE\"]}", annotations._all="Prestige Ransomware", annotations._all="T1552", annotations._all="DE.AE", annotations._all="CIS 10", annotations._all="Exploitation", annotations._all="T1552.002", annotations._all="Windows Post-Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1552.002", annotations.mitre_attack="T1552", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:29:26", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749784.537440000", lastTime="2023-06-14T13:29:26", original_file_name="reg.exe", parent_process="\"cmd.exe\" /s /k pushd \"C:\\Temp\"", parent_process_guid="{953948C6-BA8E-6489-C200-00000000F902}", parent_process_name="cmd.exe", process="reg query HKEY_LOCAL_MACHINE\\SOFTWARE\\RealVNC\\WinVNC4 /v password", process_guid="{953948C6-C0B6-6489-C418-00000000F902}", process_id="5312", process_name="reg.exe", risk_message="reg query commandline reg query HKEY_LOCAL_MACHINE\\SOFTWARE\\RealVNC\\WinVNC4 /v password in ar-win-dc.attackrange.local", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="25.0", savedsearch_description="The following analytic identifies a process command line related to the discovery of possible password or credentials in the registry. This technique is being abused by adversaries or post exploitation tools like winpeas to steal credentials in the registry in the targeted host. Registry can contain several sensitive information like username and credentials that can be used for privilege escalation, persistence or even in lateral movement. This Anomaly detection can be a good pivot to detect a suspicious process querying a registry related to password or private keys.", user="Administrator" 1686749791, search_name="ESCU - Windows Credentials in Registry Reg Query - Rule", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1552.002\",\"T1552\"],\"nist\":[\"DE.AE\"]}", annotations._all="Prestige Ransomware", annotations._all="T1552", annotations._all="DE.AE", annotations._all="CIS 10", annotations._all="Exploitation", annotations._all="T1552.002", annotations._all="Windows Post-Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1552.002", annotations.mitre_attack="T1552", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:29:26", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749784.537440000", lastTime="2023-06-14T13:29:26", original_file_name="reg.exe", parent_process="\"cmd.exe\" /s /k pushd \"C:\\Temp\"", parent_process_guid="{953948C6-BA8E-6489-C200-00000000F902}", parent_process_name="cmd.exe", process="reg query HKCU\\Software\\TightVNC\\Server", process_guid="{953948C6-C0B6-6489-C818-00000000F902}", process_id="4680", process_name="reg.exe", risk_message="reg query commandline reg query HKCU\\Software\\TightVNC\\Server in ar-win-dc.attackrange.local", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="25.0", savedsearch_description="The following analytic identifies a process command line related to the discovery of possible password or credentials in the registry. This technique is being abused by adversaries or post exploitation tools like winpeas to steal credentials in the registry in the targeted host. Registry can contain several sensitive information like username and credentials that can be used for privilege escalation, persistence or even in lateral movement. This Anomaly detection can be a good pivot to detect a suspicious process querying a registry related to password or private keys.", user="Administrator" 1686749791, search_name="ESCU - Windows Credentials in Registry Reg Query - Rule", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1552.002\",\"T1552\"],\"nist\":[\"DE.AE\"]}", annotations._all="Prestige Ransomware", annotations._all="T1552", annotations._all="DE.AE", annotations._all="CIS 10", annotations._all="Exploitation", annotations._all="T1552.002", annotations._all="Windows Post-Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1552.002", annotations.mitre_attack="T1552", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:29:26", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749784.537440000", lastTime="2023-06-14T13:29:26", original_file_name="reg.exe", parent_process="\"cmd.exe\" /s /k pushd \"C:\\Temp\"", parent_process_guid="{953948C6-BA8E-6489-C200-00000000F902}", parent_process_name="cmd.exe", process="reg query HKCU\\Software\\SimonTatham\\PuTTY\\Sessions /s", process_guid="{953948C6-C0B6-6489-C918-00000000F902}", process_id="1788", process_name="reg.exe", risk_message="reg query commandline reg query HKCU\\Software\\SimonTatham\\PuTTY\\Sessions /s in ar-win-dc.attackrange.local", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="25.0", savedsearch_description="The following analytic identifies a process command line related to the discovery of possible password or credentials in the registry. This technique is being abused by adversaries or post exploitation tools like winpeas to steal credentials in the registry in the targeted host. Registry can contain several sensitive information like username and credentials that can be used for privilege escalation, persistence or even in lateral movement. This Anomaly detection can be a good pivot to detect a suspicious process querying a registry related to password or private keys.", user="Administrator" 1686749791, search_name="ESCU - Windows Credentials in Registry Reg Query - Rule", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1552.002\",\"T1552\"],\"nist\":[\"DE.AE\"]}", annotations._all="Prestige Ransomware", annotations._all="T1552", annotations._all="DE.AE", annotations._all="CIS 10", annotations._all="Exploitation", annotations._all="T1552.002", annotations._all="Windows Post-Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1552.002", annotations.mitre_attack="T1552", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:29:26", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749784.537440000", lastTime="2023-06-14T13:29:26", original_file_name="reg.exe", parent_process="\"cmd.exe\" /s /k pushd \"C:\\Temp\"", parent_process_guid="{953948C6-BA8E-6489-C200-00000000F902}", parent_process_name="cmd.exe", process="reg query HKCU\\Software\\OpenSSH\\Agent\\Keys /s", process_guid="{953948C6-C0B6-6489-CA18-00000000F902}", process_id="2828", process_name="reg.exe", risk_message="reg query commandline reg query HKCU\\Software\\OpenSSH\\Agent\\Keys /s in ar-win-dc.attackrange.local", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="25.0", savedsearch_description="The following analytic identifies a process command line related to the discovery of possible password or credentials in the registry. This technique is being abused by adversaries or post exploitation tools like winpeas to steal credentials in the registry in the targeted host. Registry can contain several sensitive information like username and credentials that can be used for privilege escalation, persistence or even in lateral movement. This Anomaly detection can be a good pivot to detect a suspicious process querying a registry related to password or private keys.", user="Administrator" 1686749791, search_name="ESCU - Windows Credentials in Registry Reg Query - Rule", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1552.002\",\"T1552\"],\"nist\":[\"DE.AE\"]}", annotations._all="Prestige Ransomware", annotations._all="T1552", annotations._all="DE.AE", annotations._all="CIS 10", annotations._all="Exploitation", annotations._all="T1552.002", annotations._all="Windows Post-Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1552.002", annotations.mitre_attack="T1552", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:29:26", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749784.537440000", lastTime="2023-06-14T13:29:26", original_file_name="reg.exe", parent_process="\"cmd.exe\" /s /k pushd \"C:\\Temp\"", parent_process_guid="{953948C6-BA8E-6489-C200-00000000F902}", parent_process_name="cmd.exe", process="reg query HKCU\\Software\\ORL\\WinVNC3\\Password", process_guid="{953948C6-C0B6-6489-C318-00000000F902}", process_id="2360", process_name="reg.exe", risk_message="reg query commandline reg query HKCU\\Software\\ORL\\WinVNC3\\Password in ar-win-dc.attackrange.local", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="25.0", savedsearch_description="The following analytic identifies a process command line related to the discovery of possible password or credentials in the registry. This technique is being abused by adversaries or post exploitation tools like winpeas to steal credentials in the registry in the targeted host. Registry can contain several sensitive information like username and credentials that can be used for privilege escalation, persistence or even in lateral movement. This Anomaly detection can be a good pivot to detect a suspicious process querying a registry related to password or private keys.", user="Administrator" 1686749769, search_name="ESCU - Windows Credentials from Password Stores Query - Rule", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1555\"],\"nist\":[\"DE.AE\"]}", annotations._all="CIS 10", annotations._all="DE.AE", annotations._all="T1555", annotations._all="Windows Post-Exploitation", annotations._all="Exploitation", annotations._all="Prestige Ransomware", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1555", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:29:23", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749764.165886000", lastTime="2023-06-14T13:29:23", original_file_name="unknown", parent_process="C:\\Windows\\System32\\cmd.exe", parent_process_guid="null", parent_process_name="cmd.exe", process="C:\\Windows\\System32\\cmdkey.exe /list", process_guid="null", process_id="0x88c", process_name="cmdkey.exe", risk_message="a process cmdkey.exe was executed in ar-win-dc.attackrange.local to display stored username and credentials.", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="25.0", savedsearch_description="The following analytic identifies a process execution of Windows OS cmdkey.exe tool. This tool is being abused or used by several post exploitation tool such as winpeas that being used by ransomware prestige to list stored user names, passwords or credentials in the targeted Windows OS host. This information can be used by the attacker to gain privilege escalation and persistence in the targeted hosts for further attacks.", user="Administrator" 1686749769, search_name="ESCU - Windows Credentials from Password Stores Query - Rule", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1555\"],\"nist\":[\"DE.AE\"]}", annotations._all="CIS 10", annotations._all="DE.AE", annotations._all="T1555", annotations._all="Windows Post-Exploitation", annotations._all="Exploitation", annotations._all="Prestige Ransomware", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1555", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:29:23", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749764.165886000", lastTime="2023-06-14T13:29:23", original_file_name="cmdkey.exe", parent_process="\"cmd.exe\" /s /k pushd \"C:\\Temp\"", parent_process_guid="{953948C6-BA8E-6489-C200-00000000F902}", parent_process_name="cmd.exe", process="cmdkey /list", process_guid="{953948C6-C0B3-6489-A518-00000000F902}", process_id="2188", process_name="cmdkey.exe", risk_message="a process cmdkey.exe was executed in ar-win-dc.attackrange.local to display stored username and credentials.", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="25.0", savedsearch_description="The following analytic identifies a process execution of Windows OS cmdkey.exe tool. This tool is being abused or used by several post exploitation tool such as winpeas that being used by ransomware prestige to list stored user names, passwords or credentials in the targeted Windows OS host. This information can be used by the attacker to gain privilege escalation and persistence in the targeted hosts for further attacks.", user="Administrator" 1686749757, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="CIS 10", annotations._all="Living Off The Land", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:59", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749752.171565000", lastTime="2023-06-14T13:28:59", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO.0x1B[32m[*]0x1B[97m SERVICE VULNERABILITIES\"", parent_process_id="6432", parent_process_name="forfiles.exe", process="/C ECHO.\\x1B[32m[*]\\x1B[97m SERVICE VULNERABILITIES", process_id="5860", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749757, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="CIS 10", annotations._all="Living Off The Land", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:54", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749752.171565000", lastTime="2023-06-14T13:28:54", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO.0x1B[32m[*]0x1B[97m NETWORK\"", parent_process_id="1944", parent_process_name="forfiles.exe", process="/C ECHO.\\x1B[32m[*]\\x1B[97m NETWORK", process_id="5924", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749757, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="CIS 10", annotations._all="Living Off The Land", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:29:23", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749752.171565000", lastTime="2023-06-14T13:29:23", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO.0x1B[32m[*]0x1B[97m DLL HIJACKING in PATHenv variable\"", parent_process_id="1932", parent_process_name="forfiles.exe", process="/C ECHO.\\x1B[32m[*]\\x1B[97m DLL HIJACKING in PATHenv variable", process_id="6908", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749757, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="CIS 10", annotations._all="Living Off The Land", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:29:23", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749752.171565000", lastTime="2023-06-14T13:29:23", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO.0x1B[32m[*]0x1B[97m CREDENTIALS\"", parent_process_id="1764", parent_process_name="forfiles.exe", process="/C ECHO.\\x1B[32m[*]\\x1B[97m CREDENTIALS", process_id="912", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749757, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="CIS 10", annotations._all="Living Off The Land", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:56", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749752.171565000", lastTime="2023-06-14T13:28:56", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO.0x1B[32m[*]0x1B[97m BASIC USER INFO\"", parent_process_id="5640", parent_process_name="forfiles.exe", process="/C ECHO.\\x1B[32m[*]\\x1B[97m BASIC USER INFO", process_id="7164", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749757, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="CIS 10", annotations._all="Living Off The Land", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:51", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749752.171565000", lastTime="2023-06-14T13:28:51", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m WSUS\"", parent_process_id="4572", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m WSUS", process_id="6456", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749757, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="CIS 10", annotations._all="Living Off The Land", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:29:23", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749752.171565000", lastTime="2023-06-14T13:29:23", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m WINDOWS VAULT\"", parent_process_id="4816", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m WINDOWS VAULT", process_id="3796", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749757, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="CIS 10", annotations._all="Living Off The Land", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:56", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749752.171565000", lastTime="2023-06-14T13:28:56", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m WIFI\"", parent_process_id="6436", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m WIFI", process_id="5996", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749757, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="CIS 10", annotations._all="Living Off The Land", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:50", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749752.171565000", lastTime="2023-06-14T13:28:50", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m WEF Settings\"", parent_process_id="3784", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m WEF Settings", process_id="6208", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749757, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="CIS 10", annotations._all="Living Off The Land", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:50", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749752.171565000", lastTime="2023-06-14T13:28:50", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m WDigest?\"", parent_process_id="4736", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m WDigest?", process_id="4444", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749757, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="CIS 10", annotations._all="Living Off The Land", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:29:24", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749752.171565000", lastTime="2023-06-14T13:29:24", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Unattended files\"", parent_process_id="5996", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m Unattended files", process_id="6228", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749757, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="CIS 10", annotations._all="Living Off The Land", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:56", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749752.171565000", lastTime="2023-06-14T13:28:56", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m USERS\"", parent_process_id="6440", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m USERS", process_id="4112", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749757, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="CIS 10", annotations._all="Living Off The Land", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:55", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749752.171565000", lastTime="2023-06-14T13:28:55", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m USED PORTS\"", parent_process_id="3796", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m USED PORTS", process_id="2336", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749757, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="CIS 10", annotations._all="Living Off The Land", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:29:17", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749752.171565000", lastTime="2023-06-14T13:29:17", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m UNQUOTED SERVICE PATHS\"", parent_process_id="2108", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m UNQUOTED SERVICE PATHS", process_id="6908", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749757, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="CIS 10", annotations._all="Living Off The Land", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:50", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749752.171565000", lastTime="2023-06-14T13:28:50", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m UAC Settings\"", parent_process_id="4880", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m UAC Settings", process_id="5724", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749757, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="CIS 10", annotations._all="Living Off The Land", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:59", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749752.171565000", lastTime="2023-06-14T13:28:59", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m SERVICE BINARY PERMISSIONS WITH WMIC and ICACLS\"", parent_process_id="968", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m SERVICE BINARY PERMISSIONS WITH WMIC and ICACLS", process_id="4272", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749757, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="CIS 10", annotations._all="Living Off The Land", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:29:24", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749752.171565000", lastTime="2023-06-14T13:29:24", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m SAM and SYSTEM backups\"", parent_process_id="2804", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m SAM and SYSTEM backups", process_id="1096", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749757, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="CIS 10", annotations._all="Living Off The Land", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:51", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749752.171565000", lastTime="2023-06-14T13:28:51", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Remote Desktop Credentials Manager\"", parent_process_id="5544", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m Remote Desktop Credentials Manager", process_id="6708", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749757, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="CIS 10", annotations._all="Living Off The Land", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:50", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749752.171565000", lastTime="2023-06-14T13:28:50", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Registered Anti-Virus(AV)\"", parent_process_id="5676", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m Registered Anti-Virus(AV)", process_id="6372", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749757, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="CIS 10", annotations._all="Living Off The Land", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:51", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749752.171565000", lastTime="2023-06-14T13:28:51", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m RUNNING PROCESSES\"", parent_process_id="4280", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m RUNNING PROCESSES", process_id="6740", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749757, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="CIS 10", annotations._all="Living Off The Land", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:54", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749752.171565000", lastTime="2023-06-14T13:28:54", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m RUN AT STARTUP\"", parent_process_id="1892", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m RUN AT STARTUP", process_id="4192", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749757, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="CIS 10", annotations._all="Living Off The Land", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:55", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749752.171565000", lastTime="2023-06-14T13:28:55", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m ROUTES\"", parent_process_id="5012", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m ROUTES", process_id="4176", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749757, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="CIS 10", annotations._all="Living Off The Land", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:50", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749752.171565000", lastTime="2023-06-14T13:28:50", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m PowerShell settings\"", parent_process_id="3540", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m PowerShell settings", process_id="6228", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749757, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="CIS 10", annotations._all="Living Off The Land", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:50", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749752.171565000", lastTime="2023-06-14T13:28:50", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Number of cached creds\"", parent_process_id="4400", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m Number of cached creds", process_id="6348", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749757, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="CIS 10", annotations._all="Living Off The Land", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:29:24", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749752.171565000", lastTime="2023-06-14T13:29:24", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m McAffee SiteList.xml\"", parent_process_id="4652", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m McAffee SiteList.xml", process_id="1620", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749757, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="CIS 10", annotations._all="Living Off The Land", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:50", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749752.171565000", lastTime="2023-06-14T13:28:50", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m MOUNTED DISKS\"", parent_process_id="3244", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m MOUNTED DISKS", process_id="5640", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749757, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="CIS 10", annotations._all="Living Off The Land", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:50", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749752.171565000", lastTime="2023-06-14T13:28:50", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m LSA protection?\"", parent_process_id="1268", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m LSA protection?", process_id="4036", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749757, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="CIS 10", annotations._all="Living Off The Land", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:50", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749752.171565000", lastTime="2023-06-14T13:28:50", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m LAPS installed?\"", parent_process_id="6012", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m LAPS installed?", process_id="6756", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749757, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="CIS 10", annotations._all="Living Off The Land", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:58", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749752.171565000", lastTime="2023-06-14T13:28:58", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Kerberos Tickets\"", parent_process_id="3440", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m Kerberos Tickets", process_id="4028", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749757, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="CIS 10", annotations._all="Living Off The Land", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:54", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749752.171565000", lastTime="2023-06-14T13:28:54", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m INTERFACES\"", parent_process_id="2144", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m INTERFACES", process_id="4016", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749757, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="CIS 10", annotations._all="Living Off The Land", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:51", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749752.171565000", lastTime="2023-06-14T13:28:51", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m INSTALLED SOFTWARE\"", parent_process_id="5312", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m INSTALLED SOFTWARE", process_id="6852", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749757, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="CIS 10", annotations._all="Living Off The Land", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:56", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749752.171565000", lastTime="2023-06-14T13:28:56", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Hosts file\"", parent_process_id="6356", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m Hosts file", process_id="6448", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749757, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="CIS 10", annotations._all="Living Off The Land", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:58", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749752.171565000", lastTime="2023-06-14T13:28:58", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m GROUPS\"", parent_process_id="6708", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m GROUPS", process_id="5544", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749757, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="CIS 10", annotations._all="Living Off The Land", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:29:25", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749752.171565000", lastTime="2023-06-14T13:29:25", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m GPP Password\"", parent_process_id="6768", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m GPP Password", process_id="1820", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749757, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="CIS 10", annotations._all="Living Off The Land", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:29:26", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749752.171565000", lastTime="2023-06-14T13:29:26", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Files in registry that may contain credentials\"", parent_process_id="464", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m Files in registry that may contain credentials", process_id="6340", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749757, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="CIS 10", annotations._all="Living Off The Land", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:55", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749752.171565000", lastTime="2023-06-14T13:28:55", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m FIREWALL\"", parent_process_id="4268", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m FIREWALL", process_id="2188", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749757, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="CIS 10", annotations._all="Living Off The Land", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:51", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749752.171565000", lastTime="2023-06-14T13:28:51", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m ENVIRONMENT\"", parent_process_id="2368", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m ENVIRONMENT", process_id="2252", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749757, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="CIS 10", annotations._all="Living Off The Land", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:29:24", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749752.171565000", lastTime="2023-06-14T13:29:24", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m DPAPI MASTER KEYS\"", parent_process_id="4408", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m DPAPI MASTER KEYS", process_id="4168", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749757, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="CIS 10", annotations._all="Living Off The Land", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:29:23", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749752.171565000", lastTime="2023-06-14T13:29:23", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m DPAPI MASTER KEYS\"", parent_process_id="396", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m DPAPI MASTER KEYS", process_id="4104", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749757, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="CIS 10", annotations._all="Living Off The Land", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:56", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749752.171565000", lastTime="2023-06-14T13:28:56", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m DNS CACHE\"", parent_process_id="5728", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m DNS CACHE", process_id="2812", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749757, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="CIS 10", annotations._all="Living Off The Land", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:50", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749752.171565000", lastTime="2023-06-14T13:28:50", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m DATE and TIME\"", parent_process_id="4272", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m DATE and TIME", process_id="5680", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749757, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="CIS 10", annotations._all="Living Off The Land", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:50", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749752.171565000", lastTime="2023-06-14T13:28:50", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Credential Guard?\"", parent_process_id="1260", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m Credential Guard?", process_id="1604", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749757, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="CIS 10", annotations._all="Living Off The Land", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:29:26", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749752.171565000", lastTime="2023-06-14T13:29:26", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Cloud Credentials\"", parent_process_id="2368", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m Cloud Credentials", process_id="6400", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749757, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="CIS 10", annotations._all="Living Off The Land", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:56", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749752.171565000", lastTime="2023-06-14T13:28:56", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m CURRENT USER\"", parent_process_id="6340", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m CURRENT USER", process_id="7140", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749757, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="CIS 10", annotations._all="Living Off The Land", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:54", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749752.171565000", lastTime="2023-06-14T13:28:54", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m CURRENT SHARES\"", parent_process_id="1132", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m CURRENT SHARES", process_id="5648", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749757, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="CIS 10", annotations._all="Living Off The Land", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:58", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749752.171565000", lastTime="2023-06-14T13:28:58", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m CURRENT LOGGED USERS\"", parent_process_id="4956", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m CURRENT LOGGED USERS", process_id="4280", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749757, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="CIS 10", annotations._all="Living Off The Land", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:59", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749752.171565000", lastTime="2023-06-14T13:28:59", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m CURRENT CLIPBOARD\"", parent_process_id="3016", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m CURRENT CLIPBOARD", process_id="1688", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749757, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="CIS 10", annotations._all="Living Off The Land", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:29:00", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749752.171565000", lastTime="2023-06-14T13:29:00", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m CHECK IF YOU CAN MODIFY ANY SERVICE REGISTRY\"", parent_process_id="5728", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m CHECK IF YOU CAN MODIFY ANY SERVICE REGISTRY", process_id="6792", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749757, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="CIS 10", annotations._all="Living Off The Land", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:50", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749752.171565000", lastTime="2023-06-14T13:28:50", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Audit Settings\"", parent_process_id="6136", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m Audit Settings", process_id="6380", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749757, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="CIS 10", annotations._all="Living Off The Land", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:29:26", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749752.171565000", lastTime="2023-06-14T13:29:26", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m AppCmd\"", parent_process_id="5688", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m AppCmd", process_id="4704", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749757, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="CIS 10", annotations._all="Living Off The Land", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:54", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749752.171565000", lastTime="2023-06-14T13:28:54", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m AlwaysInstallElevated?\"", parent_process_id="7156", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m AlwaysInstallElevated?", process_id="1920", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749757, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="CIS 10", annotations._all="Living Off The Land", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:55", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749752.171565000", lastTime="2023-06-14T13:28:55", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m ARP\"", parent_process_id="4840", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m ARP", process_id="5824", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749757, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="CIS 10", annotations._all="Living Off The Land", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:58", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749752.171565000", lastTime="2023-06-14T13:28:58", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m ADMINISTRATORS GROUPS\"", parent_process_id="1804", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m ADMINISTRATORS GROUPS", process_id="4116", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749757, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="CIS 10", annotations._all="Living Off The Land", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:59", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749752.171565000", lastTime="2023-06-14T13:28:59", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO.0x1B[32m[*]0x1B[97m SERVICE VULNERABILITIES\"", parent_process_id="6572", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO.0x1B[32m[*]0x1B[97m SERVICE VULNERABILITIES\"", process_id="6432", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749757, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="CIS 10", annotations._all="Living Off The Land", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:54", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749752.171565000", lastTime="2023-06-14T13:28:54", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO.0x1B[32m[*]0x1B[97m NETWORK\"", parent_process_id="1428", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO.0x1B[32m[*]0x1B[97m NETWORK\"", process_id="1944", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749757, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="CIS 10", annotations._all="Living Off The Land", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:29:23", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749752.171565000", lastTime="2023-06-14T13:29:23", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO.0x1B[32m[*]0x1B[97m DLL HIJACKING in PATHenv variable\"", parent_process_id="6948", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO.0x1B[32m[*]0x1B[97m DLL HIJACKING in PATHenv variable\"", process_id="1932", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749757, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="CIS 10", annotations._all="Living Off The Land", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:29:23", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749752.171565000", lastTime="2023-06-14T13:29:23", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO.0x1B[32m[*]0x1B[97m CREDENTIALS\"", parent_process_id="4804", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO.0x1B[32m[*]0x1B[97m CREDENTIALS\"", process_id="1764", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749757, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="CIS 10", annotations._all="Living Off The Land", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:56", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749752.171565000", lastTime="2023-06-14T13:28:56", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO.0x1B[32m[*]0x1B[97m BASIC USER INFO\"", parent_process_id="5964", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO.0x1B[32m[*]0x1B[97m BASIC USER INFO\"", process_id="5640", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749757, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="CIS 10", annotations._all="Living Off The Land", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:51", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749752.171565000", lastTime="2023-06-14T13:28:51", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m WSUS\"", parent_process_id="1168", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m WSUS\"", process_id="4572", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749757, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="CIS 10", annotations._all="Living Off The Land", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:29:23", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749752.171565000", lastTime="2023-06-14T13:29:23", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m WINDOWS VAULT\"", parent_process_id="2960", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m WINDOWS VAULT\"", process_id="4816", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749757, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="CIS 10", annotations._all="Living Off The Land", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:56", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749752.171565000", lastTime="2023-06-14T13:28:56", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m WIFI\"", parent_process_id="4264", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m WIFI\"", process_id="6436", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749757, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="CIS 10", annotations._all="Living Off The Land", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:50", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749752.171565000", lastTime="2023-06-14T13:28:50", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m WEF Settings\"", parent_process_id="5648", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m WEF Settings\"", process_id="3784", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749757, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="CIS 10", annotations._all="Living Off The Land", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:50", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749752.171565000", lastTime="2023-06-14T13:28:50", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m WDigest?\"", parent_process_id="6532", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m WDigest?\"", process_id="4736", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749757, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="CIS 10", annotations._all="Living Off The Land", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:29:24", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749752.171565000", lastTime="2023-06-14T13:29:24", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Unattended files\"", parent_process_id="1100", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Unattended files\"", process_id="5996", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749757, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="CIS 10", annotations._all="Living Off The Land", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:56", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749752.171565000", lastTime="2023-06-14T13:28:56", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m USERS\"", parent_process_id="1516", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m USERS\"", process_id="6440", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749757, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="CIS 10", annotations._all="Living Off The Land", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:54", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749752.171565000", lastTime="2023-06-14T13:28:54", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m USED PORTS\"", parent_process_id="2460", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m USED PORTS\"", process_id="3796", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749757, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="CIS 10", annotations._all="Living Off The Land", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:29:17", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749752.171565000", lastTime="2023-06-14T13:29:17", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m UNQUOTED SERVICE PATHS\"", parent_process_id="3668", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m UNQUOTED SERVICE PATHS\"", process_id="2108", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749757, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="CIS 10", annotations._all="Living Off The Land", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:50", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749752.171565000", lastTime="2023-06-14T13:28:50", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m UAC Settings\"", parent_process_id="3584", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m UAC Settings\"", process_id="4880", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749757, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="CIS 10", annotations._all="Living Off The Land", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:59", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749752.171565000", lastTime="2023-06-14T13:28:59", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m SERVICE BINARY PERMISSIONS WITH WMIC and ICACLS\"", parent_process_id="816", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m SERVICE BINARY PERMISSIONS WITH WMIC and ICACLS\"", process_id="968", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749757, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="CIS 10", annotations._all="Living Off The Land", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:29:24", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749752.171565000", lastTime="2023-06-14T13:29:24", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m SAM and SYSTEM backups\"", parent_process_id="2284", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m SAM and SYSTEM backups\"", process_id="2804", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749757, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="CIS 10", annotations._all="Living Off The Land", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:51", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749752.171565000", lastTime="2023-06-14T13:28:51", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Remote Desktop Credentials Manager\"", parent_process_id="600", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Remote Desktop Credentials Manager\"", process_id="5544", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749757, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="CIS 10", annotations._all="Living Off The Land", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:50", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749752.171565000", lastTime="2023-06-14T13:28:50", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Registered Anti-Virus(AV)\"", parent_process_id="6556", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Registered Anti-Virus(AV)\"", process_id="5676", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749757, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="CIS 10", annotations._all="Living Off The Land", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:51", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749752.171565000", lastTime="2023-06-14T13:28:51", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m RUNNING PROCESSES\"", parent_process_id="8", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m RUNNING PROCESSES\"", process_id="4280", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749757, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="CIS 10", annotations._all="Living Off The Land", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:53", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749752.171565000", lastTime="2023-06-14T13:28:53", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m RUN AT STARTUP\"", parent_process_id="4572", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m RUN AT STARTUP\"", process_id="1892", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749757, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="CIS 10", annotations._all="Living Off The Land", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:55", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749752.171565000", lastTime="2023-06-14T13:28:55", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m ROUTES\"", parent_process_id="6420", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m ROUTES\"", process_id="5012", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749757, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="CIS 10", annotations._all="Living Off The Land", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:50", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749752.171565000", lastTime="2023-06-14T13:28:50", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m PowerShell settings\"", parent_process_id="3472", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m PowerShell settings\"", process_id="3540", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749757, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="CIS 10", annotations._all="Living Off The Land", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:50", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749752.171565000", lastTime="2023-06-14T13:28:50", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Number of cached creds\"", parent_process_id="4388", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Number of cached creds\"", process_id="4400", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749757, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="CIS 10", annotations._all="Living Off The Land", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:29:24", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749752.171565000", lastTime="2023-06-14T13:29:24", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m McAffee SiteList.xml\"", parent_process_id="6336", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m McAffee SiteList.xml\"", process_id="4652", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749757, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="CIS 10", annotations._all="Living Off The Land", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:50", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749752.171565000", lastTime="2023-06-14T13:28:50", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m MOUNTED DISKS\"", parent_process_id="3880", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m MOUNTED DISKS\"", process_id="3244", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749757, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="CIS 10", annotations._all="Living Off The Land", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:50", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749752.171565000", lastTime="2023-06-14T13:28:50", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m LSA protection?\"", parent_process_id="1880", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m LSA protection?\"", process_id="1268", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749757, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="CIS 10", annotations._all="Living Off The Land", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:50", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749752.171565000", lastTime="2023-06-14T13:28:50", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m LAPS installed?\"", parent_process_id="1912", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m LAPS installed?\"", process_id="6012", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749757, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="CIS 10", annotations._all="Living Off The Land", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:58", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749752.171565000", lastTime="2023-06-14T13:28:58", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Kerberos Tickets\"", parent_process_id="1980", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Kerberos Tickets\"", process_id="3440", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749757, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="CIS 10", annotations._all="Living Off The Land", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:54", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749752.171565000", lastTime="2023-06-14T13:28:54", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m INTERFACES\"", parent_process_id="3136", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m INTERFACES\"", process_id="2144", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749757, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="CIS 10", annotations._all="Living Off The Land", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:51", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749752.171565000", lastTime="2023-06-14T13:28:51", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m INSTALLED SOFTWARE\"", parent_process_id="5708", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m INSTALLED SOFTWARE\"", process_id="5312", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749757, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="CIS 10", annotations._all="Living Off The Land", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:56", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749752.171565000", lastTime="2023-06-14T13:28:56", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Hosts file\"", parent_process_id="3584", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Hosts file\"", process_id="6356", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749757, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="CIS 10", annotations._all="Living Off The Land", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:58", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749752.171565000", lastTime="2023-06-14T13:28:58", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m GROUPS\"", parent_process_id="524", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m GROUPS\"", process_id="6708", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749757, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="CIS 10", annotations._all="Living Off The Land", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:29:25", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749752.171565000", lastTime="2023-06-14T13:29:25", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m GPP Password\"", parent_process_id="7068", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m GPP Password\"", process_id="6768", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749757, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="CIS 10", annotations._all="Living Off The Land", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:29:26", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749752.171565000", lastTime="2023-06-14T13:29:26", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Files in registry that may contain credentials\"", parent_process_id="6976", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Files in registry that may contain credentials\"", process_id="464", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749757, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="CIS 10", annotations._all="Living Off The Land", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:55", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749752.171565000", lastTime="2023-06-14T13:28:55", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m FIREWALL\"", parent_process_id="1260", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m FIREWALL\"", process_id="4268", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749757, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="CIS 10", annotations._all="Living Off The Land", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:51", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749752.171565000", lastTime="2023-06-14T13:28:51", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m ENVIRONMENT\"", parent_process_id="6944", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m ENVIRONMENT\"", process_id="2368", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749757, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="CIS 10", annotations._all="Living Off The Land", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:29:24", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749752.171565000", lastTime="2023-06-14T13:29:24", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m DPAPI MASTER KEYS\"", parent_process_id="6016", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m DPAPI MASTER KEYS\"", process_id="4408", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749757, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="CIS 10", annotations._all="Living Off The Land", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:29:23", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749752.171565000", lastTime="2023-06-14T13:29:23", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m DPAPI MASTER KEYS\"", parent_process_id="2336", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m DPAPI MASTER KEYS\"", process_id="396", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749757, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="CIS 10", annotations._all="Living Off The Land", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:56", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749752.171565000", lastTime="2023-06-14T13:28:56", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m DNS CACHE\"", parent_process_id="4172", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m DNS CACHE\"", process_id="5728", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749757, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="CIS 10", annotations._all="Living Off The Land", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:50", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749752.171565000", lastTime="2023-06-14T13:28:50", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m DATE and TIME\"", parent_process_id="3652", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m DATE and TIME\"", process_id="4272", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749757, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="CIS 10", annotations._all="Living Off The Land", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:50", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749752.171565000", lastTime="2023-06-14T13:28:50", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Credential Guard?\"", parent_process_id="4088", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Credential Guard?\"", process_id="1260", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749757, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="CIS 10", annotations._all="Living Off The Land", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:29:26", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749752.171565000", lastTime="2023-06-14T13:29:26", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Cloud Credentials\"", parent_process_id="5992", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Cloud Credentials\"", process_id="2368", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749757, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="CIS 10", annotations._all="Living Off The Land", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:56", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749752.171565000", lastTime="2023-06-14T13:28:56", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m CURRENT USER\"", parent_process_id="6932", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m CURRENT USER\"", process_id="6340", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749757, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="CIS 10", annotations._all="Living Off The Land", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:54", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749752.171565000", lastTime="2023-06-14T13:28:54", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m CURRENT SHARES\"", parent_process_id="1876", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m CURRENT SHARES\"", process_id="1132", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749757, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="CIS 10", annotations._all="Living Off The Land", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:58", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749752.171565000", lastTime="2023-06-14T13:28:58", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m CURRENT LOGGED USERS\"", parent_process_id="6328", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m CURRENT LOGGED USERS\"", process_id="4956", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749757, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="CIS 10", annotations._all="Living Off The Land", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:59", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749752.171565000", lastTime="2023-06-14T13:28:59", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m CURRENT CLIPBOARD\"", parent_process_id="2016", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m CURRENT CLIPBOARD\"", process_id="3016", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749757, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="CIS 10", annotations._all="Living Off The Land", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:29:00", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749752.171565000", lastTime="2023-06-14T13:29:00", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m CHECK IF YOU CAN MODIFY ANY SERVICE REGISTRY\"", parent_process_id="1472", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m CHECK IF YOU CAN MODIFY ANY SERVICE REGISTRY\"", process_id="5728", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749757, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="CIS 10", annotations._all="Living Off The Land", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:50", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749752.171565000", lastTime="2023-06-14T13:28:50", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Audit Settings\"", parent_process_id="6824", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Audit Settings\"", process_id="6136", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749757, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="CIS 10", annotations._all="Living Off The Land", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:29:26", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749752.171565000", lastTime="2023-06-14T13:29:26", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m AppCmd\"", parent_process_id="7164", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m AppCmd\"", process_id="5688", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749757, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="CIS 10", annotations._all="Living Off The Land", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:54", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749752.171565000", lastTime="2023-06-14T13:28:54", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m AlwaysInstallElevated?\"", parent_process_id="6912", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m AlwaysInstallElevated?\"", process_id="7156", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749757, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="CIS 10", annotations._all="Living Off The Land", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:55", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749752.171565000", lastTime="2023-06-14T13:28:55", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m ARP\"", parent_process_id="3404", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m ARP\"", process_id="4840", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749757, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="CIS 10", annotations._all="Living Off The Land", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:58", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749752.171565000", lastTime="2023-06-14T13:28:58", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m ADMINISTRATORS GROUPS\"", parent_process_id="1892", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m ADMINISTRATORS GROUPS\"", process_id="1804", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749737, search_name="ESCU - Windows Cached Domain Credentials Reg Query - Rule", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":30,\"impact\":30,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1003.005\",\"T1003\"],\"nist\":[\"DE.AE\"]}", annotations._all="Exploitation", annotations._all="DE.AE", annotations._all="Windows Post-Exploitation", annotations._all="T1003", annotations._all="T1003.005", annotations._all="CIS 10", annotations._all="Prestige Ransomware", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1003.005", annotations.mitre_attack="T1003", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:50", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749731.516767000", lastTime="2023-06-14T13:28:50", original_file_name="unknown", parent_process="C:\\Windows\\System32\\cmd.exe", parent_process_guid="null", parent_process_name="cmd.exe", process="C:\\Windows\\System32\\reg.exe query \"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\" /v CACHEDLOGONSCOUNT", process_guid="null", process_id="0x14c4", process_name="reg.exe", risk_message="a process with commandline C:\\Windows\\System32\\reg.exe query \"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\" /v CACHEDLOGONSCOUNT tries to retrieve cache domain credential logon count in ar-win-dc.attackrange.local", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="9.0", savedsearch_description="The following analytic identifies a process command line related to the discovery of cache domain credential logon count in the registry. This Technique was being abused by several post exploitation tool like Winpeas where it query CachedLogonsCount registry value in Winlogon registry. This value can be good information about the login caching setting on the Windows OS target host. A value of 0 means login caching is disable and values > 50 caches only 50 login attempts. By default all versions of Windows 10 save cached logins except Windows Server 2008.", user="Administrator" 1686749737, search_name="ESCU - Windows Cached Domain Credentials Reg Query - Rule", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":30,\"impact\":30,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1003.005\",\"T1003\"],\"nist\":[\"DE.AE\"]}", annotations._all="Exploitation", annotations._all="DE.AE", annotations._all="Windows Post-Exploitation", annotations._all="T1003", annotations._all="T1003.005", annotations._all="CIS 10", annotations._all="Prestige Ransomware", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1003.005", annotations.mitre_attack="T1003", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:50", info_max_time="1686749700.000000000", info_min_time="1686749100.000000000", info_search_time="1686749731.516767000", lastTime="2023-06-14T13:28:50", original_file_name="reg.exe", parent_process="\"cmd.exe\" /s /k pushd \"C:\\Temp\"", parent_process_guid="{953948C6-BA8E-6489-C200-00000000F902}", parent_process_name="cmd.exe", process="reg query \"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\" /v CACHEDLOGONSCOUNT", process_guid="{953948C6-C092-6489-330E-00000000F902}", process_id="5316", process_name="reg.exe", risk_message="a process with commandline reg query \"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\" /v CACHEDLOGONSCOUNT tries to retrieve cache domain credential logon count in ar-win-dc.attackrange.local", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="9.0", savedsearch_description="The following analytic identifies a process command line related to the discovery of cache domain credential logon count in the registry. This Technique was being abused by several post exploitation tool like Winpeas where it query CachedLogonsCount registry value in Winlogon registry. This value can be good information about the login caching setting on the Windows OS target host. A value of 0 means login caching is disable and values > 50 caches only 50 login attempts. By default all versions of Windows 10 save cached logins except Windows Server 2008.", user="Administrator" 1686749641, search_name="ESCU - Cmdline Tool Not Executed In CMD Shell - Rule", analyticstories="CISA AA22-277A", analyticstories="FIN7", analyticstories="Qakbot", annotations="{\"analytic_story\":[\"FIN7\",\"Qakbot\",\"CISA AA22-277A\",\"Qakbot\"],\"cis20\":[\"CIS 10\"],\"confidence\":80,\"impact\":70,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1059\",\"T1059.007\"],\"nist\":[\"DE.CM\"]}", annotations._all="CISA AA22-277A", annotations._all="Installation", annotations._all="FIN7", annotations._all="T1059.007", annotations._all="T1059", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Qakbot", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="FIN7", annotations.analytic_story="Qakbot", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Qakbot", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1059", annotations.mitre_attack="T1059.007", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:56", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749637.853744000", lastTime="2023-06-14T13:28:56", original_file_name="net1.exe", parent_process="net user Administrator /domain", parent_process_name="net.exe", process="C:\\Windows\\system32\\net1 user Administrator /domain", process_id="1596", process_name="net1.exe", risk_message="A non-standard parent process net.exe spawned child process net1.exe to execute command-line tool on ar-win-dc.attackrange.local.", risk_object="net1.exe", risk_object_type="other", risk_score="56.0", savedsearch_description="The following analytic identifies a non-standard parent process (not matching CMD, PowerShell, or Explorer) spawning `ipconfig.exe` or `systeminfo.exe`. This particular behavior was seen in FIN7's JSSLoader .NET payload. This is also typically seen when an adversary is injected into another process performing different discovery techniques. This event stands out as a TTP since these tools are commonly executed with a shell application or Explorer parent, and not by another application. This TTP is a good indicator for an adversary gathering host information, but one possible false positive might be an automated tool used by a system administator.", user="Administrator" 1686749641, search_name="ESCU - Cmdline Tool Not Executed In CMD Shell - Rule", analyticstories="CISA AA22-277A", analyticstories="FIN7", analyticstories="Qakbot", annotations="{\"analytic_story\":[\"FIN7\",\"Qakbot\",\"CISA AA22-277A\",\"Qakbot\"],\"cis20\":[\"CIS 10\"],\"confidence\":80,\"impact\":70,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1059\",\"T1059.007\"],\"nist\":[\"DE.CM\"]}", annotations._all="CISA AA22-277A", annotations._all="Installation", annotations._all="FIN7", annotations._all="T1059.007", annotations._all="T1059", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Qakbot", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="FIN7", annotations.analytic_story="Qakbot", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Qakbot", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1059", annotations.mitre_attack="T1059.007", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:56", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749637.853744000", lastTime="2023-06-14T13:28:56", original_file_name="net1.exe", parent_process="net user Administrator /domain", parent_process_name="net.exe", process="C:\\Windows\\system32\\net1 user Administrator /domain", process_id="1596", process_name="net1.exe", risk_message="A non-standard parent process net.exe spawned child process net1.exe to execute command-line tool on ar-win-dc.attackrange.local.", risk_object="net.exe", risk_object_type="other", risk_score="56.0", savedsearch_description="The following analytic identifies a non-standard parent process (not matching CMD, PowerShell, or Explorer) spawning `ipconfig.exe` or `systeminfo.exe`. This particular behavior was seen in FIN7's JSSLoader .NET payload. This is also typically seen when an adversary is injected into another process performing different discovery techniques. This event stands out as a TTP since these tools are commonly executed with a shell application or Explorer parent, and not by another application. This TTP is a good indicator for an adversary gathering host information, but one possible false positive might be an automated tool used by a system administator.", user="Administrator" 1686749641, search_name="ESCU - Cmdline Tool Not Executed In CMD Shell - Rule", analyticstories="CISA AA22-277A", analyticstories="FIN7", analyticstories="Qakbot", annotations="{\"analytic_story\":[\"FIN7\",\"Qakbot\",\"CISA AA22-277A\",\"Qakbot\"],\"cis20\":[\"CIS 10\"],\"confidence\":80,\"impact\":70,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1059\",\"T1059.007\"],\"nist\":[\"DE.CM\"]}", annotations._all="CISA AA22-277A", annotations._all="Installation", annotations._all="FIN7", annotations._all="T1059.007", annotations._all="T1059", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Qakbot", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="FIN7", annotations.analytic_story="Qakbot", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Qakbot", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1059", annotations.mitre_attack="T1059.007", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:56", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749637.853744000", lastTime="2023-06-14T13:28:56", original_file_name="net1.exe", parent_process="net user Administrator /domain", parent_process_name="net.exe", process="C:\\Windows\\system32\\net1 user Administrator /domain", process_id="1596", process_name="net1.exe", risk_message="A non-standard parent process net.exe spawned child process net1.exe to execute command-line tool on ar-win-dc.attackrange.local.", risk_object="Administrator", risk_object_type="user", risk_score="56.0", savedsearch_description="The following analytic identifies a non-standard parent process (not matching CMD, PowerShell, or Explorer) spawning `ipconfig.exe` or `systeminfo.exe`. This particular behavior was seen in FIN7's JSSLoader .NET payload. This is also typically seen when an adversary is injected into another process performing different discovery techniques. This event stands out as a TTP since these tools are commonly executed with a shell application or Explorer parent, and not by another application. This TTP is a good indicator for an adversary gathering host information, but one possible false positive might be an automated tool used by a system administator.", user="Administrator" 1686749641, search_name="ESCU - Cmdline Tool Not Executed In CMD Shell - Rule", analyticstories="CISA AA22-277A", analyticstories="FIN7", analyticstories="Qakbot", annotations="{\"analytic_story\":[\"FIN7\",\"Qakbot\",\"CISA AA22-277A\",\"Qakbot\"],\"cis20\":[\"CIS 10\"],\"confidence\":80,\"impact\":70,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1059\",\"T1059.007\"],\"nist\":[\"DE.CM\"]}", annotations._all="CISA AA22-277A", annotations._all="Installation", annotations._all="FIN7", annotations._all="T1059.007", annotations._all="T1059", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Qakbot", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="FIN7", annotations.analytic_story="Qakbot", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Qakbot", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1059", annotations.mitre_attack="T1059.007", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:56", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749637.853744000", lastTime="2023-06-14T13:28:56", original_file_name="net1.exe", parent_process="net user Administrator /domain", parent_process_name="net.exe", process="C:\\Windows\\system32\\net1 user Administrator /domain", process_id="1596", process_name="net1.exe", risk_message="A non-standard parent process net.exe spawned child process net1.exe to execute command-line tool on ar-win-dc.attackrange.local.", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="56.0", savedsearch_description="The following analytic identifies a non-standard parent process (not matching CMD, PowerShell, or Explorer) spawning `ipconfig.exe` or `systeminfo.exe`. This particular behavior was seen in FIN7's JSSLoader .NET payload. This is also typically seen when an adversary is injected into another process performing different discovery techniques. This event stands out as a TTP since these tools are commonly executed with a shell application or Explorer parent, and not by another application. This TTP is a good indicator for an adversary gathering host information, but one possible false positive might be an automated tool used by a system administator.", user="Administrator" 1686749641, search_name="ESCU - Cmdline Tool Not Executed In CMD Shell - Rule", analyticstories="CISA AA22-277A", analyticstories="FIN7", analyticstories="Qakbot", annotations="{\"analytic_story\":[\"FIN7\",\"Qakbot\",\"CISA AA22-277A\",\"Qakbot\"],\"cis20\":[\"CIS 10\"],\"confidence\":80,\"impact\":70,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1059\",\"T1059.007\"],\"nist\":[\"DE.CM\"]}", annotations._all="CISA AA22-277A", annotations._all="Installation", annotations._all="FIN7", annotations._all="T1059.007", annotations._all="T1059", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Qakbot", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="FIN7", annotations.analytic_story="Qakbot", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Qakbot", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1059", annotations.mitre_attack="T1059.007", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:56", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749637.853744000", lastTime="2023-06-14T13:28:56", original_file_name="net1.exe", parent_process="net user Administrator", parent_process_name="net.exe", process="C:\\Windows\\system32\\net1 user Administrator", process_id="5408", process_name="net1.exe", risk_message="A non-standard parent process net.exe spawned child process net1.exe to execute command-line tool on ar-win-dc.attackrange.local.", risk_object="net1.exe", risk_object_type="other", risk_score="56.0", savedsearch_description="The following analytic identifies a non-standard parent process (not matching CMD, PowerShell, or Explorer) spawning `ipconfig.exe` or `systeminfo.exe`. This particular behavior was seen in FIN7's JSSLoader .NET payload. This is also typically seen when an adversary is injected into another process performing different discovery techniques. This event stands out as a TTP since these tools are commonly executed with a shell application or Explorer parent, and not by another application. This TTP is a good indicator for an adversary gathering host information, but one possible false positive might be an automated tool used by a system administator.", user="Administrator" 1686749641, search_name="ESCU - Cmdline Tool Not Executed In CMD Shell - Rule", analyticstories="CISA AA22-277A", analyticstories="FIN7", analyticstories="Qakbot", annotations="{\"analytic_story\":[\"FIN7\",\"Qakbot\",\"CISA AA22-277A\",\"Qakbot\"],\"cis20\":[\"CIS 10\"],\"confidence\":80,\"impact\":70,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1059\",\"T1059.007\"],\"nist\":[\"DE.CM\"]}", annotations._all="CISA AA22-277A", annotations._all="Installation", annotations._all="FIN7", annotations._all="T1059.007", annotations._all="T1059", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Qakbot", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="FIN7", annotations.analytic_story="Qakbot", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Qakbot", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1059", annotations.mitre_attack="T1059.007", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:56", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749637.853744000", lastTime="2023-06-14T13:28:56", original_file_name="net1.exe", parent_process="net user Administrator", parent_process_name="net.exe", process="C:\\Windows\\system32\\net1 user Administrator", process_id="5408", process_name="net1.exe", risk_message="A non-standard parent process net.exe spawned child process net1.exe to execute command-line tool on ar-win-dc.attackrange.local.", risk_object="net.exe", risk_object_type="other", risk_score="56.0", savedsearch_description="The following analytic identifies a non-standard parent process (not matching CMD, PowerShell, or Explorer) spawning `ipconfig.exe` or `systeminfo.exe`. This particular behavior was seen in FIN7's JSSLoader .NET payload. This is also typically seen when an adversary is injected into another process performing different discovery techniques. This event stands out as a TTP since these tools are commonly executed with a shell application or Explorer parent, and not by another application. This TTP is a good indicator for an adversary gathering host information, but one possible false positive might be an automated tool used by a system administator.", user="Administrator" 1686749641, search_name="ESCU - Cmdline Tool Not Executed In CMD Shell - Rule", analyticstories="CISA AA22-277A", analyticstories="FIN7", analyticstories="Qakbot", annotations="{\"analytic_story\":[\"FIN7\",\"Qakbot\",\"CISA AA22-277A\",\"Qakbot\"],\"cis20\":[\"CIS 10\"],\"confidence\":80,\"impact\":70,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1059\",\"T1059.007\"],\"nist\":[\"DE.CM\"]}", annotations._all="CISA AA22-277A", annotations._all="Installation", annotations._all="FIN7", annotations._all="T1059.007", annotations._all="T1059", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Qakbot", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="FIN7", annotations.analytic_story="Qakbot", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Qakbot", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1059", annotations.mitre_attack="T1059.007", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:56", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749637.853744000", lastTime="2023-06-14T13:28:56", original_file_name="net1.exe", parent_process="net user Administrator", parent_process_name="net.exe", process="C:\\Windows\\system32\\net1 user Administrator", process_id="5408", process_name="net1.exe", risk_message="A non-standard parent process net.exe spawned child process net1.exe to execute command-line tool on ar-win-dc.attackrange.local.", risk_object="Administrator", risk_object_type="user", risk_score="56.0", savedsearch_description="The following analytic identifies a non-standard parent process (not matching CMD, PowerShell, or Explorer) spawning `ipconfig.exe` or `systeminfo.exe`. This particular behavior was seen in FIN7's JSSLoader .NET payload. This is also typically seen when an adversary is injected into another process performing different discovery techniques. This event stands out as a TTP since these tools are commonly executed with a shell application or Explorer parent, and not by another application. This TTP is a good indicator for an adversary gathering host information, but one possible false positive might be an automated tool used by a system administator.", user="Administrator" 1686749641, search_name="ESCU - Cmdline Tool Not Executed In CMD Shell - Rule", analyticstories="CISA AA22-277A", analyticstories="FIN7", analyticstories="Qakbot", annotations="{\"analytic_story\":[\"FIN7\",\"Qakbot\",\"CISA AA22-277A\",\"Qakbot\"],\"cis20\":[\"CIS 10\"],\"confidence\":80,\"impact\":70,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1059\",\"T1059.007\"],\"nist\":[\"DE.CM\"]}", annotations._all="CISA AA22-277A", annotations._all="Installation", annotations._all="FIN7", annotations._all="T1059.007", annotations._all="T1059", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Qakbot", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="FIN7", annotations.analytic_story="Qakbot", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Qakbot", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1059", annotations.mitre_attack="T1059.007", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:56", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749637.853744000", lastTime="2023-06-14T13:28:56", original_file_name="net1.exe", parent_process="net user Administrator", parent_process_name="net.exe", process="C:\\Windows\\system32\\net1 user Administrator", process_id="5408", process_name="net1.exe", risk_message="A non-standard parent process net.exe spawned child process net1.exe to execute command-line tool on ar-win-dc.attackrange.local.", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="56.0", savedsearch_description="The following analytic identifies a non-standard parent process (not matching CMD, PowerShell, or Explorer) spawning `ipconfig.exe` or `systeminfo.exe`. This particular behavior was seen in FIN7's JSSLoader .NET payload. This is also typically seen when an adversary is injected into another process performing different discovery techniques. This event stands out as a TTP since these tools are commonly executed with a shell application or Explorer parent, and not by another application. This TTP is a good indicator for an adversary gathering host information, but one possible false positive might be an automated tool used by a system administator.", user="Administrator" 1686749641, search_name="ESCU - Cmdline Tool Not Executed In CMD Shell - Rule", analyticstories="CISA AA22-277A", analyticstories="FIN7", analyticstories="Qakbot", annotations="{\"analytic_story\":[\"FIN7\",\"Qakbot\",\"CISA AA22-277A\",\"Qakbot\"],\"cis20\":[\"CIS 10\"],\"confidence\":80,\"impact\":70,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1059\",\"T1059.007\"],\"nist\":[\"DE.CM\"]}", annotations._all="CISA AA22-277A", annotations._all="Installation", annotations._all="FIN7", annotations._all="T1059.007", annotations._all="T1059", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Qakbot", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="FIN7", annotations.analytic_story="Qakbot", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Qakbot", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1059", annotations.mitre_attack="T1059.007", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:56", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749637.853744000", lastTime="2023-06-14T13:28:56", original_file_name="net1.exe", parent_process="net user", parent_process_name="net.exe", process="C:\\Windows\\system32\\net1 user", process_id="7108", process_name="net1.exe", risk_message="A non-standard parent process net.exe spawned child process net1.exe to execute command-line tool on ar-win-dc.attackrange.local.", risk_object="net1.exe", risk_object_type="other", risk_score="56.0", savedsearch_description="The following analytic identifies a non-standard parent process (not matching CMD, PowerShell, or Explorer) spawning `ipconfig.exe` or `systeminfo.exe`. This particular behavior was seen in FIN7's JSSLoader .NET payload. This is also typically seen when an adversary is injected into another process performing different discovery techniques. This event stands out as a TTP since these tools are commonly executed with a shell application or Explorer parent, and not by another application. This TTP is a good indicator for an adversary gathering host information, but one possible false positive might be an automated tool used by a system administator.", user="Administrator" 1686749641, search_name="ESCU - Cmdline Tool Not Executed In CMD Shell - Rule", analyticstories="CISA AA22-277A", analyticstories="FIN7", analyticstories="Qakbot", annotations="{\"analytic_story\":[\"FIN7\",\"Qakbot\",\"CISA AA22-277A\",\"Qakbot\"],\"cis20\":[\"CIS 10\"],\"confidence\":80,\"impact\":70,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1059\",\"T1059.007\"],\"nist\":[\"DE.CM\"]}", annotations._all="CISA AA22-277A", annotations._all="Installation", annotations._all="FIN7", annotations._all="T1059.007", annotations._all="T1059", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Qakbot", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="FIN7", annotations.analytic_story="Qakbot", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Qakbot", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1059", annotations.mitre_attack="T1059.007", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:56", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749637.853744000", lastTime="2023-06-14T13:28:56", original_file_name="net1.exe", parent_process="net user", parent_process_name="net.exe", process="C:\\Windows\\system32\\net1 user", process_id="7108", process_name="net1.exe", risk_message="A non-standard parent process net.exe spawned child process net1.exe to execute command-line tool on ar-win-dc.attackrange.local.", risk_object="net.exe", risk_object_type="other", risk_score="56.0", savedsearch_description="The following analytic identifies a non-standard parent process (not matching CMD, PowerShell, or Explorer) spawning `ipconfig.exe` or `systeminfo.exe`. This particular behavior was seen in FIN7's JSSLoader .NET payload. This is also typically seen when an adversary is injected into another process performing different discovery techniques. This event stands out as a TTP since these tools are commonly executed with a shell application or Explorer parent, and not by another application. This TTP is a good indicator for an adversary gathering host information, but one possible false positive might be an automated tool used by a system administator.", user="Administrator" 1686749641, search_name="ESCU - Cmdline Tool Not Executed In CMD Shell - Rule", analyticstories="CISA AA22-277A", analyticstories="FIN7", analyticstories="Qakbot", annotations="{\"analytic_story\":[\"FIN7\",\"Qakbot\",\"CISA AA22-277A\",\"Qakbot\"],\"cis20\":[\"CIS 10\"],\"confidence\":80,\"impact\":70,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1059\",\"T1059.007\"],\"nist\":[\"DE.CM\"]}", annotations._all="CISA AA22-277A", annotations._all="Installation", annotations._all="FIN7", annotations._all="T1059.007", annotations._all="T1059", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Qakbot", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="FIN7", annotations.analytic_story="Qakbot", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Qakbot", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1059", annotations.mitre_attack="T1059.007", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:56", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749637.853744000", lastTime="2023-06-14T13:28:56", original_file_name="net1.exe", parent_process="net user", parent_process_name="net.exe", process="C:\\Windows\\system32\\net1 user", process_id="7108", process_name="net1.exe", risk_message="A non-standard parent process net.exe spawned child process net1.exe to execute command-line tool on ar-win-dc.attackrange.local.", risk_object="Administrator", risk_object_type="user", risk_score="56.0", savedsearch_description="The following analytic identifies a non-standard parent process (not matching CMD, PowerShell, or Explorer) spawning `ipconfig.exe` or `systeminfo.exe`. This particular behavior was seen in FIN7's JSSLoader .NET payload. This is also typically seen when an adversary is injected into another process performing different discovery techniques. This event stands out as a TTP since these tools are commonly executed with a shell application or Explorer parent, and not by another application. This TTP is a good indicator for an adversary gathering host information, but one possible false positive might be an automated tool used by a system administator.", user="Administrator" 1686749641, search_name="ESCU - Cmdline Tool Not Executed In CMD Shell - Rule", analyticstories="CISA AA22-277A", analyticstories="FIN7", analyticstories="Qakbot", annotations="{\"analytic_story\":[\"FIN7\",\"Qakbot\",\"CISA AA22-277A\",\"Qakbot\"],\"cis20\":[\"CIS 10\"],\"confidence\":80,\"impact\":70,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1059\",\"T1059.007\"],\"nist\":[\"DE.CM\"]}", annotations._all="CISA AA22-277A", annotations._all="Installation", annotations._all="FIN7", annotations._all="T1059.007", annotations._all="T1059", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Qakbot", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="FIN7", annotations.analytic_story="Qakbot", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Qakbot", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1059", annotations.mitre_attack="T1059.007", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:56", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749637.853744000", lastTime="2023-06-14T13:28:56", original_file_name="net1.exe", parent_process="net user", parent_process_name="net.exe", process="C:\\Windows\\system32\\net1 user", process_id="7108", process_name="net1.exe", risk_message="A non-standard parent process net.exe spawned child process net1.exe to execute command-line tool on ar-win-dc.attackrange.local.", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="56.0", savedsearch_description="The following analytic identifies a non-standard parent process (not matching CMD, PowerShell, or Explorer) spawning `ipconfig.exe` or `systeminfo.exe`. This particular behavior was seen in FIN7's JSSLoader .NET payload. This is also typically seen when an adversary is injected into another process performing different discovery techniques. This event stands out as a TTP since these tools are commonly executed with a shell application or Explorer parent, and not by another application. This TTP is a good indicator for an adversary gathering host information, but one possible false positive might be an automated tool used by a system administator.", user="Administrator" 1686749641, search_name="ESCU - Cmdline Tool Not Executed In CMD Shell - Rule", analyticstories="CISA AA22-277A", analyticstories="FIN7", analyticstories="Qakbot", annotations="{\"analytic_story\":[\"FIN7\",\"Qakbot\",\"CISA AA22-277A\",\"Qakbot\"],\"cis20\":[\"CIS 10\"],\"confidence\":80,\"impact\":70,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1059\",\"T1059.007\"],\"nist\":[\"DE.CM\"]}", annotations._all="CISA AA22-277A", annotations._all="Installation", annotations._all="FIN7", annotations._all="T1059.007", annotations._all="T1059", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Qakbot", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="FIN7", annotations.analytic_story="Qakbot", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Qakbot", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1059", annotations.mitre_attack="T1059.007", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:54", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749637.853744000", lastTime="2023-06-14T13:28:54", original_file_name="net1.exe", parent_process="net share", parent_process_name="net.exe", process="C:\\Windows\\system32\\net1 share", process_id="6700", process_name="net1.exe", risk_message="A non-standard parent process net.exe spawned child process net1.exe to execute command-line tool on ar-win-dc.attackrange.local.", risk_object="net1.exe", risk_object_type="other", risk_score="56.0", savedsearch_description="The following analytic identifies a non-standard parent process (not matching CMD, PowerShell, or Explorer) spawning `ipconfig.exe` or `systeminfo.exe`. This particular behavior was seen in FIN7's JSSLoader .NET payload. This is also typically seen when an adversary is injected into another process performing different discovery techniques. This event stands out as a TTP since these tools are commonly executed with a shell application or Explorer parent, and not by another application. This TTP is a good indicator for an adversary gathering host information, but one possible false positive might be an automated tool used by a system administator.", user="Administrator" 1686749641, search_name="ESCU - Cmdline Tool Not Executed In CMD Shell - Rule", analyticstories="CISA AA22-277A", analyticstories="FIN7", analyticstories="Qakbot", annotations="{\"analytic_story\":[\"FIN7\",\"Qakbot\",\"CISA AA22-277A\",\"Qakbot\"],\"cis20\":[\"CIS 10\"],\"confidence\":80,\"impact\":70,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1059\",\"T1059.007\"],\"nist\":[\"DE.CM\"]}", annotations._all="CISA AA22-277A", annotations._all="Installation", annotations._all="FIN7", annotations._all="T1059.007", annotations._all="T1059", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Qakbot", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="FIN7", annotations.analytic_story="Qakbot", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Qakbot", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1059", annotations.mitre_attack="T1059.007", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:54", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749637.853744000", lastTime="2023-06-14T13:28:54", original_file_name="net1.exe", parent_process="net share", parent_process_name="net.exe", process="C:\\Windows\\system32\\net1 share", process_id="6700", process_name="net1.exe", risk_message="A non-standard parent process net.exe spawned child process net1.exe to execute command-line tool on ar-win-dc.attackrange.local.", risk_object="net.exe", risk_object_type="other", risk_score="56.0", savedsearch_description="The following analytic identifies a non-standard parent process (not matching CMD, PowerShell, or Explorer) spawning `ipconfig.exe` or `systeminfo.exe`. This particular behavior was seen in FIN7's JSSLoader .NET payload. This is also typically seen when an adversary is injected into another process performing different discovery techniques. This event stands out as a TTP since these tools are commonly executed with a shell application or Explorer parent, and not by another application. This TTP is a good indicator for an adversary gathering host information, but one possible false positive might be an automated tool used by a system administator.", user="Administrator" 1686749641, search_name="ESCU - Cmdline Tool Not Executed In CMD Shell - Rule", analyticstories="CISA AA22-277A", analyticstories="FIN7", analyticstories="Qakbot", annotations="{\"analytic_story\":[\"FIN7\",\"Qakbot\",\"CISA AA22-277A\",\"Qakbot\"],\"cis20\":[\"CIS 10\"],\"confidence\":80,\"impact\":70,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1059\",\"T1059.007\"],\"nist\":[\"DE.CM\"]}", annotations._all="CISA AA22-277A", annotations._all="Installation", annotations._all="FIN7", annotations._all="T1059.007", annotations._all="T1059", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Qakbot", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="FIN7", annotations.analytic_story="Qakbot", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Qakbot", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1059", annotations.mitre_attack="T1059.007", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:54", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749637.853744000", lastTime="2023-06-14T13:28:54", original_file_name="net1.exe", parent_process="net share", parent_process_name="net.exe", process="C:\\Windows\\system32\\net1 share", process_id="6700", process_name="net1.exe", risk_message="A non-standard parent process net.exe spawned child process net1.exe to execute command-line tool on ar-win-dc.attackrange.local.", risk_object="Administrator", risk_object_type="user", risk_score="56.0", savedsearch_description="The following analytic identifies a non-standard parent process (not matching CMD, PowerShell, or Explorer) spawning `ipconfig.exe` or `systeminfo.exe`. This particular behavior was seen in FIN7's JSSLoader .NET payload. This is also typically seen when an adversary is injected into another process performing different discovery techniques. This event stands out as a TTP since these tools are commonly executed with a shell application or Explorer parent, and not by another application. This TTP is a good indicator for an adversary gathering host information, but one possible false positive might be an automated tool used by a system administator.", user="Administrator" 1686749641, search_name="ESCU - Cmdline Tool Not Executed In CMD Shell - Rule", analyticstories="CISA AA22-277A", analyticstories="FIN7", analyticstories="Qakbot", annotations="{\"analytic_story\":[\"FIN7\",\"Qakbot\",\"CISA AA22-277A\",\"Qakbot\"],\"cis20\":[\"CIS 10\"],\"confidence\":80,\"impact\":70,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1059\",\"T1059.007\"],\"nist\":[\"DE.CM\"]}", annotations._all="CISA AA22-277A", annotations._all="Installation", annotations._all="FIN7", annotations._all="T1059.007", annotations._all="T1059", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Qakbot", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="FIN7", annotations.analytic_story="Qakbot", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Qakbot", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1059", annotations.mitre_attack="T1059.007", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:54", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749637.853744000", lastTime="2023-06-14T13:28:54", original_file_name="net1.exe", parent_process="net share", parent_process_name="net.exe", process="C:\\Windows\\system32\\net1 share", process_id="6700", process_name="net1.exe", risk_message="A non-standard parent process net.exe spawned child process net1.exe to execute command-line tool on ar-win-dc.attackrange.local.", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="56.0", savedsearch_description="The following analytic identifies a non-standard parent process (not matching CMD, PowerShell, or Explorer) spawning `ipconfig.exe` or `systeminfo.exe`. This particular behavior was seen in FIN7's JSSLoader .NET payload. This is also typically seen when an adversary is injected into another process performing different discovery techniques. This event stands out as a TTP since these tools are commonly executed with a shell application or Explorer parent, and not by another application. This TTP is a good indicator for an adversary gathering host information, but one possible false positive might be an automated tool used by a system administator.", user="Administrator" 1686749641, search_name="ESCU - Cmdline Tool Not Executed In CMD Shell - Rule", analyticstories="CISA AA22-277A", analyticstories="FIN7", analyticstories="Qakbot", annotations="{\"analytic_story\":[\"FIN7\",\"Qakbot\",\"CISA AA22-277A\",\"Qakbot\"],\"cis20\":[\"CIS 10\"],\"confidence\":80,\"impact\":70,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1059\",\"T1059.007\"],\"nist\":[\"DE.CM\"]}", annotations._all="CISA AA22-277A", annotations._all="Installation", annotations._all="FIN7", annotations._all="T1059.007", annotations._all="T1059", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Qakbot", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="FIN7", annotations.analytic_story="Qakbot", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Qakbot", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1059", annotations.mitre_attack="T1059.007", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:58", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749637.853744000", lastTime="2023-06-14T13:28:58", original_file_name="net1.exe", parent_process="net localgroup Administrators", parent_process_name="net.exe", process="C:\\Windows\\system32\\net1 localgroup Administrators", process_id="5652", process_name="net1.exe", risk_message="A non-standard parent process net.exe spawned child process net1.exe to execute command-line tool on ar-win-dc.attackrange.local.", risk_object="net1.exe", risk_object_type="other", risk_score="56.0", savedsearch_description="The following analytic identifies a non-standard parent process (not matching CMD, PowerShell, or Explorer) spawning `ipconfig.exe` or `systeminfo.exe`. This particular behavior was seen in FIN7's JSSLoader .NET payload. This is also typically seen when an adversary is injected into another process performing different discovery techniques. This event stands out as a TTP since these tools are commonly executed with a shell application or Explorer parent, and not by another application. This TTP is a good indicator for an adversary gathering host information, but one possible false positive might be an automated tool used by a system administator.", user="Administrator" 1686749641, search_name="ESCU - Cmdline Tool Not Executed In CMD Shell - Rule", analyticstories="CISA AA22-277A", analyticstories="FIN7", analyticstories="Qakbot", annotations="{\"analytic_story\":[\"FIN7\",\"Qakbot\",\"CISA AA22-277A\",\"Qakbot\"],\"cis20\":[\"CIS 10\"],\"confidence\":80,\"impact\":70,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1059\",\"T1059.007\"],\"nist\":[\"DE.CM\"]}", annotations._all="CISA AA22-277A", annotations._all="Installation", annotations._all="FIN7", annotations._all="T1059.007", annotations._all="T1059", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Qakbot", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="FIN7", annotations.analytic_story="Qakbot", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Qakbot", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1059", annotations.mitre_attack="T1059.007", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:58", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749637.853744000", lastTime="2023-06-14T13:28:58", original_file_name="net1.exe", parent_process="net localgroup Administrators", parent_process_name="net.exe", process="C:\\Windows\\system32\\net1 localgroup Administrators", process_id="5652", process_name="net1.exe", risk_message="A non-standard parent process net.exe spawned child process net1.exe to execute command-line tool on ar-win-dc.attackrange.local.", risk_object="net.exe", risk_object_type="other", risk_score="56.0", savedsearch_description="The following analytic identifies a non-standard parent process (not matching CMD, PowerShell, or Explorer) spawning `ipconfig.exe` or `systeminfo.exe`. This particular behavior was seen in FIN7's JSSLoader .NET payload. This is also typically seen when an adversary is injected into another process performing different discovery techniques. This event stands out as a TTP since these tools are commonly executed with a shell application or Explorer parent, and not by another application. This TTP is a good indicator for an adversary gathering host information, but one possible false positive might be an automated tool used by a system administator.", user="Administrator" 1686749641, search_name="ESCU - Cmdline Tool Not Executed In CMD Shell - Rule", analyticstories="CISA AA22-277A", analyticstories="FIN7", analyticstories="Qakbot", annotations="{\"analytic_story\":[\"FIN7\",\"Qakbot\",\"CISA AA22-277A\",\"Qakbot\"],\"cis20\":[\"CIS 10\"],\"confidence\":80,\"impact\":70,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1059\",\"T1059.007\"],\"nist\":[\"DE.CM\"]}", annotations._all="CISA AA22-277A", annotations._all="Installation", annotations._all="FIN7", annotations._all="T1059.007", annotations._all="T1059", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Qakbot", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="FIN7", annotations.analytic_story="Qakbot", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Qakbot", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1059", annotations.mitre_attack="T1059.007", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:58", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749637.853744000", lastTime="2023-06-14T13:28:58", original_file_name="net1.exe", parent_process="net localgroup Administrators", parent_process_name="net.exe", process="C:\\Windows\\system32\\net1 localgroup Administrators", process_id="5652", process_name="net1.exe", risk_message="A non-standard parent process net.exe spawned child process net1.exe to execute command-line tool on ar-win-dc.attackrange.local.", risk_object="Administrator", risk_object_type="user", risk_score="56.0", savedsearch_description="The following analytic identifies a non-standard parent process (not matching CMD, PowerShell, or Explorer) spawning `ipconfig.exe` or `systeminfo.exe`. This particular behavior was seen in FIN7's JSSLoader .NET payload. This is also typically seen when an adversary is injected into another process performing different discovery techniques. This event stands out as a TTP since these tools are commonly executed with a shell application or Explorer parent, and not by another application. This TTP is a good indicator for an adversary gathering host information, but one possible false positive might be an automated tool used by a system administator.", user="Administrator" 1686749641, search_name="ESCU - Cmdline Tool Not Executed In CMD Shell - Rule", analyticstories="CISA AA22-277A", analyticstories="FIN7", analyticstories="Qakbot", annotations="{\"analytic_story\":[\"FIN7\",\"Qakbot\",\"CISA AA22-277A\",\"Qakbot\"],\"cis20\":[\"CIS 10\"],\"confidence\":80,\"impact\":70,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1059\",\"T1059.007\"],\"nist\":[\"DE.CM\"]}", annotations._all="CISA AA22-277A", annotations._all="Installation", annotations._all="FIN7", annotations._all="T1059.007", annotations._all="T1059", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Qakbot", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="FIN7", annotations.analytic_story="Qakbot", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Qakbot", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1059", annotations.mitre_attack="T1059.007", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:58", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749637.853744000", lastTime="2023-06-14T13:28:58", original_file_name="net1.exe", parent_process="net localgroup Administrators", parent_process_name="net.exe", process="C:\\Windows\\system32\\net1 localgroup Administrators", process_id="5652", process_name="net1.exe", risk_message="A non-standard parent process net.exe spawned child process net1.exe to execute command-line tool on ar-win-dc.attackrange.local.", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="56.0", savedsearch_description="The following analytic identifies a non-standard parent process (not matching CMD, PowerShell, or Explorer) spawning `ipconfig.exe` or `systeminfo.exe`. This particular behavior was seen in FIN7's JSSLoader .NET payload. This is also typically seen when an adversary is injected into another process performing different discovery techniques. This event stands out as a TTP since these tools are commonly executed with a shell application or Explorer parent, and not by another application. This TTP is a good indicator for an adversary gathering host information, but one possible false positive might be an automated tool used by a system administator.", user="Administrator" 1686749641, search_name="ESCU - Cmdline Tool Not Executed In CMD Shell - Rule", analyticstories="CISA AA22-277A", analyticstories="FIN7", analyticstories="Qakbot", annotations="{\"analytic_story\":[\"FIN7\",\"Qakbot\",\"CISA AA22-277A\",\"Qakbot\"],\"cis20\":[\"CIS 10\"],\"confidence\":80,\"impact\":70,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1059\",\"T1059.007\"],\"nist\":[\"DE.CM\"]}", annotations._all="CISA AA22-277A", annotations._all="Installation", annotations._all="FIN7", annotations._all="T1059.007", annotations._all="T1059", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Qakbot", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="FIN7", annotations.analytic_story="Qakbot", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Qakbot", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1059", annotations.mitre_attack="T1059.007", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:58", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749637.853744000", lastTime="2023-06-14T13:28:58", original_file_name="net1.exe", parent_process="net localgroup Administradores", parent_process_name="net.exe", process="C:\\Windows\\system32\\net1 localgroup Administradores", process_id="6740", process_name="net1.exe", risk_message="A non-standard parent process net.exe spawned child process net1.exe to execute command-line tool on ar-win-dc.attackrange.local.", risk_object="net1.exe", risk_object_type="other", risk_score="56.0", savedsearch_description="The following analytic identifies a non-standard parent process (not matching CMD, PowerShell, or Explorer) spawning `ipconfig.exe` or `systeminfo.exe`. This particular behavior was seen in FIN7's JSSLoader .NET payload. This is also typically seen when an adversary is injected into another process performing different discovery techniques. This event stands out as a TTP since these tools are commonly executed with a shell application or Explorer parent, and not by another application. This TTP is a good indicator for an adversary gathering host information, but one possible false positive might be an automated tool used by a system administator.", user="Administrator" 1686749641, search_name="ESCU - Cmdline Tool Not Executed In CMD Shell - Rule", analyticstories="CISA AA22-277A", analyticstories="FIN7", analyticstories="Qakbot", annotations="{\"analytic_story\":[\"FIN7\",\"Qakbot\",\"CISA AA22-277A\",\"Qakbot\"],\"cis20\":[\"CIS 10\"],\"confidence\":80,\"impact\":70,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1059\",\"T1059.007\"],\"nist\":[\"DE.CM\"]}", annotations._all="CISA AA22-277A", annotations._all="Installation", annotations._all="FIN7", annotations._all="T1059.007", annotations._all="T1059", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Qakbot", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="FIN7", annotations.analytic_story="Qakbot", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Qakbot", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1059", annotations.mitre_attack="T1059.007", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:58", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749637.853744000", lastTime="2023-06-14T13:28:58", original_file_name="net1.exe", parent_process="net localgroup Administradores", parent_process_name="net.exe", process="C:\\Windows\\system32\\net1 localgroup Administradores", process_id="6740", process_name="net1.exe", risk_message="A non-standard parent process net.exe spawned child process net1.exe to execute command-line tool on ar-win-dc.attackrange.local.", risk_object="net.exe", risk_object_type="other", risk_score="56.0", savedsearch_description="The following analytic identifies a non-standard parent process (not matching CMD, PowerShell, or Explorer) spawning `ipconfig.exe` or `systeminfo.exe`. This particular behavior was seen in FIN7's JSSLoader .NET payload. This is also typically seen when an adversary is injected into another process performing different discovery techniques. This event stands out as a TTP since these tools are commonly executed with a shell application or Explorer parent, and not by another application. This TTP is a good indicator for an adversary gathering host information, but one possible false positive might be an automated tool used by a system administator.", user="Administrator" 1686749641, search_name="ESCU - Cmdline Tool Not Executed In CMD Shell - Rule", analyticstories="CISA AA22-277A", analyticstories="FIN7", analyticstories="Qakbot", annotations="{\"analytic_story\":[\"FIN7\",\"Qakbot\",\"CISA AA22-277A\",\"Qakbot\"],\"cis20\":[\"CIS 10\"],\"confidence\":80,\"impact\":70,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1059\",\"T1059.007\"],\"nist\":[\"DE.CM\"]}", annotations._all="CISA AA22-277A", annotations._all="Installation", annotations._all="FIN7", annotations._all="T1059.007", annotations._all="T1059", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Qakbot", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="FIN7", annotations.analytic_story="Qakbot", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Qakbot", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1059", annotations.mitre_attack="T1059.007", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:58", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749637.853744000", lastTime="2023-06-14T13:28:58", original_file_name="net1.exe", parent_process="net localgroup Administradores", parent_process_name="net.exe", process="C:\\Windows\\system32\\net1 localgroup Administradores", process_id="6740", process_name="net1.exe", risk_message="A non-standard parent process net.exe spawned child process net1.exe to execute command-line tool on ar-win-dc.attackrange.local.", risk_object="Administrator", risk_object_type="user", risk_score="56.0", savedsearch_description="The following analytic identifies a non-standard parent process (not matching CMD, PowerShell, or Explorer) spawning `ipconfig.exe` or `systeminfo.exe`. This particular behavior was seen in FIN7's JSSLoader .NET payload. This is also typically seen when an adversary is injected into another process performing different discovery techniques. This event stands out as a TTP since these tools are commonly executed with a shell application or Explorer parent, and not by another application. This TTP is a good indicator for an adversary gathering host information, but one possible false positive might be an automated tool used by a system administator.", user="Administrator" 1686749641, search_name="ESCU - Cmdline Tool Not Executed In CMD Shell - Rule", analyticstories="CISA AA22-277A", analyticstories="FIN7", analyticstories="Qakbot", annotations="{\"analytic_story\":[\"FIN7\",\"Qakbot\",\"CISA AA22-277A\",\"Qakbot\"],\"cis20\":[\"CIS 10\"],\"confidence\":80,\"impact\":70,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1059\",\"T1059.007\"],\"nist\":[\"DE.CM\"]}", annotations._all="CISA AA22-277A", annotations._all="Installation", annotations._all="FIN7", annotations._all="T1059.007", annotations._all="T1059", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Qakbot", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="FIN7", annotations.analytic_story="Qakbot", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Qakbot", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1059", annotations.mitre_attack="T1059.007", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:58", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749637.853744000", lastTime="2023-06-14T13:28:58", original_file_name="net1.exe", parent_process="net localgroup Administradores", parent_process_name="net.exe", process="C:\\Windows\\system32\\net1 localgroup Administradores", process_id="6740", process_name="net1.exe", risk_message="A non-standard parent process net.exe spawned child process net1.exe to execute command-line tool on ar-win-dc.attackrange.local.", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="56.0", savedsearch_description="The following analytic identifies a non-standard parent process (not matching CMD, PowerShell, or Explorer) spawning `ipconfig.exe` or `systeminfo.exe`. This particular behavior was seen in FIN7's JSSLoader .NET payload. This is also typically seen when an adversary is injected into another process performing different discovery techniques. This event stands out as a TTP since these tools are commonly executed with a shell application or Explorer parent, and not by another application. This TTP is a good indicator for an adversary gathering host information, but one possible false positive might be an automated tool used by a system administator.", user="Administrator" 1686749641, search_name="ESCU - Cmdline Tool Not Executed In CMD Shell - Rule", analyticstories="CISA AA22-277A", analyticstories="FIN7", analyticstories="Qakbot", annotations="{\"analytic_story\":[\"FIN7\",\"Qakbot\",\"CISA AA22-277A\",\"Qakbot\"],\"cis20\":[\"CIS 10\"],\"confidence\":80,\"impact\":70,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1059\",\"T1059.007\"],\"nist\":[\"DE.CM\"]}", annotations._all="CISA AA22-277A", annotations._all="Installation", annotations._all="FIN7", annotations._all="T1059.007", annotations._all="T1059", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Qakbot", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="FIN7", annotations.analytic_story="Qakbot", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Qakbot", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1059", annotations.mitre_attack="T1059.007", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:58", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749637.853744000", lastTime="2023-06-14T13:28:58", original_file_name="net1.exe", parent_process="net localgroup", parent_process_name="net.exe", process="C:\\Windows\\system32\\net1 localgroup", process_id="6392", process_name="net1.exe", risk_message="A non-standard parent process net.exe spawned child process net1.exe to execute command-line tool on ar-win-dc.attackrange.local.", risk_object="net1.exe", risk_object_type="other", risk_score="56.0", savedsearch_description="The following analytic identifies a non-standard parent process (not matching CMD, PowerShell, or Explorer) spawning `ipconfig.exe` or `systeminfo.exe`. This particular behavior was seen in FIN7's JSSLoader .NET payload. This is also typically seen when an adversary is injected into another process performing different discovery techniques. This event stands out as a TTP since these tools are commonly executed with a shell application or Explorer parent, and not by another application. This TTP is a good indicator for an adversary gathering host information, but one possible false positive might be an automated tool used by a system administator.", user="Administrator" 1686749641, search_name="ESCU - Cmdline Tool Not Executed In CMD Shell - Rule", analyticstories="CISA AA22-277A", analyticstories="FIN7", analyticstories="Qakbot", annotations="{\"analytic_story\":[\"FIN7\",\"Qakbot\",\"CISA AA22-277A\",\"Qakbot\"],\"cis20\":[\"CIS 10\"],\"confidence\":80,\"impact\":70,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1059\",\"T1059.007\"],\"nist\":[\"DE.CM\"]}", annotations._all="CISA AA22-277A", annotations._all="Installation", annotations._all="FIN7", annotations._all="T1059.007", annotations._all="T1059", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Qakbot", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="FIN7", annotations.analytic_story="Qakbot", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Qakbot", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1059", annotations.mitre_attack="T1059.007", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:58", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749637.853744000", lastTime="2023-06-14T13:28:58", original_file_name="net1.exe", parent_process="net localgroup", parent_process_name="net.exe", process="C:\\Windows\\system32\\net1 localgroup", process_id="6392", process_name="net1.exe", risk_message="A non-standard parent process net.exe spawned child process net1.exe to execute command-line tool on ar-win-dc.attackrange.local.", risk_object="net.exe", risk_object_type="other", risk_score="56.0", savedsearch_description="The following analytic identifies a non-standard parent process (not matching CMD, PowerShell, or Explorer) spawning `ipconfig.exe` or `systeminfo.exe`. This particular behavior was seen in FIN7's JSSLoader .NET payload. This is also typically seen when an adversary is injected into another process performing different discovery techniques. This event stands out as a TTP since these tools are commonly executed with a shell application or Explorer parent, and not by another application. This TTP is a good indicator for an adversary gathering host information, but one possible false positive might be an automated tool used by a system administator.", user="Administrator" 1686749641, search_name="ESCU - Cmdline Tool Not Executed In CMD Shell - Rule", analyticstories="CISA AA22-277A", analyticstories="FIN7", analyticstories="Qakbot", annotations="{\"analytic_story\":[\"FIN7\",\"Qakbot\",\"CISA AA22-277A\",\"Qakbot\"],\"cis20\":[\"CIS 10\"],\"confidence\":80,\"impact\":70,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1059\",\"T1059.007\"],\"nist\":[\"DE.CM\"]}", annotations._all="CISA AA22-277A", annotations._all="Installation", annotations._all="FIN7", annotations._all="T1059.007", annotations._all="T1059", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Qakbot", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="FIN7", annotations.analytic_story="Qakbot", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Qakbot", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1059", annotations.mitre_attack="T1059.007", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:58", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749637.853744000", lastTime="2023-06-14T13:28:58", original_file_name="net1.exe", parent_process="net localgroup", parent_process_name="net.exe", process="C:\\Windows\\system32\\net1 localgroup", process_id="6392", process_name="net1.exe", risk_message="A non-standard parent process net.exe spawned child process net1.exe to execute command-line tool on ar-win-dc.attackrange.local.", risk_object="Administrator", risk_object_type="user", risk_score="56.0", savedsearch_description="The following analytic identifies a non-standard parent process (not matching CMD, PowerShell, or Explorer) spawning `ipconfig.exe` or `systeminfo.exe`. This particular behavior was seen in FIN7's JSSLoader .NET payload. This is also typically seen when an adversary is injected into another process performing different discovery techniques. This event stands out as a TTP since these tools are commonly executed with a shell application or Explorer parent, and not by another application. This TTP is a good indicator for an adversary gathering host information, but one possible false positive might be an automated tool used by a system administator.", user="Administrator" 1686749641, search_name="ESCU - Cmdline Tool Not Executed In CMD Shell - Rule", analyticstories="CISA AA22-277A", analyticstories="FIN7", analyticstories="Qakbot", annotations="{\"analytic_story\":[\"FIN7\",\"Qakbot\",\"CISA AA22-277A\",\"Qakbot\"],\"cis20\":[\"CIS 10\"],\"confidence\":80,\"impact\":70,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1059\",\"T1059.007\"],\"nist\":[\"DE.CM\"]}", annotations._all="CISA AA22-277A", annotations._all="Installation", annotations._all="FIN7", annotations._all="T1059.007", annotations._all="T1059", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Qakbot", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="FIN7", annotations.analytic_story="Qakbot", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Qakbot", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1059", annotations.mitre_attack="T1059.007", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:58", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749637.853744000", lastTime="2023-06-14T13:28:58", original_file_name="net1.exe", parent_process="net localgroup", parent_process_name="net.exe", process="C:\\Windows\\system32\\net1 localgroup", process_id="6392", process_name="net1.exe", risk_message="A non-standard parent process net.exe spawned child process net1.exe to execute command-line tool on ar-win-dc.attackrange.local.", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="56.0", savedsearch_description="The following analytic identifies a non-standard parent process (not matching CMD, PowerShell, or Explorer) spawning `ipconfig.exe` or `systeminfo.exe`. This particular behavior was seen in FIN7's JSSLoader .NET payload. This is also typically seen when an adversary is injected into another process performing different discovery techniques. This event stands out as a TTP since these tools are commonly executed with a shell application or Explorer parent, and not by another application. This TTP is a good indicator for an adversary gathering host information, but one possible false positive might be an automated tool used by a system administator.", user="Administrator" 1686749641, search_name="ESCU - Cmdline Tool Not Executed In CMD Shell - Rule", analyticstories="CISA AA22-277A", analyticstories="FIN7", analyticstories="Qakbot", annotations="{\"analytic_story\":[\"FIN7\",\"Qakbot\",\"CISA AA22-277A\",\"Qakbot\"],\"cis20\":[\"CIS 10\"],\"confidence\":80,\"impact\":70,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1059\",\"T1059.007\"],\"nist\":[\"DE.CM\"]}", annotations._all="CISA AA22-277A", annotations._all="Installation", annotations._all="FIN7", annotations._all="T1059.007", annotations._all="T1059", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Qakbot", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="FIN7", annotations.analytic_story="Qakbot", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Qakbot", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1059", annotations.mitre_attack="T1059.007", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:56", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749637.853744000", lastTime="2023-06-14T13:28:56", original_file_name="unknown", parent_process="C:\\Windows\\System32\\net.exe", parent_process_name="net.exe", process="C:\\Windows\\system32\\net1 user Administrator /domain", process_id="0x63c", process_name="net1.exe", risk_message="A non-standard parent process net.exe spawned child process net1.exe to execute command-line tool on ar-win-dc.attackrange.local.", risk_object="net1.exe", risk_object_type="other", risk_score="56.0", savedsearch_description="The following analytic identifies a non-standard parent process (not matching CMD, PowerShell, or Explorer) spawning `ipconfig.exe` or `systeminfo.exe`. This particular behavior was seen in FIN7's JSSLoader .NET payload. This is also typically seen when an adversary is injected into another process performing different discovery techniques. This event stands out as a TTP since these tools are commonly executed with a shell application or Explorer parent, and not by another application. This TTP is a good indicator for an adversary gathering host information, but one possible false positive might be an automated tool used by a system administator.", user="Administrator" 1686749641, search_name="ESCU - Cmdline Tool Not Executed In CMD Shell - Rule", analyticstories="CISA AA22-277A", analyticstories="FIN7", analyticstories="Qakbot", annotations="{\"analytic_story\":[\"FIN7\",\"Qakbot\",\"CISA AA22-277A\",\"Qakbot\"],\"cis20\":[\"CIS 10\"],\"confidence\":80,\"impact\":70,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1059\",\"T1059.007\"],\"nist\":[\"DE.CM\"]}", annotations._all="CISA AA22-277A", annotations._all="Installation", annotations._all="FIN7", annotations._all="T1059.007", annotations._all="T1059", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Qakbot", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="FIN7", annotations.analytic_story="Qakbot", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Qakbot", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1059", annotations.mitre_attack="T1059.007", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:56", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749637.853744000", lastTime="2023-06-14T13:28:56", original_file_name="unknown", parent_process="C:\\Windows\\System32\\net.exe", parent_process_name="net.exe", process="C:\\Windows\\system32\\net1 user Administrator /domain", process_id="0x63c", process_name="net1.exe", risk_message="A non-standard parent process net.exe spawned child process net1.exe to execute command-line tool on ar-win-dc.attackrange.local.", risk_object="net.exe", risk_object_type="other", risk_score="56.0", savedsearch_description="The following analytic identifies a non-standard parent process (not matching CMD, PowerShell, or Explorer) spawning `ipconfig.exe` or `systeminfo.exe`. This particular behavior was seen in FIN7's JSSLoader .NET payload. This is also typically seen when an adversary is injected into another process performing different discovery techniques. This event stands out as a TTP since these tools are commonly executed with a shell application or Explorer parent, and not by another application. This TTP is a good indicator for an adversary gathering host information, but one possible false positive might be an automated tool used by a system administator.", user="Administrator" 1686749641, search_name="ESCU - Cmdline Tool Not Executed In CMD Shell - Rule", analyticstories="CISA AA22-277A", analyticstories="FIN7", analyticstories="Qakbot", annotations="{\"analytic_story\":[\"FIN7\",\"Qakbot\",\"CISA AA22-277A\",\"Qakbot\"],\"cis20\":[\"CIS 10\"],\"confidence\":80,\"impact\":70,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1059\",\"T1059.007\"],\"nist\":[\"DE.CM\"]}", annotations._all="CISA AA22-277A", annotations._all="Installation", annotations._all="FIN7", annotations._all="T1059.007", annotations._all="T1059", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Qakbot", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="FIN7", annotations.analytic_story="Qakbot", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Qakbot", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1059", annotations.mitre_attack="T1059.007", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:56", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749637.853744000", lastTime="2023-06-14T13:28:56", original_file_name="unknown", parent_process="C:\\Windows\\System32\\net.exe", parent_process_name="net.exe", process="C:\\Windows\\system32\\net1 user Administrator /domain", process_id="0x63c", process_name="net1.exe", risk_message="A non-standard parent process net.exe spawned child process net1.exe to execute command-line tool on ar-win-dc.attackrange.local.", risk_object="Administrator", risk_object_type="user", risk_score="56.0", savedsearch_description="The following analytic identifies a non-standard parent process (not matching CMD, PowerShell, or Explorer) spawning `ipconfig.exe` or `systeminfo.exe`. This particular behavior was seen in FIN7's JSSLoader .NET payload. This is also typically seen when an adversary is injected into another process performing different discovery techniques. This event stands out as a TTP since these tools are commonly executed with a shell application or Explorer parent, and not by another application. This TTP is a good indicator for an adversary gathering host information, but one possible false positive might be an automated tool used by a system administator.", user="Administrator" 1686749641, search_name="ESCU - Cmdline Tool Not Executed In CMD Shell - Rule", analyticstories="CISA AA22-277A", analyticstories="FIN7", analyticstories="Qakbot", annotations="{\"analytic_story\":[\"FIN7\",\"Qakbot\",\"CISA AA22-277A\",\"Qakbot\"],\"cis20\":[\"CIS 10\"],\"confidence\":80,\"impact\":70,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1059\",\"T1059.007\"],\"nist\":[\"DE.CM\"]}", annotations._all="CISA AA22-277A", annotations._all="Installation", annotations._all="FIN7", annotations._all="T1059.007", annotations._all="T1059", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Qakbot", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="FIN7", annotations.analytic_story="Qakbot", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Qakbot", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1059", annotations.mitre_attack="T1059.007", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:56", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749637.853744000", lastTime="2023-06-14T13:28:56", original_file_name="unknown", parent_process="C:\\Windows\\System32\\net.exe", parent_process_name="net.exe", process="C:\\Windows\\system32\\net1 user Administrator /domain", process_id="0x63c", process_name="net1.exe", risk_message="A non-standard parent process net.exe spawned child process net1.exe to execute command-line tool on ar-win-dc.attackrange.local.", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="56.0", savedsearch_description="The following analytic identifies a non-standard parent process (not matching CMD, PowerShell, or Explorer) spawning `ipconfig.exe` or `systeminfo.exe`. This particular behavior was seen in FIN7's JSSLoader .NET payload. This is also typically seen when an adversary is injected into another process performing different discovery techniques. This event stands out as a TTP since these tools are commonly executed with a shell application or Explorer parent, and not by another application. This TTP is a good indicator for an adversary gathering host information, but one possible false positive might be an automated tool used by a system administator.", user="Administrator" 1686749641, search_name="ESCU - Cmdline Tool Not Executed In CMD Shell - Rule", analyticstories="CISA AA22-277A", analyticstories="FIN7", analyticstories="Qakbot", annotations="{\"analytic_story\":[\"FIN7\",\"Qakbot\",\"CISA AA22-277A\",\"Qakbot\"],\"cis20\":[\"CIS 10\"],\"confidence\":80,\"impact\":70,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1059\",\"T1059.007\"],\"nist\":[\"DE.CM\"]}", annotations._all="CISA AA22-277A", annotations._all="Installation", annotations._all="FIN7", annotations._all="T1059.007", annotations._all="T1059", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Qakbot", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="FIN7", annotations.analytic_story="Qakbot", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Qakbot", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1059", annotations.mitre_attack="T1059.007", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:56", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749637.853744000", lastTime="2023-06-14T13:28:56", original_file_name="unknown", parent_process="C:\\Windows\\System32\\net.exe", parent_process_name="net.exe", process="C:\\Windows\\system32\\net1 user", process_id="0x1bc4", process_name="net1.exe", risk_message="A non-standard parent process net.exe spawned child process net1.exe to execute command-line tool on ar-win-dc.attackrange.local.", risk_object="net1.exe", risk_object_type="other", risk_score="56.0", savedsearch_description="The following analytic identifies a non-standard parent process (not matching CMD, PowerShell, or Explorer) spawning `ipconfig.exe` or `systeminfo.exe`. This particular behavior was seen in FIN7's JSSLoader .NET payload. This is also typically seen when an adversary is injected into another process performing different discovery techniques. This event stands out as a TTP since these tools are commonly executed with a shell application or Explorer parent, and not by another application. This TTP is a good indicator for an adversary gathering host information, but one possible false positive might be an automated tool used by a system administator.", user="Administrator" 1686749641, search_name="ESCU - Cmdline Tool Not Executed In CMD Shell - Rule", analyticstories="CISA AA22-277A", analyticstories="FIN7", analyticstories="Qakbot", annotations="{\"analytic_story\":[\"FIN7\",\"Qakbot\",\"CISA AA22-277A\",\"Qakbot\"],\"cis20\":[\"CIS 10\"],\"confidence\":80,\"impact\":70,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1059\",\"T1059.007\"],\"nist\":[\"DE.CM\"]}", annotations._all="CISA AA22-277A", annotations._all="Installation", annotations._all="FIN7", annotations._all="T1059.007", annotations._all="T1059", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Qakbot", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="FIN7", annotations.analytic_story="Qakbot", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Qakbot", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1059", annotations.mitre_attack="T1059.007", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:56", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749637.853744000", lastTime="2023-06-14T13:28:56", original_file_name="unknown", parent_process="C:\\Windows\\System32\\net.exe", parent_process_name="net.exe", process="C:\\Windows\\system32\\net1 user", process_id="0x1bc4", process_name="net1.exe", risk_message="A non-standard parent process net.exe spawned child process net1.exe to execute command-line tool on ar-win-dc.attackrange.local.", risk_object="net.exe", risk_object_type="other", risk_score="56.0", savedsearch_description="The following analytic identifies a non-standard parent process (not matching CMD, PowerShell, or Explorer) spawning `ipconfig.exe` or `systeminfo.exe`. This particular behavior was seen in FIN7's JSSLoader .NET payload. This is also typically seen when an adversary is injected into another process performing different discovery techniques. This event stands out as a TTP since these tools are commonly executed with a shell application or Explorer parent, and not by another application. This TTP is a good indicator for an adversary gathering host information, but one possible false positive might be an automated tool used by a system administator.", user="Administrator" 1686749641, search_name="ESCU - Cmdline Tool Not Executed In CMD Shell - Rule", analyticstories="CISA AA22-277A", analyticstories="FIN7", analyticstories="Qakbot", annotations="{\"analytic_story\":[\"FIN7\",\"Qakbot\",\"CISA AA22-277A\",\"Qakbot\"],\"cis20\":[\"CIS 10\"],\"confidence\":80,\"impact\":70,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1059\",\"T1059.007\"],\"nist\":[\"DE.CM\"]}", annotations._all="CISA AA22-277A", annotations._all="Installation", annotations._all="FIN7", annotations._all="T1059.007", annotations._all="T1059", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Qakbot", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="FIN7", annotations.analytic_story="Qakbot", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Qakbot", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1059", annotations.mitre_attack="T1059.007", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:56", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749637.853744000", lastTime="2023-06-14T13:28:56", original_file_name="unknown", parent_process="C:\\Windows\\System32\\net.exe", parent_process_name="net.exe", process="C:\\Windows\\system32\\net1 user", process_id="0x1bc4", process_name="net1.exe", risk_message="A non-standard parent process net.exe spawned child process net1.exe to execute command-line tool on ar-win-dc.attackrange.local.", risk_object="Administrator", risk_object_type="user", risk_score="56.0", savedsearch_description="The following analytic identifies a non-standard parent process (not matching CMD, PowerShell, or Explorer) spawning `ipconfig.exe` or `systeminfo.exe`. This particular behavior was seen in FIN7's JSSLoader .NET payload. This is also typically seen when an adversary is injected into another process performing different discovery techniques. This event stands out as a TTP since these tools are commonly executed with a shell application or Explorer parent, and not by another application. This TTP is a good indicator for an adversary gathering host information, but one possible false positive might be an automated tool used by a system administator.", user="Administrator" 1686749641, search_name="ESCU - Cmdline Tool Not Executed In CMD Shell - Rule", analyticstories="CISA AA22-277A", analyticstories="FIN7", analyticstories="Qakbot", annotations="{\"analytic_story\":[\"FIN7\",\"Qakbot\",\"CISA AA22-277A\",\"Qakbot\"],\"cis20\":[\"CIS 10\"],\"confidence\":80,\"impact\":70,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1059\",\"T1059.007\"],\"nist\":[\"DE.CM\"]}", annotations._all="CISA AA22-277A", annotations._all="Installation", annotations._all="FIN7", annotations._all="T1059.007", annotations._all="T1059", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Qakbot", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="FIN7", annotations.analytic_story="Qakbot", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Qakbot", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1059", annotations.mitre_attack="T1059.007", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:56", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749637.853744000", lastTime="2023-06-14T13:28:56", original_file_name="unknown", parent_process="C:\\Windows\\System32\\net.exe", parent_process_name="net.exe", process="C:\\Windows\\system32\\net1 user", process_id="0x1bc4", process_name="net1.exe", risk_message="A non-standard parent process net.exe spawned child process net1.exe to execute command-line tool on ar-win-dc.attackrange.local.", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="56.0", savedsearch_description="The following analytic identifies a non-standard parent process (not matching CMD, PowerShell, or Explorer) spawning `ipconfig.exe` or `systeminfo.exe`. This particular behavior was seen in FIN7's JSSLoader .NET payload. This is also typically seen when an adversary is injected into another process performing different discovery techniques. This event stands out as a TTP since these tools are commonly executed with a shell application or Explorer parent, and not by another application. This TTP is a good indicator for an adversary gathering host information, but one possible false positive might be an automated tool used by a system administator.", user="Administrator" 1686749641, search_name="ESCU - Cmdline Tool Not Executed In CMD Shell - Rule", analyticstories="CISA AA22-277A", analyticstories="FIN7", analyticstories="Qakbot", annotations="{\"analytic_story\":[\"FIN7\",\"Qakbot\",\"CISA AA22-277A\",\"Qakbot\"],\"cis20\":[\"CIS 10\"],\"confidence\":80,\"impact\":70,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1059\",\"T1059.007\"],\"nist\":[\"DE.CM\"]}", annotations._all="CISA AA22-277A", annotations._all="Installation", annotations._all="FIN7", annotations._all="T1059.007", annotations._all="T1059", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Qakbot", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="FIN7", annotations.analytic_story="Qakbot", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Qakbot", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1059", annotations.mitre_attack="T1059.007", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:58", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749637.853744000", lastTime="2023-06-14T13:28:58", original_file_name="unknown", parent_process="C:\\Windows\\System32\\net.exe", parent_process_name="net.exe", process="C:\\Windows\\system32\\net1 localgroup Administradores", process_id="0x1a54", process_name="net1.exe", risk_message="A non-standard parent process net.exe spawned child process net1.exe to execute command-line tool on ar-win-dc.attackrange.local.", risk_object="net1.exe", risk_object_type="other", risk_score="56.0", savedsearch_description="The following analytic identifies a non-standard parent process (not matching CMD, PowerShell, or Explorer) spawning `ipconfig.exe` or `systeminfo.exe`. This particular behavior was seen in FIN7's JSSLoader .NET payload. This is also typically seen when an adversary is injected into another process performing different discovery techniques. This event stands out as a TTP since these tools are commonly executed with a shell application or Explorer parent, and not by another application. This TTP is a good indicator for an adversary gathering host information, but one possible false positive might be an automated tool used by a system administator.", user="Administrator" 1686749641, search_name="ESCU - Cmdline Tool Not Executed In CMD Shell - Rule", analyticstories="CISA AA22-277A", analyticstories="FIN7", analyticstories="Qakbot", annotations="{\"analytic_story\":[\"FIN7\",\"Qakbot\",\"CISA AA22-277A\",\"Qakbot\"],\"cis20\":[\"CIS 10\"],\"confidence\":80,\"impact\":70,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1059\",\"T1059.007\"],\"nist\":[\"DE.CM\"]}", annotations._all="CISA AA22-277A", annotations._all="Installation", annotations._all="FIN7", annotations._all="T1059.007", annotations._all="T1059", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Qakbot", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="FIN7", annotations.analytic_story="Qakbot", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Qakbot", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1059", annotations.mitre_attack="T1059.007", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:58", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749637.853744000", lastTime="2023-06-14T13:28:58", original_file_name="unknown", parent_process="C:\\Windows\\System32\\net.exe", parent_process_name="net.exe", process="C:\\Windows\\system32\\net1 localgroup Administradores", process_id="0x1a54", process_name="net1.exe", risk_message="A non-standard parent process net.exe spawned child process net1.exe to execute command-line tool on ar-win-dc.attackrange.local.", risk_object="net.exe", risk_object_type="other", risk_score="56.0", savedsearch_description="The following analytic identifies a non-standard parent process (not matching CMD, PowerShell, or Explorer) spawning `ipconfig.exe` or `systeminfo.exe`. This particular behavior was seen in FIN7's JSSLoader .NET payload. This is also typically seen when an adversary is injected into another process performing different discovery techniques. This event stands out as a TTP since these tools are commonly executed with a shell application or Explorer parent, and not by another application. This TTP is a good indicator for an adversary gathering host information, but one possible false positive might be an automated tool used by a system administator.", user="Administrator" 1686749641, search_name="ESCU - Cmdline Tool Not Executed In CMD Shell - Rule", analyticstories="CISA AA22-277A", analyticstories="FIN7", analyticstories="Qakbot", annotations="{\"analytic_story\":[\"FIN7\",\"Qakbot\",\"CISA AA22-277A\",\"Qakbot\"],\"cis20\":[\"CIS 10\"],\"confidence\":80,\"impact\":70,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1059\",\"T1059.007\"],\"nist\":[\"DE.CM\"]}", annotations._all="CISA AA22-277A", annotations._all="Installation", annotations._all="FIN7", annotations._all="T1059.007", annotations._all="T1059", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Qakbot", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="FIN7", annotations.analytic_story="Qakbot", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Qakbot", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1059", annotations.mitre_attack="T1059.007", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:58", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749637.853744000", lastTime="2023-06-14T13:28:58", original_file_name="unknown", parent_process="C:\\Windows\\System32\\net.exe", parent_process_name="net.exe", process="C:\\Windows\\system32\\net1 localgroup Administradores", process_id="0x1a54", process_name="net1.exe", risk_message="A non-standard parent process net.exe spawned child process net1.exe to execute command-line tool on ar-win-dc.attackrange.local.", risk_object="Administrator", risk_object_type="user", risk_score="56.0", savedsearch_description="The following analytic identifies a non-standard parent process (not matching CMD, PowerShell, or Explorer) spawning `ipconfig.exe` or `systeminfo.exe`. This particular behavior was seen in FIN7's JSSLoader .NET payload. This is also typically seen when an adversary is injected into another process performing different discovery techniques. This event stands out as a TTP since these tools are commonly executed with a shell application or Explorer parent, and not by another application. This TTP is a good indicator for an adversary gathering host information, but one possible false positive might be an automated tool used by a system administator.", user="Administrator" 1686749641, search_name="ESCU - Cmdline Tool Not Executed In CMD Shell - Rule", analyticstories="CISA AA22-277A", analyticstories="FIN7", analyticstories="Qakbot", annotations="{\"analytic_story\":[\"FIN7\",\"Qakbot\",\"CISA AA22-277A\",\"Qakbot\"],\"cis20\":[\"CIS 10\"],\"confidence\":80,\"impact\":70,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1059\",\"T1059.007\"],\"nist\":[\"DE.CM\"]}", annotations._all="CISA AA22-277A", annotations._all="Installation", annotations._all="FIN7", annotations._all="T1059.007", annotations._all="T1059", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Qakbot", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="FIN7", annotations.analytic_story="Qakbot", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Qakbot", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1059", annotations.mitre_attack="T1059.007", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:58", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749637.853744000", lastTime="2023-06-14T13:28:58", original_file_name="unknown", parent_process="C:\\Windows\\System32\\net.exe", parent_process_name="net.exe", process="C:\\Windows\\system32\\net1 localgroup Administradores", process_id="0x1a54", process_name="net1.exe", risk_message="A non-standard parent process net.exe spawned child process net1.exe to execute command-line tool on ar-win-dc.attackrange.local.", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="56.0", savedsearch_description="The following analytic identifies a non-standard parent process (not matching CMD, PowerShell, or Explorer) spawning `ipconfig.exe` or `systeminfo.exe`. This particular behavior was seen in FIN7's JSSLoader .NET payload. This is also typically seen when an adversary is injected into another process performing different discovery techniques. This event stands out as a TTP since these tools are commonly executed with a shell application or Explorer parent, and not by another application. This TTP is a good indicator for an adversary gathering host information, but one possible false positive might be an automated tool used by a system administator.", user="Administrator" 1686749641, search_name="ESCU - Cmdline Tool Not Executed In CMD Shell - Rule", analyticstories="CISA AA22-277A", analyticstories="FIN7", analyticstories="Qakbot", annotations="{\"analytic_story\":[\"FIN7\",\"Qakbot\",\"CISA AA22-277A\",\"Qakbot\"],\"cis20\":[\"CIS 10\"],\"confidence\":80,\"impact\":70,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1059\",\"T1059.007\"],\"nist\":[\"DE.CM\"]}", annotations._all="CISA AA22-277A", annotations._all="Installation", annotations._all="FIN7", annotations._all="T1059.007", annotations._all="T1059", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Qakbot", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="FIN7", annotations.analytic_story="Qakbot", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Qakbot", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1059", annotations.mitre_attack="T1059.007", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:54", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749637.853744000", lastTime="2023-06-14T13:28:54", original_file_name="unknown", parent_process="C:\\Windows\\System32\\net.exe", parent_process_name="net.exe", process="C:\\Windows\\system32\\net1 share", process_id="0x1a2c", process_name="net1.exe", risk_message="A non-standard parent process net.exe spawned child process net1.exe to execute command-line tool on ar-win-dc.attackrange.local.", risk_object="net1.exe", risk_object_type="other", risk_score="56.0", savedsearch_description="The following analytic identifies a non-standard parent process (not matching CMD, PowerShell, or Explorer) spawning `ipconfig.exe` or `systeminfo.exe`. This particular behavior was seen in FIN7's JSSLoader .NET payload. This is also typically seen when an adversary is injected into another process performing different discovery techniques. This event stands out as a TTP since these tools are commonly executed with a shell application or Explorer parent, and not by another application. This TTP is a good indicator for an adversary gathering host information, but one possible false positive might be an automated tool used by a system administator.", user="Administrator" 1686749641, search_name="ESCU - Cmdline Tool Not Executed In CMD Shell - Rule", analyticstories="CISA AA22-277A", analyticstories="FIN7", analyticstories="Qakbot", annotations="{\"analytic_story\":[\"FIN7\",\"Qakbot\",\"CISA AA22-277A\",\"Qakbot\"],\"cis20\":[\"CIS 10\"],\"confidence\":80,\"impact\":70,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1059\",\"T1059.007\"],\"nist\":[\"DE.CM\"]}", annotations._all="CISA AA22-277A", annotations._all="Installation", annotations._all="FIN7", annotations._all="T1059.007", annotations._all="T1059", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Qakbot", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="FIN7", annotations.analytic_story="Qakbot", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Qakbot", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1059", annotations.mitre_attack="T1059.007", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:54", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749637.853744000", lastTime="2023-06-14T13:28:54", original_file_name="unknown", parent_process="C:\\Windows\\System32\\net.exe", parent_process_name="net.exe", process="C:\\Windows\\system32\\net1 share", process_id="0x1a2c", process_name="net1.exe", risk_message="A non-standard parent process net.exe spawned child process net1.exe to execute command-line tool on ar-win-dc.attackrange.local.", risk_object="net.exe", risk_object_type="other", risk_score="56.0", savedsearch_description="The following analytic identifies a non-standard parent process (not matching CMD, PowerShell, or Explorer) spawning `ipconfig.exe` or `systeminfo.exe`. This particular behavior was seen in FIN7's JSSLoader .NET payload. This is also typically seen when an adversary is injected into another process performing different discovery techniques. This event stands out as a TTP since these tools are commonly executed with a shell application or Explorer parent, and not by another application. This TTP is a good indicator for an adversary gathering host information, but one possible false positive might be an automated tool used by a system administator.", user="Administrator" 1686749641, search_name="ESCU - Cmdline Tool Not Executed In CMD Shell - Rule", analyticstories="CISA AA22-277A", analyticstories="FIN7", analyticstories="Qakbot", annotations="{\"analytic_story\":[\"FIN7\",\"Qakbot\",\"CISA AA22-277A\",\"Qakbot\"],\"cis20\":[\"CIS 10\"],\"confidence\":80,\"impact\":70,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1059\",\"T1059.007\"],\"nist\":[\"DE.CM\"]}", annotations._all="CISA AA22-277A", annotations._all="Installation", annotations._all="FIN7", annotations._all="T1059.007", annotations._all="T1059", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Qakbot", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="FIN7", annotations.analytic_story="Qakbot", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Qakbot", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1059", annotations.mitre_attack="T1059.007", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:54", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749637.853744000", lastTime="2023-06-14T13:28:54", original_file_name="unknown", parent_process="C:\\Windows\\System32\\net.exe", parent_process_name="net.exe", process="C:\\Windows\\system32\\net1 share", process_id="0x1a2c", process_name="net1.exe", risk_message="A non-standard parent process net.exe spawned child process net1.exe to execute command-line tool on ar-win-dc.attackrange.local.", risk_object="Administrator", risk_object_type="user", risk_score="56.0", savedsearch_description="The following analytic identifies a non-standard parent process (not matching CMD, PowerShell, or Explorer) spawning `ipconfig.exe` or `systeminfo.exe`. This particular behavior was seen in FIN7's JSSLoader .NET payload. This is also typically seen when an adversary is injected into another process performing different discovery techniques. This event stands out as a TTP since these tools are commonly executed with a shell application or Explorer parent, and not by another application. This TTP is a good indicator for an adversary gathering host information, but one possible false positive might be an automated tool used by a system administator.", user="Administrator" 1686749641, search_name="ESCU - Cmdline Tool Not Executed In CMD Shell - Rule", analyticstories="CISA AA22-277A", analyticstories="FIN7", analyticstories="Qakbot", annotations="{\"analytic_story\":[\"FIN7\",\"Qakbot\",\"CISA AA22-277A\",\"Qakbot\"],\"cis20\":[\"CIS 10\"],\"confidence\":80,\"impact\":70,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1059\",\"T1059.007\"],\"nist\":[\"DE.CM\"]}", annotations._all="CISA AA22-277A", annotations._all="Installation", annotations._all="FIN7", annotations._all="T1059.007", annotations._all="T1059", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Qakbot", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="FIN7", annotations.analytic_story="Qakbot", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Qakbot", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1059", annotations.mitre_attack="T1059.007", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:54", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749637.853744000", lastTime="2023-06-14T13:28:54", original_file_name="unknown", parent_process="C:\\Windows\\System32\\net.exe", parent_process_name="net.exe", process="C:\\Windows\\system32\\net1 share", process_id="0x1a2c", process_name="net1.exe", risk_message="A non-standard parent process net.exe spawned child process net1.exe to execute command-line tool on ar-win-dc.attackrange.local.", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="56.0", savedsearch_description="The following analytic identifies a non-standard parent process (not matching CMD, PowerShell, or Explorer) spawning `ipconfig.exe` or `systeminfo.exe`. This particular behavior was seen in FIN7's JSSLoader .NET payload. This is also typically seen when an adversary is injected into another process performing different discovery techniques. This event stands out as a TTP since these tools are commonly executed with a shell application or Explorer parent, and not by another application. This TTP is a good indicator for an adversary gathering host information, but one possible false positive might be an automated tool used by a system administator.", user="Administrator" 1686749641, search_name="ESCU - Cmdline Tool Not Executed In CMD Shell - Rule", analyticstories="CISA AA22-277A", analyticstories="FIN7", analyticstories="Qakbot", annotations="{\"analytic_story\":[\"FIN7\",\"Qakbot\",\"CISA AA22-277A\",\"Qakbot\"],\"cis20\":[\"CIS 10\"],\"confidence\":80,\"impact\":70,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1059\",\"T1059.007\"],\"nist\":[\"DE.CM\"]}", annotations._all="CISA AA22-277A", annotations._all="Installation", annotations._all="FIN7", annotations._all="T1059.007", annotations._all="T1059", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Qakbot", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="FIN7", annotations.analytic_story="Qakbot", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Qakbot", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1059", annotations.mitre_attack="T1059.007", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:58", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749637.853744000", lastTime="2023-06-14T13:28:58", original_file_name="unknown", parent_process="C:\\Windows\\System32\\net.exe", parent_process_name="net.exe", process="C:\\Windows\\system32\\net1 localgroup", process_id="0x18f8", process_name="net1.exe", risk_message="A non-standard parent process net.exe spawned child process net1.exe to execute command-line tool on ar-win-dc.attackrange.local.", risk_object="net1.exe", risk_object_type="other", risk_score="56.0", savedsearch_description="The following analytic identifies a non-standard parent process (not matching CMD, PowerShell, or Explorer) spawning `ipconfig.exe` or `systeminfo.exe`. This particular behavior was seen in FIN7's JSSLoader .NET payload. This is also typically seen when an adversary is injected into another process performing different discovery techniques. This event stands out as a TTP since these tools are commonly executed with a shell application or Explorer parent, and not by another application. This TTP is a good indicator for an adversary gathering host information, but one possible false positive might be an automated tool used by a system administator.", user="Administrator" 1686749641, search_name="ESCU - Cmdline Tool Not Executed In CMD Shell - Rule", analyticstories="CISA AA22-277A", analyticstories="FIN7", analyticstories="Qakbot", annotations="{\"analytic_story\":[\"FIN7\",\"Qakbot\",\"CISA AA22-277A\",\"Qakbot\"],\"cis20\":[\"CIS 10\"],\"confidence\":80,\"impact\":70,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1059\",\"T1059.007\"],\"nist\":[\"DE.CM\"]}", annotations._all="CISA AA22-277A", annotations._all="Installation", annotations._all="FIN7", annotations._all="T1059.007", annotations._all="T1059", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Qakbot", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="FIN7", annotations.analytic_story="Qakbot", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Qakbot", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1059", annotations.mitre_attack="T1059.007", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:58", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749637.853744000", lastTime="2023-06-14T13:28:58", original_file_name="unknown", parent_process="C:\\Windows\\System32\\net.exe", parent_process_name="net.exe", process="C:\\Windows\\system32\\net1 localgroup", process_id="0x18f8", process_name="net1.exe", risk_message="A non-standard parent process net.exe spawned child process net1.exe to execute command-line tool on ar-win-dc.attackrange.local.", risk_object="net.exe", risk_object_type="other", risk_score="56.0", savedsearch_description="The following analytic identifies a non-standard parent process (not matching CMD, PowerShell, or Explorer) spawning `ipconfig.exe` or `systeminfo.exe`. This particular behavior was seen in FIN7's JSSLoader .NET payload. This is also typically seen when an adversary is injected into another process performing different discovery techniques. This event stands out as a TTP since these tools are commonly executed with a shell application or Explorer parent, and not by another application. This TTP is a good indicator for an adversary gathering host information, but one possible false positive might be an automated tool used by a system administator.", user="Administrator" 1686749641, search_name="ESCU - Cmdline Tool Not Executed In CMD Shell - Rule", analyticstories="CISA AA22-277A", analyticstories="FIN7", analyticstories="Qakbot", annotations="{\"analytic_story\":[\"FIN7\",\"Qakbot\",\"CISA AA22-277A\",\"Qakbot\"],\"cis20\":[\"CIS 10\"],\"confidence\":80,\"impact\":70,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1059\",\"T1059.007\"],\"nist\":[\"DE.CM\"]}", annotations._all="CISA AA22-277A", annotations._all="Installation", annotations._all="FIN7", annotations._all="T1059.007", annotations._all="T1059", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Qakbot", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="FIN7", annotations.analytic_story="Qakbot", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Qakbot", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1059", annotations.mitre_attack="T1059.007", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:58", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749637.853744000", lastTime="2023-06-14T13:28:58", original_file_name="unknown", parent_process="C:\\Windows\\System32\\net.exe", parent_process_name="net.exe", process="C:\\Windows\\system32\\net1 localgroup", process_id="0x18f8", process_name="net1.exe", risk_message="A non-standard parent process net.exe spawned child process net1.exe to execute command-line tool on ar-win-dc.attackrange.local.", risk_object="Administrator", risk_object_type="user", risk_score="56.0", savedsearch_description="The following analytic identifies a non-standard parent process (not matching CMD, PowerShell, or Explorer) spawning `ipconfig.exe` or `systeminfo.exe`. This particular behavior was seen in FIN7's JSSLoader .NET payload. This is also typically seen when an adversary is injected into another process performing different discovery techniques. This event stands out as a TTP since these tools are commonly executed with a shell application or Explorer parent, and not by another application. This TTP is a good indicator for an adversary gathering host information, but one possible false positive might be an automated tool used by a system administator.", user="Administrator" 1686749641, search_name="ESCU - Cmdline Tool Not Executed In CMD Shell - Rule", analyticstories="CISA AA22-277A", analyticstories="FIN7", analyticstories="Qakbot", annotations="{\"analytic_story\":[\"FIN7\",\"Qakbot\",\"CISA AA22-277A\",\"Qakbot\"],\"cis20\":[\"CIS 10\"],\"confidence\":80,\"impact\":70,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1059\",\"T1059.007\"],\"nist\":[\"DE.CM\"]}", annotations._all="CISA AA22-277A", annotations._all="Installation", annotations._all="FIN7", annotations._all="T1059.007", annotations._all="T1059", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Qakbot", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="FIN7", annotations.analytic_story="Qakbot", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Qakbot", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1059", annotations.mitre_attack="T1059.007", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:58", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749637.853744000", lastTime="2023-06-14T13:28:58", original_file_name="unknown", parent_process="C:\\Windows\\System32\\net.exe", parent_process_name="net.exe", process="C:\\Windows\\system32\\net1 localgroup", process_id="0x18f8", process_name="net1.exe", risk_message="A non-standard parent process net.exe spawned child process net1.exe to execute command-line tool on ar-win-dc.attackrange.local.", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="56.0", savedsearch_description="The following analytic identifies a non-standard parent process (not matching CMD, PowerShell, or Explorer) spawning `ipconfig.exe` or `systeminfo.exe`. This particular behavior was seen in FIN7's JSSLoader .NET payload. This is also typically seen when an adversary is injected into another process performing different discovery techniques. This event stands out as a TTP since these tools are commonly executed with a shell application or Explorer parent, and not by another application. This TTP is a good indicator for an adversary gathering host information, but one possible false positive might be an automated tool used by a system administator.", user="Administrator" 1686749641, search_name="ESCU - Cmdline Tool Not Executed In CMD Shell - Rule", analyticstories="CISA AA22-277A", analyticstories="FIN7", analyticstories="Qakbot", annotations="{\"analytic_story\":[\"FIN7\",\"Qakbot\",\"CISA AA22-277A\",\"Qakbot\"],\"cis20\":[\"CIS 10\"],\"confidence\":80,\"impact\":70,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1059\",\"T1059.007\"],\"nist\":[\"DE.CM\"]}", annotations._all="CISA AA22-277A", annotations._all="Installation", annotations._all="FIN7", annotations._all="T1059.007", annotations._all="T1059", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Qakbot", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="FIN7", annotations.analytic_story="Qakbot", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Qakbot", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1059", annotations.mitre_attack="T1059.007", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:58", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749637.853744000", lastTime="2023-06-14T13:28:58", original_file_name="unknown", parent_process="C:\\Windows\\System32\\net.exe", parent_process_name="net.exe", process="C:\\Windows\\system32\\net1 localgroup Administrators", process_id="0x1614", process_name="net1.exe", risk_message="A non-standard parent process net.exe spawned child process net1.exe to execute command-line tool on ar-win-dc.attackrange.local.", risk_object="net1.exe", risk_object_type="other", risk_score="56.0", savedsearch_description="The following analytic identifies a non-standard parent process (not matching CMD, PowerShell, or Explorer) spawning `ipconfig.exe` or `systeminfo.exe`. This particular behavior was seen in FIN7's JSSLoader .NET payload. This is also typically seen when an adversary is injected into another process performing different discovery techniques. This event stands out as a TTP since these tools are commonly executed with a shell application or Explorer parent, and not by another application. This TTP is a good indicator for an adversary gathering host information, but one possible false positive might be an automated tool used by a system administator.", user="Administrator" 1686749641, search_name="ESCU - Cmdline Tool Not Executed In CMD Shell - Rule", analyticstories="CISA AA22-277A", analyticstories="FIN7", analyticstories="Qakbot", annotations="{\"analytic_story\":[\"FIN7\",\"Qakbot\",\"CISA AA22-277A\",\"Qakbot\"],\"cis20\":[\"CIS 10\"],\"confidence\":80,\"impact\":70,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1059\",\"T1059.007\"],\"nist\":[\"DE.CM\"]}", annotations._all="CISA AA22-277A", annotations._all="Installation", annotations._all="FIN7", annotations._all="T1059.007", annotations._all="T1059", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Qakbot", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="FIN7", annotations.analytic_story="Qakbot", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Qakbot", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1059", annotations.mitre_attack="T1059.007", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:58", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749637.853744000", lastTime="2023-06-14T13:28:58", original_file_name="unknown", parent_process="C:\\Windows\\System32\\net.exe", parent_process_name="net.exe", process="C:\\Windows\\system32\\net1 localgroup Administrators", process_id="0x1614", process_name="net1.exe", risk_message="A non-standard parent process net.exe spawned child process net1.exe to execute command-line tool on ar-win-dc.attackrange.local.", risk_object="net.exe", risk_object_type="other", risk_score="56.0", savedsearch_description="The following analytic identifies a non-standard parent process (not matching CMD, PowerShell, or Explorer) spawning `ipconfig.exe` or `systeminfo.exe`. This particular behavior was seen in FIN7's JSSLoader .NET payload. This is also typically seen when an adversary is injected into another process performing different discovery techniques. This event stands out as a TTP since these tools are commonly executed with a shell application or Explorer parent, and not by another application. This TTP is a good indicator for an adversary gathering host information, but one possible false positive might be an automated tool used by a system administator.", user="Administrator" 1686749641, search_name="ESCU - Cmdline Tool Not Executed In CMD Shell - Rule", analyticstories="CISA AA22-277A", analyticstories="FIN7", analyticstories="Qakbot", annotations="{\"analytic_story\":[\"FIN7\",\"Qakbot\",\"CISA AA22-277A\",\"Qakbot\"],\"cis20\":[\"CIS 10\"],\"confidence\":80,\"impact\":70,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1059\",\"T1059.007\"],\"nist\":[\"DE.CM\"]}", annotations._all="CISA AA22-277A", annotations._all="Installation", annotations._all="FIN7", annotations._all="T1059.007", annotations._all="T1059", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Qakbot", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="FIN7", annotations.analytic_story="Qakbot", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Qakbot", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1059", annotations.mitre_attack="T1059.007", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:58", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749637.853744000", lastTime="2023-06-14T13:28:58", original_file_name="unknown", parent_process="C:\\Windows\\System32\\net.exe", parent_process_name="net.exe", process="C:\\Windows\\system32\\net1 localgroup Administrators", process_id="0x1614", process_name="net1.exe", risk_message="A non-standard parent process net.exe spawned child process net1.exe to execute command-line tool on ar-win-dc.attackrange.local.", risk_object="Administrator", risk_object_type="user", risk_score="56.0", savedsearch_description="The following analytic identifies a non-standard parent process (not matching CMD, PowerShell, or Explorer) spawning `ipconfig.exe` or `systeminfo.exe`. This particular behavior was seen in FIN7's JSSLoader .NET payload. This is also typically seen when an adversary is injected into another process performing different discovery techniques. This event stands out as a TTP since these tools are commonly executed with a shell application or Explorer parent, and not by another application. This TTP is a good indicator for an adversary gathering host information, but one possible false positive might be an automated tool used by a system administator.", user="Administrator" 1686749641, search_name="ESCU - Cmdline Tool Not Executed In CMD Shell - Rule", analyticstories="CISA AA22-277A", analyticstories="FIN7", analyticstories="Qakbot", annotations="{\"analytic_story\":[\"FIN7\",\"Qakbot\",\"CISA AA22-277A\",\"Qakbot\"],\"cis20\":[\"CIS 10\"],\"confidence\":80,\"impact\":70,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1059\",\"T1059.007\"],\"nist\":[\"DE.CM\"]}", annotations._all="CISA AA22-277A", annotations._all="Installation", annotations._all="FIN7", annotations._all="T1059.007", annotations._all="T1059", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Qakbot", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="FIN7", annotations.analytic_story="Qakbot", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Qakbot", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1059", annotations.mitre_attack="T1059.007", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:58", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749637.853744000", lastTime="2023-06-14T13:28:58", original_file_name="unknown", parent_process="C:\\Windows\\System32\\net.exe", parent_process_name="net.exe", process="C:\\Windows\\system32\\net1 localgroup Administrators", process_id="0x1614", process_name="net1.exe", risk_message="A non-standard parent process net.exe spawned child process net1.exe to execute command-line tool on ar-win-dc.attackrange.local.", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="56.0", savedsearch_description="The following analytic identifies a non-standard parent process (not matching CMD, PowerShell, or Explorer) spawning `ipconfig.exe` or `systeminfo.exe`. This particular behavior was seen in FIN7's JSSLoader .NET payload. This is also typically seen when an adversary is injected into another process performing different discovery techniques. This event stands out as a TTP since these tools are commonly executed with a shell application or Explorer parent, and not by another application. This TTP is a good indicator for an adversary gathering host information, but one possible false positive might be an automated tool used by a system administator.", user="Administrator" 1686749641, search_name="ESCU - Cmdline Tool Not Executed In CMD Shell - Rule", analyticstories="CISA AA22-277A", analyticstories="FIN7", analyticstories="Qakbot", annotations="{\"analytic_story\":[\"FIN7\",\"Qakbot\",\"CISA AA22-277A\",\"Qakbot\"],\"cis20\":[\"CIS 10\"],\"confidence\":80,\"impact\":70,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1059\",\"T1059.007\"],\"nist\":[\"DE.CM\"]}", annotations._all="CISA AA22-277A", annotations._all="Installation", annotations._all="FIN7", annotations._all="T1059.007", annotations._all="T1059", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Qakbot", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="FIN7", annotations.analytic_story="Qakbot", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Qakbot", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1059", annotations.mitre_attack="T1059.007", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:56", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749637.853744000", lastTime="2023-06-14T13:28:56", original_file_name="unknown", parent_process="C:\\Windows\\System32\\net.exe", parent_process_name="net.exe", process="C:\\Windows\\system32\\net1 user Administrator", process_id="0x1520", process_name="net1.exe", risk_message="A non-standard parent process net.exe spawned child process net1.exe to execute command-line tool on ar-win-dc.attackrange.local.", risk_object="net1.exe", risk_object_type="other", risk_score="56.0", savedsearch_description="The following analytic identifies a non-standard parent process (not matching CMD, PowerShell, or Explorer) spawning `ipconfig.exe` or `systeminfo.exe`. This particular behavior was seen in FIN7's JSSLoader .NET payload. This is also typically seen when an adversary is injected into another process performing different discovery techniques. This event stands out as a TTP since these tools are commonly executed with a shell application or Explorer parent, and not by another application. This TTP is a good indicator for an adversary gathering host information, but one possible false positive might be an automated tool used by a system administator.", user="Administrator" 1686749641, search_name="ESCU - Cmdline Tool Not Executed In CMD Shell - Rule", analyticstories="CISA AA22-277A", analyticstories="FIN7", analyticstories="Qakbot", annotations="{\"analytic_story\":[\"FIN7\",\"Qakbot\",\"CISA AA22-277A\",\"Qakbot\"],\"cis20\":[\"CIS 10\"],\"confidence\":80,\"impact\":70,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1059\",\"T1059.007\"],\"nist\":[\"DE.CM\"]}", annotations._all="CISA AA22-277A", annotations._all="Installation", annotations._all="FIN7", annotations._all="T1059.007", annotations._all="T1059", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Qakbot", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="FIN7", annotations.analytic_story="Qakbot", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Qakbot", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1059", annotations.mitre_attack="T1059.007", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:56", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749637.853744000", lastTime="2023-06-14T13:28:56", original_file_name="unknown", parent_process="C:\\Windows\\System32\\net.exe", parent_process_name="net.exe", process="C:\\Windows\\system32\\net1 user Administrator", process_id="0x1520", process_name="net1.exe", risk_message="A non-standard parent process net.exe spawned child process net1.exe to execute command-line tool on ar-win-dc.attackrange.local.", risk_object="net.exe", risk_object_type="other", risk_score="56.0", savedsearch_description="The following analytic identifies a non-standard parent process (not matching CMD, PowerShell, or Explorer) spawning `ipconfig.exe` or `systeminfo.exe`. This particular behavior was seen in FIN7's JSSLoader .NET payload. This is also typically seen when an adversary is injected into another process performing different discovery techniques. This event stands out as a TTP since these tools are commonly executed with a shell application or Explorer parent, and not by another application. This TTP is a good indicator for an adversary gathering host information, but one possible false positive might be an automated tool used by a system administator.", user="Administrator" 1686749641, search_name="ESCU - Cmdline Tool Not Executed In CMD Shell - Rule", analyticstories="CISA AA22-277A", analyticstories="FIN7", analyticstories="Qakbot", annotations="{\"analytic_story\":[\"FIN7\",\"Qakbot\",\"CISA AA22-277A\",\"Qakbot\"],\"cis20\":[\"CIS 10\"],\"confidence\":80,\"impact\":70,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1059\",\"T1059.007\"],\"nist\":[\"DE.CM\"]}", annotations._all="CISA AA22-277A", annotations._all="Installation", annotations._all="FIN7", annotations._all="T1059.007", annotations._all="T1059", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Qakbot", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="FIN7", annotations.analytic_story="Qakbot", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Qakbot", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1059", annotations.mitre_attack="T1059.007", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:56", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749637.853744000", lastTime="2023-06-14T13:28:56", original_file_name="unknown", parent_process="C:\\Windows\\System32\\net.exe", parent_process_name="net.exe", process="C:\\Windows\\system32\\net1 user Administrator", process_id="0x1520", process_name="net1.exe", risk_message="A non-standard parent process net.exe spawned child process net1.exe to execute command-line tool on ar-win-dc.attackrange.local.", risk_object="Administrator", risk_object_type="user", risk_score="56.0", savedsearch_description="The following analytic identifies a non-standard parent process (not matching CMD, PowerShell, or Explorer) spawning `ipconfig.exe` or `systeminfo.exe`. This particular behavior was seen in FIN7's JSSLoader .NET payload. This is also typically seen when an adversary is injected into another process performing different discovery techniques. This event stands out as a TTP since these tools are commonly executed with a shell application or Explorer parent, and not by another application. This TTP is a good indicator for an adversary gathering host information, but one possible false positive might be an automated tool used by a system administator.", user="Administrator" 1686749641, search_name="ESCU - Cmdline Tool Not Executed In CMD Shell - Rule", analyticstories="CISA AA22-277A", analyticstories="FIN7", analyticstories="Qakbot", annotations="{\"analytic_story\":[\"FIN7\",\"Qakbot\",\"CISA AA22-277A\",\"Qakbot\"],\"cis20\":[\"CIS 10\"],\"confidence\":80,\"impact\":70,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1059\",\"T1059.007\"],\"nist\":[\"DE.CM\"]}", annotations._all="CISA AA22-277A", annotations._all="Installation", annotations._all="FIN7", annotations._all="T1059.007", annotations._all="T1059", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Qakbot", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="FIN7", annotations.analytic_story="Qakbot", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Qakbot", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1059", annotations.mitre_attack="T1059.007", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:56", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749637.853744000", lastTime="2023-06-14T13:28:56", original_file_name="unknown", parent_process="C:\\Windows\\System32\\net.exe", parent_process_name="net.exe", process="C:\\Windows\\system32\\net1 user Administrator", process_id="0x1520", process_name="net1.exe", risk_message="A non-standard parent process net.exe spawned child process net1.exe to execute command-line tool on ar-win-dc.attackrange.local.", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="56.0", savedsearch_description="The following analytic identifies a non-standard parent process (not matching CMD, PowerShell, or Explorer) spawning `ipconfig.exe` or `systeminfo.exe`. This particular behavior was seen in FIN7's JSSLoader .NET payload. This is also typically seen when an adversary is injected into another process performing different discovery techniques. This event stands out as a TTP since these tools are commonly executed with a shell application or Explorer parent, and not by another application. This TTP is a good indicator for an adversary gathering host information, but one possible false positive might be an automated tool used by a system administator.", user="Administrator" 1686749632, search_name="ESCU - Windows ClipBoard Data via Get-ClipBoard - Rule", Computer="ar-win-dc.attackrange.local", EventCode="4104", ScriptBlockText="Get-Clipboard", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1115\"],\"nist\":[\"DE.AE\"]}", annotations._all="Exploitation", annotations._all="DE.AE", annotations._all="Windows Post-Exploitation", annotations._all="T1115", annotations._all="CIS 10", annotations._all="Prestige Ransomware", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1115", annotations.nist="DE.AE", count="1", firstTime="2023-06-14T13:28:59", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749630.458864000", lastTime="2023-06-14T13:28:59", risk_message="powershell script Get-Clipboard execute Get-Clipboard commandlet in $dest$", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="25.0", savedsearch_description="The following analytic identifies a powershell script command to retrieve clipboard data. This technique was seen in several post exploitation tools like WINPEAS to steal sensitive information that was saved in clipboard. Using the Get-Clipboard powershell commandlet, adversaries can be able collect data stored in clipboard that might be a copied user name, password or other sensitive information.", user_id="'S-1-5-21-647039874-1738661239-2692048096-500'" 1686749628, search_name="ESCU - Windows Private Keys Discovery - Rule", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1552.004\",\"T1552\"],\"nist\":[\"DE.AE\"]}", annotations._all="T1552.004", annotations._all="Prestige Ransomware", annotations._all="CIS 10", annotations._all="Exploitation", annotations._all="T1552", annotations._all="Windows Post-Exploitation", annotations._all="DE.AE", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1552.004", annotations.mitre_attack="T1552", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:29:27", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749620.074627000", lastTime="2023-06-14T13:29:27", original_file_name="unknown", parent_process="C:\\Windows\\System32\\cmd.exe", parent_process_guid="null", parent_process_name="cmd.exe", process="C:\\Windows\\system32\\cmd.exe /S /D /c\" dir /s/b /A:-D RDCMan.settings == *.rdg == SCClient.exe == *_history == .sudo_as_admin_successful == .profile == *bashrc == httpd.conf == *.plan == .htpasswd == .git-credentials == *.rhosts == hosts.equiv == Dockerfile == docker-compose.yml == appcmd.exe == TypedURLs == TypedURLsTime == History == Bookmarks == Cookies == \"Login Data\" == places.sqlite == key3.db == key4.db == credentials == credentials.db == access_tokens.db == accessTokens.json == legacy_credentials == azureProfile.json == unattend.txt == access.log == error.log == *.gpg == *.pgp == *config*.php == elasticsearch.y*ml == kibana.y*ml == *.p12 == *.der == *.csr == *.cer == known_hosts == id_rsa == id_dsa == *.ovpn == anaconda-ks.cfg == hostapd.conf == rsyncd.conf == cesi.conf == supervisord.conf == tomcat-users.xml == *.kdbx == KeePass.config == Ntds.dit == SAM == SYSTEM == FreeSSHDservice.ini == sysprep.inf == sysprep.xml == unattend.xml == unattended.xml == *vnc*.ini == *vnc*.c*nf* == *vnc*.txt == *vnc*.xml == groups.xml == services.xml == scheduledtasks.xml == printers.xml == drives.xml == datasources.xml == php.ini == https.conf == https-xampp.conf == httpd.conf == my.ini == my.cnf == access.log == error.log == server.xml == SiteList.xml == ConsoleHost_history.txt == setupinfo == setupinfo.bak 2>nul\"", process_guid="null", process_id="0x1908", process_name="cmd.exe", risk_message="a process with commandline C:\\Windows\\system32\\cmd.exe /S /D /c\" dir /s/b /A:-D RDCMan.settings == *.rdg == SCClient.exe == *_history == .sudo_as_admin_successful == .profile == *bashrc == httpd.conf == *.plan == .htpasswd == .git-credentials == *.rhosts == hosts.equiv == Dockerfile == docker-compose.yml == appcmd.exe == TypedURLs == TypedURLsTime == History == Bookmarks == Cookies == \"Login Data\" == places.sqlite == key3.db == key4.db == credentials == credentials.db == access_tokens.db == accessTokens.json == legacy_credentials == azureProfile.json == unattend.txt == access.log == error.log == *.gpg == *.pgp == *config*.php == elasticsearch.y*ml == kibana.y*ml == *.p12 == *.der == *.csr == *.cer == known_hosts == id_rsa == id_dsa == *.ovpn == anaconda-ks.cfg == hostapd.conf == rsyncd.conf == cesi.conf == supervisord.conf == tomcat-users.xml == *.kdbx == KeePass.config == Ntds.dit == SAM == SYSTEM == FreeSSHDservice.ini == sysprep.inf == sysprep.xml == unattend.xml == unattended.xml == *vnc*.ini == *vnc*.c*nf* == *vnc*.txt == *vnc*.xml == groups.xml == services.xml == scheduledtasks.xml == printers.xml == drives.xml == datasources.xml == php.ini == https.conf == https-xampp.conf == httpd.conf == my.ini == my.cnf == access.log == error.log == server.xml == SiteList.xml == ConsoleHost_history.txt == setupinfo == setupinfo.bak 2>nul\" that can retrieve information related to private keys in ar-win-dc.attackrange.local", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="25.0", savedsearch_description="The following analytic identifies a process command line that retrieves information related to private keys files. This technique was seen in several post exploitation tools like winpeas that are being used by Ransomware Prestige to search for private key certificates on the compromised host for insecurely stored credentials. This files can be used by adversaries to gain privileges, persistence or remote service authentication to collect more sensitive information. Some private keys required password for operation, so in this case adversaries may need to have that passphrase either via keylogging or brute force attack.", user="Administrator" 1686749628, search_name="ESCU - Windows Private Keys Discovery - Rule", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1552.004\",\"T1552\"],\"nist\":[\"DE.AE\"]}", annotations._all="T1552.004", annotations._all="Prestige Ransomware", annotations._all="CIS 10", annotations._all="Exploitation", annotations._all="T1552", annotations._all="Windows Post-Exploitation", annotations._all="DE.AE", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1552.004", annotations.mitre_attack="T1552", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:29:27", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749620.074627000", lastTime="2023-06-14T13:29:27", original_file_name="Cmd.Exe", parent_process="\"cmd.exe\" /s /k pushd \"C:\\Temp\"", parent_process_guid="{953948C6-BA8E-6489-C200-00000000F902}", parent_process_name="cmd.exe", process="C:\\Windows\\system32\\cmd.exe /S /D /c\" dir /s/b /A:-D RDCMan.settings == *.rdg == SCClient.exe == *_history == .sudo_as_admin_successful == .profile == *bashrc == httpd.conf == *.plan == .htpasswd == .git-credentials == *.rhosts == hosts.equiv == Dockerfile == docker-compose.yml == appcmd.exe == TypedURLs == TypedURLsTime == History == Bookmarks == Cookies == \"Login Data\" == places.sqlite == key3.db == key4.db == credentials == credentials.db == access_tokens.db == accessTokens.json == legacy_credentials == azureProfile.json == unattend.txt == access.log == error.log == *.gpg == *.pgp == *config*.php == elasticsearch.y*ml == kibana.y*ml == *.p12 == *.der == *.csr == *.cer == known_hosts == id_rsa == id_dsa == *.ovpn == anaconda-ks.cfg == hostapd.conf == rsyncd.conf == cesi.conf == supervisord.conf == tomcat-users.xml == *.kdbx == KeePass.config == Ntds.dit == SAM == SYSTEM == FreeSSHDservice.ini == sysprep.inf == sysprep.xml == unattend.xml == unattended.xml == *vnc*.ini == *vnc*.c*nf* == *vnc*.txt == *vnc*.xml == groups.xml == services.xml == scheduledtasks.xml == printers.xml == drives.xml == datasources.xml == php.ini == https.conf == https-xampp.conf == httpd.conf == my.ini == my.cnf == access.log == error.log == server.xml == SiteList.xml == ConsoleHost_history.txt == setupinfo == setupinfo.bak 2>nul\"", process_guid="{953948C6-C0B7-6489-CB18-00000000F902}", process_id="6408", process_name="cmd.exe", risk_message="a process with commandline C:\\Windows\\system32\\cmd.exe /S /D /c\" dir /s/b /A:-D RDCMan.settings == *.rdg == SCClient.exe == *_history == .sudo_as_admin_successful == .profile == *bashrc == httpd.conf == *.plan == .htpasswd == .git-credentials == *.rhosts == hosts.equiv == Dockerfile == docker-compose.yml == appcmd.exe == TypedURLs == TypedURLsTime == History == Bookmarks == Cookies == \"Login Data\" == places.sqlite == key3.db == key4.db == credentials == credentials.db == access_tokens.db == accessTokens.json == legacy_credentials == azureProfile.json == unattend.txt == access.log == error.log == *.gpg == *.pgp == *config*.php == elasticsearch.y*ml == kibana.y*ml == *.p12 == *.der == *.csr == *.cer == known_hosts == id_rsa == id_dsa == *.ovpn == anaconda-ks.cfg == hostapd.conf == rsyncd.conf == cesi.conf == supervisord.conf == tomcat-users.xml == *.kdbx == KeePass.config == Ntds.dit == SAM == SYSTEM == FreeSSHDservice.ini == sysprep.inf == sysprep.xml == unattend.xml == unattended.xml == *vnc*.ini == *vnc*.c*nf* == *vnc*.txt == *vnc*.xml == groups.xml == services.xml == scheduledtasks.xml == printers.xml == drives.xml == datasources.xml == php.ini == https.conf == https-xampp.conf == httpd.conf == my.ini == my.cnf == access.log == error.log == server.xml == SiteList.xml == ConsoleHost_history.txt == setupinfo == setupinfo.bak 2>nul\" that can retrieve information related to private keys in ar-win-dc.attackrange.local", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="25.0", savedsearch_description="The following analytic identifies a process command line that retrieves information related to private keys files. This technique was seen in several post exploitation tools like winpeas that are being used by Ransomware Prestige to search for private key certificates on the compromised host for insecurely stored credentials. This files can be used by adversaries to gain privileges, persistence or remote service authentication to collect more sensitive information. Some private keys required password for operation, so in this case adversaries may need to have that passphrase either via keylogging or brute force attack.", user="Administrator" 1686749607, search_name="ESCU - Windows Security Support Provider Reg Query - Rule", analyticstories="Prestige Ransomware", analyticstories="Sneaky Active Directory Persistence Tricks", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\",\"Sneaky Active Directory Persistence Tricks\"],\"cis20\":[\"CIS 10\"],\"confidence\":30,\"impact\":30,\"kill_chain_phases\":[\"Installation\",\"Exploitation\"],\"mitre_attack\":[\"T1547.005\",\"T1547\"],\"nist\":[\"DE.AE\"]}", annotations._all="Installation", annotations._all="Prestige Ransomware", annotations._all="Sneaky Active Directory Persistence Tricks", annotations._all="CIS 10", annotations._all="T1547", annotations._all="Windows Post-Exploitation", annotations._all="Exploitation", annotations._all="T1547.005", annotations._all="DE.AE", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.analytic_story="Sneaky Active Directory Persistence Tricks", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1547.005", annotations.mitre_attack="T1547", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:50", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749599.585986000", lastTime="2023-06-14T13:28:50", original_file_name="unknown", parent_process="C:\\Windows\\System32\\cmd.exe", parent_process_guid="null", parent_process_name="cmd.exe", process="C:\\Windows\\System32\\reg.exe QUERY \"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\LSA\" /v RunAsPPL", process_guid="null", process_id="0xed4", process_name="reg.exe", risk_message="process with reg query command line C:\\Windows\\System32\\reg.exe QUERY \"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\LSA\" /v RunAsPPL in ar-win-dc.attackrange.local", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="9.0", savedsearch_description="The following analytic identifies a process command line related to the discovery of possible Security Support Providers in the registry. This technique is being abused by adversaries or post exploitation tools like winpeas to gather LSA protection and configuration in the registry in the targeted host. This registry entry can contain several information related to LSA that validates users for local and remote sign-ins and enforces local security policies. Understanding LSA protection may give a good information in accessing LSA content in memory which is commonly attack by adversaries and tool like mimikatz to scrape password hashes or clear plain text passwords.", user="Administrator" 1686749607, search_name="ESCU - Windows Security Support Provider Reg Query - Rule", analyticstories="Prestige Ransomware", analyticstories="Sneaky Active Directory Persistence Tricks", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\",\"Sneaky Active Directory Persistence Tricks\"],\"cis20\":[\"CIS 10\"],\"confidence\":30,\"impact\":30,\"kill_chain_phases\":[\"Installation\",\"Exploitation\"],\"mitre_attack\":[\"T1547.005\",\"T1547\"],\"nist\":[\"DE.AE\"]}", annotations._all="Installation", annotations._all="Prestige Ransomware", annotations._all="Sneaky Active Directory Persistence Tricks", annotations._all="CIS 10", annotations._all="T1547", annotations._all="Windows Post-Exploitation", annotations._all="Exploitation", annotations._all="T1547.005", annotations._all="DE.AE", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.analytic_story="Sneaky Active Directory Persistence Tricks", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1547.005", annotations.mitre_attack="T1547", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:50", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749599.585986000", lastTime="2023-06-14T13:28:50", original_file_name="unknown", parent_process="C:\\Windows\\System32\\cmd.exe", parent_process_guid="null", parent_process_name="cmd.exe", process="C:\\Windows\\System32\\reg.exe QUERY \"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\LSA\" /v LsaCfgFlags", process_guid="null", process_id="0x6e8", process_name="reg.exe", risk_message="process with reg query command line C:\\Windows\\System32\\reg.exe QUERY \"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\LSA\" /v LsaCfgFlags in ar-win-dc.attackrange.local", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="9.0", savedsearch_description="The following analytic identifies a process command line related to the discovery of possible Security Support Providers in the registry. This technique is being abused by adversaries or post exploitation tools like winpeas to gather LSA protection and configuration in the registry in the targeted host. This registry entry can contain several information related to LSA that validates users for local and remote sign-ins and enforces local security policies. Understanding LSA protection may give a good information in accessing LSA content in memory which is commonly attack by adversaries and tool like mimikatz to scrape password hashes or clear plain text passwords.", user="Administrator" 1686749607, search_name="ESCU - Windows Security Support Provider Reg Query - Rule", analyticstories="Prestige Ransomware", analyticstories="Sneaky Active Directory Persistence Tricks", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\",\"Sneaky Active Directory Persistence Tricks\"],\"cis20\":[\"CIS 10\"],\"confidence\":30,\"impact\":30,\"kill_chain_phases\":[\"Installation\",\"Exploitation\"],\"mitre_attack\":[\"T1547.005\",\"T1547\"],\"nist\":[\"DE.AE\"]}", annotations._all="Installation", annotations._all="Prestige Ransomware", annotations._all="Sneaky Active Directory Persistence Tricks", annotations._all="CIS 10", annotations._all="T1547", annotations._all="Windows Post-Exploitation", annotations._all="Exploitation", annotations._all="T1547.005", annotations._all="DE.AE", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.analytic_story="Sneaky Active Directory Persistence Tricks", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1547.005", annotations.mitre_attack="T1547", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:50", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749599.585986000", lastTime="2023-06-14T13:28:50", original_file_name="reg.exe", parent_process="\"cmd.exe\" /s /k pushd \"C:\\Temp\"", parent_process_guid="{953948C6-BA8E-6489-C200-00000000F902}", parent_process_name="cmd.exe", process="REG QUERY \"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\LSA\" /v RunAsPPL", process_guid="{953948C6-C092-6489-270E-00000000F902}", process_id="3796", process_name="reg.exe", risk_message="process with reg query command line REG QUERY \"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\LSA\" /v RunAsPPL in ar-win-dc.attackrange.local", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="9.0", savedsearch_description="The following analytic identifies a process command line related to the discovery of possible Security Support Providers in the registry. This technique is being abused by adversaries or post exploitation tools like winpeas to gather LSA protection and configuration in the registry in the targeted host. This registry entry can contain several information related to LSA that validates users for local and remote sign-ins and enforces local security policies. Understanding LSA protection may give a good information in accessing LSA content in memory which is commonly attack by adversaries and tool like mimikatz to scrape password hashes or clear plain text passwords.", user="Administrator" 1686749607, search_name="ESCU - Windows Security Support Provider Reg Query - Rule", analyticstories="Prestige Ransomware", analyticstories="Sneaky Active Directory Persistence Tricks", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\",\"Sneaky Active Directory Persistence Tricks\"],\"cis20\":[\"CIS 10\"],\"confidence\":30,\"impact\":30,\"kill_chain_phases\":[\"Installation\",\"Exploitation\"],\"mitre_attack\":[\"T1547.005\",\"T1547\"],\"nist\":[\"DE.AE\"]}", annotations._all="Installation", annotations._all="Prestige Ransomware", annotations._all="Sneaky Active Directory Persistence Tricks", annotations._all="CIS 10", annotations._all="T1547", annotations._all="Windows Post-Exploitation", annotations._all="Exploitation", annotations._all="T1547.005", annotations._all="DE.AE", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.analytic_story="Sneaky Active Directory Persistence Tricks", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1547.005", annotations.mitre_attack="T1547", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:50", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749599.585986000", lastTime="2023-06-14T13:28:50", original_file_name="reg.exe", parent_process="\"cmd.exe\" /s /k pushd \"C:\\Temp\"", parent_process_guid="{953948C6-BA8E-6489-C200-00000000F902}", parent_process_name="cmd.exe", process="REG QUERY \"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\LSA\" /v LsaCfgFlags", process_guid="{953948C6-C092-6489-2B0E-00000000F902}", process_id="1768", process_name="reg.exe", risk_message="process with reg query command line REG QUERY \"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\LSA\" /v LsaCfgFlags in ar-win-dc.attackrange.local", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="9.0", savedsearch_description="The following analytic identifies a process command line related to the discovery of possible Security Support Providers in the registry. This technique is being abused by adversaries or post exploitation tools like winpeas to gather LSA protection and configuration in the registry in the targeted host. This registry entry can contain several information related to LSA that validates users for local and remote sign-ins and enforces local security policies. Understanding LSA protection may give a good information in accessing LSA content in memory which is commonly attack by adversaries and tool like mimikatz to scrape password hashes or clear plain text passwords.", user="Administrator" 1686749570, search_name="ESCU - Create or delete windows shares using net exe - Rule", analyticstories="CISA AA22-277A", analyticstories="Hidden Cobra Malware", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Hidden Cobra Malware\",\"CISA AA22-277A\",\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1070\",\"T1070.005\"],\"nist\":[\"DE.CM\"]}", annotations._all="Exploitation", annotations._all="Hidden Cobra Malware", annotations._all="T1070.005", annotations._all="Windows Post-Exploitation", annotations._all="Prestige Ransomware", annotations._all="CIS 10", annotations._all="CISA AA22-277A", annotations._all="T1070", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Hidden Cobra Malware", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1070", annotations.mitre_attack="T1070.005", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:54", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749564.536243000", lastTime="2023-06-14T13:28:54", original_file_name="net.exe", parent_process="\"cmd.exe\" /s /k pushd \"C:\\Temp\"", process="net share", process_name="net.exe", risk_message="An instance of $parent_process_name$ spawning net.exe was identified on endpoint ar-win-dc.attackrange.local by user Administrator enumerating Windows file shares.", risk_object="net.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="This search looks for the creation or deletion of hidden shares using net.exe.", user="Administrator" 1686749570, search_name="ESCU - Create or delete windows shares using net exe - Rule", analyticstories="CISA AA22-277A", analyticstories="Hidden Cobra Malware", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Hidden Cobra Malware\",\"CISA AA22-277A\",\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1070\",\"T1070.005\"],\"nist\":[\"DE.CM\"]}", annotations._all="Exploitation", annotations._all="Hidden Cobra Malware", annotations._all="T1070.005", annotations._all="Windows Post-Exploitation", annotations._all="Prestige Ransomware", annotations._all="CIS 10", annotations._all="CISA AA22-277A", annotations._all="T1070", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Hidden Cobra Malware", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1070", annotations.mitre_attack="T1070.005", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:54", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749564.536243000", lastTime="2023-06-14T13:28:54", original_file_name="net.exe", parent_process="\"cmd.exe\" /s /k pushd \"C:\\Temp\"", process="net share", process_name="net.exe", risk_message="An instance of $parent_process_name$ spawning net.exe was identified on endpoint ar-win-dc.attackrange.local by user Administrator enumerating Windows file shares.", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="25.0", savedsearch_description="This search looks for the creation or deletion of hidden shares using net.exe.", user="Administrator" 1686749570, search_name="ESCU - Create or delete windows shares using net exe - Rule", analyticstories="CISA AA22-277A", analyticstories="Hidden Cobra Malware", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Hidden Cobra Malware\",\"CISA AA22-277A\",\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1070\",\"T1070.005\"],\"nist\":[\"DE.CM\"]}", annotations._all="Exploitation", annotations._all="Hidden Cobra Malware", annotations._all="T1070.005", annotations._all="Windows Post-Exploitation", annotations._all="Prestige Ransomware", annotations._all="CIS 10", annotations._all="CISA AA22-277A", annotations._all="T1070", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Hidden Cobra Malware", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1070", annotations.mitre_attack="T1070.005", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:54", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749564.536243000", lastTime="2023-06-14T13:28:54", original_file_name="net.exe", parent_process="\"cmd.exe\" /s /k pushd \"C:\\Temp\"", process="net share", process_name="net.exe", risk_message="An instance of $parent_process_name$ spawning net.exe was identified on endpoint ar-win-dc.attackrange.local by user Administrator enumerating Windows file shares.", risk_object="Administrator", risk_object_type="user", risk_score="25.0", savedsearch_description="This search looks for the creation or deletion of hidden shares using net.exe.", user="Administrator" 1686749570, search_name="ESCU - Create or delete windows shares using net exe - Rule", analyticstories="CISA AA22-277A", analyticstories="Hidden Cobra Malware", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Hidden Cobra Malware\",\"CISA AA22-277A\",\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1070\",\"T1070.005\"],\"nist\":[\"DE.CM\"]}", annotations._all="Exploitation", annotations._all="Hidden Cobra Malware", annotations._all="T1070.005", annotations._all="Windows Post-Exploitation", annotations._all="Prestige Ransomware", annotations._all="CIS 10", annotations._all="CISA AA22-277A", annotations._all="T1070", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Hidden Cobra Malware", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1070", annotations.mitre_attack="T1070.005", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:54", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749564.536243000", lastTime="2023-06-14T13:28:54", original_file_name="unknown", parent_process="C:\\Windows\\System32\\net.exe", process="C:\\Windows\\system32\\net1 share", process_name="net1.exe", risk_message="An instance of $parent_process_name$ spawning net1.exe was identified on endpoint ar-win-dc.attackrange.local by user Administrator enumerating Windows file shares.", risk_object="net1.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="This search looks for the creation or deletion of hidden shares using net.exe.", user="Administrator" 1686749570, search_name="ESCU - Create or delete windows shares using net exe - Rule", analyticstories="CISA AA22-277A", analyticstories="Hidden Cobra Malware", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Hidden Cobra Malware\",\"CISA AA22-277A\",\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1070\",\"T1070.005\"],\"nist\":[\"DE.CM\"]}", annotations._all="Exploitation", annotations._all="Hidden Cobra Malware", annotations._all="T1070.005", annotations._all="Windows Post-Exploitation", annotations._all="Prestige Ransomware", annotations._all="CIS 10", annotations._all="CISA AA22-277A", annotations._all="T1070", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Hidden Cobra Malware", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1070", annotations.mitre_attack="T1070.005", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:54", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749564.536243000", lastTime="2023-06-14T13:28:54", original_file_name="unknown", parent_process="C:\\Windows\\System32\\net.exe", process="C:\\Windows\\system32\\net1 share", process_name="net1.exe", risk_message="An instance of $parent_process_name$ spawning net1.exe was identified on endpoint ar-win-dc.attackrange.local by user Administrator enumerating Windows file shares.", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="25.0", savedsearch_description="This search looks for the creation or deletion of hidden shares using net.exe.", user="Administrator" 1686749570, search_name="ESCU - Create or delete windows shares using net exe - Rule", analyticstories="CISA AA22-277A", analyticstories="Hidden Cobra Malware", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Hidden Cobra Malware\",\"CISA AA22-277A\",\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1070\",\"T1070.005\"],\"nist\":[\"DE.CM\"]}", annotations._all="Exploitation", annotations._all="Hidden Cobra Malware", annotations._all="T1070.005", annotations._all="Windows Post-Exploitation", annotations._all="Prestige Ransomware", annotations._all="CIS 10", annotations._all="CISA AA22-277A", annotations._all="T1070", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Hidden Cobra Malware", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1070", annotations.mitre_attack="T1070.005", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:54", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749564.536243000", lastTime="2023-06-14T13:28:54", original_file_name="unknown", parent_process="C:\\Windows\\System32\\net.exe", process="C:\\Windows\\system32\\net1 share", process_name="net1.exe", risk_message="An instance of $parent_process_name$ spawning net1.exe was identified on endpoint ar-win-dc.attackrange.local by user Administrator enumerating Windows file shares.", risk_object="Administrator", risk_object_type="user", risk_score="25.0", savedsearch_description="This search looks for the creation or deletion of hidden shares using net.exe.", user="Administrator" 1686749570, search_name="ESCU - Create or delete windows shares using net exe - Rule", analyticstories="CISA AA22-277A", analyticstories="Hidden Cobra Malware", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Hidden Cobra Malware\",\"CISA AA22-277A\",\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1070\",\"T1070.005\"],\"nist\":[\"DE.CM\"]}", annotations._all="Exploitation", annotations._all="Hidden Cobra Malware", annotations._all="T1070.005", annotations._all="Windows Post-Exploitation", annotations._all="Prestige Ransomware", annotations._all="CIS 10", annotations._all="CISA AA22-277A", annotations._all="T1070", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Hidden Cobra Malware", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1070", annotations.mitre_attack="T1070.005", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:54", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749564.536243000", lastTime="2023-06-14T13:28:54", original_file_name="net1.exe", parent_process="net share", process="C:\\Windows\\system32\\net1 share", process_name="net1.exe", risk_message="An instance of $parent_process_name$ spawning net1.exe was identified on endpoint ar-win-dc.attackrange.local by user Administrator enumerating Windows file shares.", risk_object="net1.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="This search looks for the creation or deletion of hidden shares using net.exe.", user="Administrator" 1686749570, search_name="ESCU - Create or delete windows shares using net exe - Rule", analyticstories="CISA AA22-277A", analyticstories="Hidden Cobra Malware", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Hidden Cobra Malware\",\"CISA AA22-277A\",\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1070\",\"T1070.005\"],\"nist\":[\"DE.CM\"]}", annotations._all="Exploitation", annotations._all="Hidden Cobra Malware", annotations._all="T1070.005", annotations._all="Windows Post-Exploitation", annotations._all="Prestige Ransomware", annotations._all="CIS 10", annotations._all="CISA AA22-277A", annotations._all="T1070", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Hidden Cobra Malware", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1070", annotations.mitre_attack="T1070.005", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:54", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749564.536243000", lastTime="2023-06-14T13:28:54", original_file_name="net1.exe", parent_process="net share", process="C:\\Windows\\system32\\net1 share", process_name="net1.exe", risk_message="An instance of $parent_process_name$ spawning net1.exe was identified on endpoint ar-win-dc.attackrange.local by user Administrator enumerating Windows file shares.", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="25.0", savedsearch_description="This search looks for the creation or deletion of hidden shares using net.exe.", user="Administrator" 1686749570, search_name="ESCU - Create or delete windows shares using net exe - Rule", analyticstories="CISA AA22-277A", analyticstories="Hidden Cobra Malware", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Hidden Cobra Malware\",\"CISA AA22-277A\",\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1070\",\"T1070.005\"],\"nist\":[\"DE.CM\"]}", annotations._all="Exploitation", annotations._all="Hidden Cobra Malware", annotations._all="T1070.005", annotations._all="Windows Post-Exploitation", annotations._all="Prestige Ransomware", annotations._all="CIS 10", annotations._all="CISA AA22-277A", annotations._all="T1070", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Hidden Cobra Malware", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1070", annotations.mitre_attack="T1070.005", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:54", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749564.536243000", lastTime="2023-06-14T13:28:54", original_file_name="net1.exe", parent_process="net share", process="C:\\Windows\\system32\\net1 share", process_name="net1.exe", risk_message="An instance of $parent_process_name$ spawning net1.exe was identified on endpoint ar-win-dc.attackrange.local by user Administrator enumerating Windows file shares.", risk_object="Administrator", risk_object_type="user", risk_score="25.0", savedsearch_description="This search looks for the creation or deletion of hidden shares using net.exe.", user="Administrator" 1686749570, search_name="ESCU - Create or delete windows shares using net exe - Rule", analyticstories="CISA AA22-277A", analyticstories="Hidden Cobra Malware", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Hidden Cobra Malware\",\"CISA AA22-277A\",\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1070\",\"T1070.005\"],\"nist\":[\"DE.CM\"]}", annotations._all="Exploitation", annotations._all="Hidden Cobra Malware", annotations._all="T1070.005", annotations._all="Windows Post-Exploitation", annotations._all="Prestige Ransomware", annotations._all="CIS 10", annotations._all="CISA AA22-277A", annotations._all="T1070", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Hidden Cobra Malware", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1070", annotations.mitre_attack="T1070.005", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:54", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749564.536243000", lastTime="2023-06-14T13:28:54", original_file_name="unknown", parent_process="C:\\Windows\\System32\\cmd.exe", process="C:\\Windows\\System32\\net.exe share", process_name="net.exe", risk_message="An instance of $parent_process_name$ spawning net.exe was identified on endpoint ar-win-dc.attackrange.local by user Administrator enumerating Windows file shares.", risk_object="net.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="This search looks for the creation or deletion of hidden shares using net.exe.", user="Administrator" 1686749570, search_name="ESCU - Create or delete windows shares using net exe - Rule", analyticstories="CISA AA22-277A", analyticstories="Hidden Cobra Malware", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Hidden Cobra Malware\",\"CISA AA22-277A\",\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1070\",\"T1070.005\"],\"nist\":[\"DE.CM\"]}", annotations._all="Exploitation", annotations._all="Hidden Cobra Malware", annotations._all="T1070.005", annotations._all="Windows Post-Exploitation", annotations._all="Prestige Ransomware", annotations._all="CIS 10", annotations._all="CISA AA22-277A", annotations._all="T1070", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Hidden Cobra Malware", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1070", annotations.mitre_attack="T1070.005", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:54", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749564.536243000", lastTime="2023-06-14T13:28:54", original_file_name="unknown", parent_process="C:\\Windows\\System32\\cmd.exe", process="C:\\Windows\\System32\\net.exe share", process_name="net.exe", risk_message="An instance of $parent_process_name$ spawning net.exe was identified on endpoint ar-win-dc.attackrange.local by user Administrator enumerating Windows file shares.", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="25.0", savedsearch_description="This search looks for the creation or deletion of hidden shares using net.exe.", user="Administrator" 1686749570, search_name="ESCU - Create or delete windows shares using net exe - Rule", analyticstories="CISA AA22-277A", analyticstories="Hidden Cobra Malware", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Hidden Cobra Malware\",\"CISA AA22-277A\",\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1070\",\"T1070.005\"],\"nist\":[\"DE.CM\"]}", annotations._all="Exploitation", annotations._all="Hidden Cobra Malware", annotations._all="T1070.005", annotations._all="Windows Post-Exploitation", annotations._all="Prestige Ransomware", annotations._all="CIS 10", annotations._all="CISA AA22-277A", annotations._all="T1070", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Hidden Cobra Malware", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1070", annotations.mitre_attack="T1070.005", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:54", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749564.536243000", lastTime="2023-06-14T13:28:54", original_file_name="unknown", parent_process="C:\\Windows\\System32\\cmd.exe", process="C:\\Windows\\System32\\net.exe share", process_name="net.exe", risk_message="An instance of $parent_process_name$ spawning net.exe was identified on endpoint ar-win-dc.attackrange.local by user Administrator enumerating Windows file shares.", risk_object="Administrator", risk_object_type="user", risk_score="25.0", savedsearch_description="This search looks for the creation or deletion of hidden shares using net.exe.", user="Administrator" 1686749340, search_name="ESCU - Excessive Usage Of Cacls App - Rule", orig_time="1686749340", analyticstories="Azorult", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", analyticstories="XMRig", annotations="{\"analytic_story\":[\"XMRig\",\"Azorult\",\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":100,\"impact\":80,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1222\"],\"nist\":[\"DE.AE\"]}", annotations._all="Prestige Ransomware", annotations._all="DE.AE", annotations._all="CIS 10", annotations._all="T1222", annotations._all="XMRig", annotations._all="Azorult", annotations._all="Exploitation", annotations._all="Windows Post-Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="XMRig", annotations.analytic_story="Azorult", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1222", annotations.nist="DE.AE", count="26", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:29:00", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749562.211902000", lastTime="2023-06-14T13:29:00", parent_process="C:\\Windows\\System32\\cmd.exe", parent_process_name="cmd.exe", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files (x86)\\Mozilla Maintenance Service\\maintenanceservice.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Amazon\\XenTools\\LiteAgent.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Amazon\\cfn-bootstrap\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Amazon\\cfn-bootstrap\\winhup.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Aurora-Agent\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Aurora-Agent\\aurora-agent.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Git\\cmd\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\ProgramData\\chocolatey\\bin\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Python311\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Python311\\Scripts\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Users\\Administrator\\AppData\\Local\\Microsoft\\WindowsApps\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\SMSvcHost.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\SysWow64\\perfhost.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\System32\\Wbem\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\servicing\\TrustedInstaller.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\sysmon64.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\system32\"", process="C:\\Windows\\System32\\icacls.exe \"c:\\Program Files\\ansible\\sysmon\"", process="C:\\Windows\\System32\\icacls.exe C:\\Windows\\ADWS\\Microsoft.ActiveDirectory.WebServices.exe", process="C:\\Windows\\System32\\icacls.exe C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\SMSvcHost.exe", process="C:\\Windows\\System32\\icacls.exe C:\\Windows\\SysWow64\\perfhost.exe", process="C:\\Windows\\System32\\icacls.exe C:\\Windows\\servicing\\TrustedInstaller.exe", process="C:\\Windows\\System32\\icacls.exe C:\\Windows\\sysmon64.exe", process_id="0x10f4", process_id="0x1128", process_id="0x11f4", process_id="0x12e8", process_id="0x1368", process_id="0x1390", process_id="0x14c0", process_id="0x162c", process_id="0x165c", process_id="0x17cc", process_id="0x18b4", process_id="0x1a54", process_id="0x1a5c", process_id="0x1b00", process_id="0x1b6c", process_id="0x1b7c", process_id="0x1be0", process_id="0x1e4", process_id="0x6a0", process_id="0x784", process_id="0x7d4", process_id="0x998", process_id="0x9a4", process_id="0xe00", process_name="icacls.exe", risk_message="An excessive amount of icacls.exe was executed on ar-win-dc.attackrange.local attempting to modify permissions.", risk_object="icacls.exe", risk_object_type="other", risk_score="80.0", savedsearch_description="The following analytic identifies excessive usage of `cacls.exe`, `xcacls.exe` or `icacls.exe` application to change file or folder permission. This behavior is commonly seen where the adversary attempts to impair some users from deleting or accessing its malware components or artifact from the compromised system.", user="Administrator" 1686749340, search_name="ESCU - Excessive Usage Of Cacls App - Rule", orig_time="1686749340", analyticstories="Azorult", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", analyticstories="XMRig", annotations="{\"analytic_story\":[\"XMRig\",\"Azorult\",\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":100,\"impact\":80,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1222\"],\"nist\":[\"DE.AE\"]}", annotations._all="Prestige Ransomware", annotations._all="DE.AE", annotations._all="CIS 10", annotations._all="T1222", annotations._all="XMRig", annotations._all="Azorult", annotations._all="Exploitation", annotations._all="Windows Post-Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="XMRig", annotations.analytic_story="Azorult", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1222", annotations.nist="DE.AE", count="26", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:29:00", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749562.211902000", lastTime="2023-06-14T13:29:00", parent_process="C:\\Windows\\System32\\cmd.exe", parent_process_name="cmd.exe", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files (x86)\\Mozilla Maintenance Service\\maintenanceservice.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Amazon\\XenTools\\LiteAgent.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Amazon\\cfn-bootstrap\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Amazon\\cfn-bootstrap\\winhup.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Aurora-Agent\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Aurora-Agent\\aurora-agent.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Git\\cmd\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\ProgramData\\chocolatey\\bin\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Python311\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Python311\\Scripts\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Users\\Administrator\\AppData\\Local\\Microsoft\\WindowsApps\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\SMSvcHost.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\SysWow64\\perfhost.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\System32\\Wbem\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\servicing\\TrustedInstaller.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\sysmon64.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\system32\"", process="C:\\Windows\\System32\\icacls.exe \"c:\\Program Files\\ansible\\sysmon\"", process="C:\\Windows\\System32\\icacls.exe C:\\Windows\\ADWS\\Microsoft.ActiveDirectory.WebServices.exe", process="C:\\Windows\\System32\\icacls.exe C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\SMSvcHost.exe", process="C:\\Windows\\System32\\icacls.exe C:\\Windows\\SysWow64\\perfhost.exe", process="C:\\Windows\\System32\\icacls.exe C:\\Windows\\servicing\\TrustedInstaller.exe", process="C:\\Windows\\System32\\icacls.exe C:\\Windows\\sysmon64.exe", process_id="0x10f4", process_id="0x1128", process_id="0x11f4", process_id="0x12e8", process_id="0x1368", process_id="0x1390", process_id="0x14c0", process_id="0x162c", process_id="0x165c", process_id="0x17cc", process_id="0x18b4", process_id="0x1a54", process_id="0x1a5c", process_id="0x1b00", process_id="0x1b6c", process_id="0x1b7c", process_id="0x1be0", process_id="0x1e4", process_id="0x6a0", process_id="0x784", process_id="0x7d4", process_id="0x998", process_id="0x9a4", process_id="0xe00", process_name="icacls.exe", risk_message="An excessive amount of icacls.exe was executed on ar-win-dc.attackrange.local attempting to modify permissions.", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="80.0", savedsearch_description="The following analytic identifies excessive usage of `cacls.exe`, `xcacls.exe` or `icacls.exe` application to change file or folder permission. This behavior is commonly seen where the adversary attempts to impair some users from deleting or accessing its malware components or artifact from the compromised system.", user="Administrator" 1686749280, search_name="ESCU - Excessive Usage Of Cacls App - Rule", orig_time="1686749280", analyticstories="Azorult", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", analyticstories="XMRig", annotations="{\"analytic_story\":[\"XMRig\",\"Azorult\",\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":100,\"impact\":80,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1222\"],\"nist\":[\"DE.AE\"]}", annotations._all="Prestige Ransomware", annotations._all="DE.AE", annotations._all="CIS 10", annotations._all="T1222", annotations._all="XMRig", annotations._all="Azorult", annotations._all="Exploitation", annotations._all="Windows Post-Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="XMRig", annotations.analytic_story="Azorult", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1222", annotations.nist="DE.AE", count="62", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:00", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749562.211902000", lastTime="2023-06-14T13:28:00", parent_process="C:\\Windows\\System32\\cmd.exe", parent_process_name="cmd.exe", process="C:\\Windows\\System32\\icacls.exe \"C:\\Documents and Settings\\Administrator\\Start Menu\\Programs\\Startup\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Documents and Settings\\Administrator\\Start Menu\\Programs\\Startup\\*\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\*\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Amazon\\SSM\\\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Amazon\\SSM\\amazon-ssm-agent.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Amazon\\SSM\\ssm-agent-worker.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Aurora-Agent\\\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Aurora-Agent\\aurora-agent.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Aurora-Agent\\tools\\\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Aurora-Agent\\tools\\aurora-dashboard.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Mozilla Firefox\\\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Mozilla Firefox\\firefox.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Notepad++\\\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Notepad++\\notepad++.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\*\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Users\\Administrator\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Users\\Administrator\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\*\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\ADWS\\Microsoft.ActiveDirectory.WebServices.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\ADWS\\\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\Explorer.EXE\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\SystemApps\\Microsoft.Windows.Cortana_cw5n1h2txyewy\\SearchUI.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\SystemApps\\Microsoft.Windows.Cortana_cw5n1h2txyewy\\\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\SystemApps\\ShellExperienceHost_cw5n1h2txyewy\\ShellExperienceHost.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\SystemApps\\ShellExperienceHost_cw5n1h2txyewy\\\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\WinSxS\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.5771_none_7ee250a22208ec93\\\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\servicing\\TrustedInstaller.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\servicing\\\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\sysmon64.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\winsxs\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.5771_none_7ee250a22208ec93\\TiWorker.exe\"", process_id="0x1020", process_id="0x104c", process_id="0x10ac", process_id="0x1138", process_id="0x1160", process_id="0x1164", process_id="0x120", process_id="0x1260", process_id="0x12d0", process_id="0x1394", process_id="0x13c0", process_id="0x13dc", process_id="0x1478", process_id="0x14d0", process_id="0x1618", process_id="0x1630", process_id="0x1674", process_id="0x16d0", process_id="0x16f0", process_id="0x1780", process_id="0x17c8", process_id="0x17cc", process_id="0x1844", process_id="0x1870", process_id="0x1904", process_id="0x1924", process_id="0x198c", process_id="0x199c", process_id="0x19fc", process_id="0x1a04", process_id="0x1a28", process_id="0x1a2c", process_id="0x1a30", process_id="0x1a5c", process_id="0x1a6c", process_id="0x1a70", process_id="0x1a88", process_id="0x1b34", process_id="0x1b68", process_id="0x1be0", process_id="0x214", process_id="0x230", process_id="0x408", process_id="0x434", process_id="0x66c", process_id="0x694", process_id="0x6a8", process_id="0x8e0", process_id="0x8ec", process_id="0xb90", process_id="0xc28", process_id="0xc40", process_id="0xc98", process_id="0xd98", process_id="0xe00", process_id="0xe84", process_id="0xf28", process_name="icacls.exe", risk_message="An excessive amount of icacls.exe was executed on ar-win-dc.attackrange.local attempting to modify permissions.", risk_object="icacls.exe", risk_object_type="other", risk_score="80.0", savedsearch_description="The following analytic identifies excessive usage of `cacls.exe`, `xcacls.exe` or `icacls.exe` application to change file or folder permission. This behavior is commonly seen where the adversary attempts to impair some users from deleting or accessing its malware components or artifact from the compromised system.", user="Administrator" 1686749280, search_name="ESCU - Excessive Usage Of Cacls App - Rule", orig_time="1686749280", analyticstories="Azorult", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", analyticstories="XMRig", annotations="{\"analytic_story\":[\"XMRig\",\"Azorult\",\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":100,\"impact\":80,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1222\"],\"nist\":[\"DE.AE\"]}", annotations._all="Prestige Ransomware", annotations._all="DE.AE", annotations._all="CIS 10", annotations._all="T1222", annotations._all="XMRig", annotations._all="Azorult", annotations._all="Exploitation", annotations._all="Windows Post-Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="XMRig", annotations.analytic_story="Azorult", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1222", annotations.nist="DE.AE", count="62", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:00", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749562.211902000", lastTime="2023-06-14T13:28:00", parent_process="C:\\Windows\\System32\\cmd.exe", parent_process_name="cmd.exe", process="C:\\Windows\\System32\\icacls.exe \"C:\\Documents and Settings\\Administrator\\Start Menu\\Programs\\Startup\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Documents and Settings\\Administrator\\Start Menu\\Programs\\Startup\\*\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\*\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Amazon\\SSM\\\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Amazon\\SSM\\amazon-ssm-agent.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Amazon\\SSM\\ssm-agent-worker.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Aurora-Agent\\\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Aurora-Agent\\aurora-agent.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Aurora-Agent\\tools\\\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Aurora-Agent\\tools\\aurora-dashboard.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Mozilla Firefox\\\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Mozilla Firefox\\firefox.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Notepad++\\\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Notepad++\\notepad++.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\*\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Users\\Administrator\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Users\\Administrator\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\*\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\ADWS\\Microsoft.ActiveDirectory.WebServices.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\ADWS\\\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\Explorer.EXE\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\SystemApps\\Microsoft.Windows.Cortana_cw5n1h2txyewy\\SearchUI.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\SystemApps\\Microsoft.Windows.Cortana_cw5n1h2txyewy\\\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\SystemApps\\ShellExperienceHost_cw5n1h2txyewy\\ShellExperienceHost.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\SystemApps\\ShellExperienceHost_cw5n1h2txyewy\\\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\WinSxS\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.5771_none_7ee250a22208ec93\\\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\servicing\\TrustedInstaller.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\servicing\\\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\sysmon64.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\winsxs\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.5771_none_7ee250a22208ec93\\TiWorker.exe\"", process_id="0x1020", process_id="0x104c", process_id="0x10ac", process_id="0x1138", process_id="0x1160", process_id="0x1164", process_id="0x120", process_id="0x1260", process_id="0x12d0", process_id="0x1394", process_id="0x13c0", process_id="0x13dc", process_id="0x1478", process_id="0x14d0", process_id="0x1618", process_id="0x1630", process_id="0x1674", process_id="0x16d0", process_id="0x16f0", process_id="0x1780", process_id="0x17c8", process_id="0x17cc", process_id="0x1844", process_id="0x1870", process_id="0x1904", process_id="0x1924", process_id="0x198c", process_id="0x199c", process_id="0x19fc", process_id="0x1a04", process_id="0x1a28", process_id="0x1a2c", process_id="0x1a30", process_id="0x1a5c", process_id="0x1a6c", process_id="0x1a70", process_id="0x1a88", process_id="0x1b34", process_id="0x1b68", process_id="0x1be0", process_id="0x214", process_id="0x230", process_id="0x408", process_id="0x434", process_id="0x66c", process_id="0x694", process_id="0x6a8", process_id="0x8e0", process_id="0x8ec", process_id="0xb90", process_id="0xc28", process_id="0xc40", process_id="0xc98", process_id="0xd98", process_id="0xe00", process_id="0xe84", process_id="0xf28", process_name="icacls.exe", risk_message="An excessive amount of icacls.exe was executed on ar-win-dc.attackrange.local attempting to modify permissions.", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="80.0", savedsearch_description="The following analytic identifies excessive usage of `cacls.exe`, `xcacls.exe` or `icacls.exe` application to change file or folder permission. This behavior is commonly seen where the adversary attempts to impair some users from deleting or accessing its malware components or artifact from the compromised system.", user="Administrator" 1686749340, search_name="ESCU - Excessive Usage Of Cacls App - Rule", orig_time="1686749340", analyticstories="Azorult", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", analyticstories="XMRig", annotations="{\"analytic_story\":[\"XMRig\",\"Azorult\",\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":100,\"impact\":80,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1222\"],\"nist\":[\"DE.AE\"]}", annotations._all="Prestige Ransomware", annotations._all="DE.AE", annotations._all="CIS 10", annotations._all="T1222", annotations._all="XMRig", annotations._all="Azorult", annotations._all="Exploitation", annotations._all="Windows Post-Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="XMRig", annotations.analytic_story="Azorult", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1222", annotations.nist="DE.AE", count="14", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:29:00", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749562.211902000", lastTime="2023-06-14T13:29:00", parent_process="\"cmd.exe\" /s /k pushd \"C:\\Temp\"", parent_process_name="cmd.exe", process="icacls C:\\Windows\\ADWS\\Microsoft.ActiveDirectory.WebServices.exe", process="icacls C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\SMSvcHost.exe", process="icacls C:\\Windows\\SysWow64\\perfhost.exe", process="icacls C:\\Windows\\servicing\\TrustedInstaller.exe", process="icacls C:\\Windows\\sysmon64.exe", process="icacls \"C:\\Program Files (x86)\\Mozilla Maintenance Service\\maintenanceservice.exe\"", process="icacls \"C:\\Program Files\\Amazon\\XenTools\\LiteAgent.exe\"", process="icacls \"C:\\Program Files\\Amazon\\cfn-bootstrap\\winhup.exe\"", process="icacls \"C:\\Program Files\\Aurora-Agent\\aurora-agent.exe\"", process="icacls \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\"", process="icacls \"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\SMSvcHost.exe\"", process="icacls \"C:\\Windows\\SysWow64\\perfhost.exe\"", process="icacls \"C:\\Windows\\servicing\\TrustedInstaller.exe\"", process="icacls \"C:\\Windows\\sysmon64.exe\"", process_id="1696", process_id="2468", process_id="3584", process_id="4340", process_id="4596", process_id="484", process_id="4840", process_id="4968", process_id="5008", process_id="5312", process_id="5676", process_id="5724", process_id="6912", process_id="7136", process_name="icacls.exe", risk_message="An excessive amount of icacls.exe was executed on ar-win-dc.attackrange.local attempting to modify permissions.", risk_object="icacls.exe", risk_object_type="other", risk_score="80.0", savedsearch_description="The following analytic identifies excessive usage of `cacls.exe`, `xcacls.exe` or `icacls.exe` application to change file or folder permission. This behavior is commonly seen where the adversary attempts to impair some users from deleting or accessing its malware components or artifact from the compromised system.", user="Administrator" 1686749340, search_name="ESCU - Excessive Usage Of Cacls App - Rule", orig_time="1686749340", analyticstories="Azorult", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", analyticstories="XMRig", annotations="{\"analytic_story\":[\"XMRig\",\"Azorult\",\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":100,\"impact\":80,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1222\"],\"nist\":[\"DE.AE\"]}", annotations._all="Prestige Ransomware", annotations._all="DE.AE", annotations._all="CIS 10", annotations._all="T1222", annotations._all="XMRig", annotations._all="Azorult", annotations._all="Exploitation", annotations._all="Windows Post-Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="XMRig", annotations.analytic_story="Azorult", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1222", annotations.nist="DE.AE", count="14", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:29:00", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749562.211902000", lastTime="2023-06-14T13:29:00", parent_process="\"cmd.exe\" /s /k pushd \"C:\\Temp\"", parent_process_name="cmd.exe", process="icacls C:\\Windows\\ADWS\\Microsoft.ActiveDirectory.WebServices.exe", process="icacls C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\SMSvcHost.exe", process="icacls C:\\Windows\\SysWow64\\perfhost.exe", process="icacls C:\\Windows\\servicing\\TrustedInstaller.exe", process="icacls C:\\Windows\\sysmon64.exe", process="icacls \"C:\\Program Files (x86)\\Mozilla Maintenance Service\\maintenanceservice.exe\"", process="icacls \"C:\\Program Files\\Amazon\\XenTools\\LiteAgent.exe\"", process="icacls \"C:\\Program Files\\Amazon\\cfn-bootstrap\\winhup.exe\"", process="icacls \"C:\\Program Files\\Aurora-Agent\\aurora-agent.exe\"", process="icacls \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\"", process="icacls \"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\SMSvcHost.exe\"", process="icacls \"C:\\Windows\\SysWow64\\perfhost.exe\"", process="icacls \"C:\\Windows\\servicing\\TrustedInstaller.exe\"", process="icacls \"C:\\Windows\\sysmon64.exe\"", process_id="1696", process_id="2468", process_id="3584", process_id="4340", process_id="4596", process_id="484", process_id="4840", process_id="4968", process_id="5008", process_id="5312", process_id="5676", process_id="5724", process_id="6912", process_id="7136", process_name="icacls.exe", risk_message="An excessive amount of icacls.exe was executed on ar-win-dc.attackrange.local attempting to modify permissions.", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="80.0", savedsearch_description="The following analytic identifies excessive usage of `cacls.exe`, `xcacls.exe` or `icacls.exe` application to change file or folder permission. This behavior is commonly seen where the adversary attempts to impair some users from deleting or accessing its malware components or artifact from the compromised system.", user="Administrator" 1686749280, search_name="ESCU - Excessive Usage Of Cacls App - Rule", orig_time="1686749280", analyticstories="Azorult", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", analyticstories="XMRig", annotations="{\"analytic_story\":[\"XMRig\",\"Azorult\",\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":100,\"impact\":80,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1222\"],\"nist\":[\"DE.AE\"]}", annotations._all="Prestige Ransomware", annotations._all="DE.AE", annotations._all="CIS 10", annotations._all="T1222", annotations._all="XMRig", annotations._all="Azorult", annotations._all="Exploitation", annotations._all="Windows Post-Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="XMRig", annotations.analytic_story="Azorult", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1222", annotations.nist="DE.AE", count="62", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:00", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749562.211902000", lastTime="2023-06-14T13:28:00", parent_process="\"cmd.exe\" /s /k pushd \"C:\\Temp\"", parent_process_name="cmd.exe", process="icacls \"C:\\Documents and Settings\\Administrator\\Start Menu\\Programs\\Startup\"", process="icacls \"C:\\Documents and Settings\\Administrator\\Start Menu\\Programs\\Startup\\*\"", process="icacls \"C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\"", process="icacls \"C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\*\"", process="icacls \"C:\\Program Files\\Amazon\\SSM\\\\\"", process="icacls \"C:\\Program Files\\Amazon\\SSM\\amazon-ssm-agent.exe\"", process="icacls \"C:\\Program Files\\Amazon\\SSM\\ssm-agent-worker.exe\"", process="icacls \"C:\\Program Files\\Aurora-Agent\\\\\"", process="icacls \"C:\\Program Files\\Aurora-Agent\\aurora-agent.exe\"", process="icacls \"C:\\Program Files\\Aurora-Agent\\tools\\\\\"", process="icacls \"C:\\Program Files\\Aurora-Agent\\tools\\aurora-dashboard.exe\"", process="icacls \"C:\\Program Files\\Mozilla Firefox\\\\\"", process="icacls \"C:\\Program Files\\Mozilla Firefox\\firefox.exe\"", process="icacls \"C:\\Program Files\\Notepad++\\\\\"", process="icacls \"C:\\Program Files\\Notepad++\\notepad++.exe\"", process="icacls \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\\\\"", process="icacls \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\"", process="icacls \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe\"", process="icacls \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\"", process="icacls \"C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\"", process="icacls \"C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\*\"", process="icacls \"C:\\Users\\Administrator\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\"", process="icacls \"C:\\Users\\Administrator\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\*\"", process="icacls \"C:\\Windows\\ADWS\\Microsoft.ActiveDirectory.WebServices.exe\"", process="icacls \"C:\\Windows\\ADWS\\\\\"", process="icacls \"C:\\Windows\\Explorer.EXE\"", process="icacls \"C:\\Windows\\SystemApps\\Microsoft.Windows.Cortana_cw5n1h2txyewy\\SearchUI.exe\"", process="icacls \"C:\\Windows\\SystemApps\\Microsoft.Windows.Cortana_cw5n1h2txyewy\\\\\"", process="icacls \"C:\\Windows\\SystemApps\\ShellExperienceHost_cw5n1h2txyewy\\ShellExperienceHost.exe\"", process="icacls \"C:\\Windows\\SystemApps\\ShellExperienceHost_cw5n1h2txyewy\\\\\"", process="icacls \"C:\\Windows\\WinSxS\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.5771_none_7ee250a22208ec93\\\\\"", process="icacls \"C:\\Windows\\\\\"", process="icacls \"C:\\Windows\\servicing\\TrustedInstaller.exe\"", process="icacls \"C:\\Windows\\servicing\\\\\"", process="icacls \"C:\\Windows\\sysmon64.exe\"", process="icacls \"C:\\Windows\\winsxs\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.5771_none_7ee250a22208ec93\\TiWorker.exe\"", process_id="1032", process_id="1076", process_id="1644", process_id="1684", process_id="1704", process_id="2272", process_id="2284", process_id="288", process_id="2960", process_id="3112", process_id="3136", process_id="3224", process_id="3480", process_id="3584", process_id="3716", process_id="3880", process_id="4128", process_id="4172", process_id="4268", process_id="4408", process_id="4448", process_id="4452", process_id="4704", process_id="4816", process_id="5012", process_id="5056", process_id="5084", process_id="5240", process_id="532", process_id="5328", process_id="560", process_id="5656", process_id="5680", process_id="5748", process_id="5840", process_id="5872", process_id="6016", process_id="6088", process_id="6092", process_id="6212", process_id="6256", process_id="6404", process_id="6436", process_id="6540", process_id="6556", process_id="6652", process_id="6660", process_id="6696", process_id="6700", process_id="6704", process_id="6748", process_id="6764", process_id="6768", process_id="6792", process_id="6964", process_id="7016", process_id="7136", process_name="icacls.exe", risk_message="An excessive amount of icacls.exe was executed on ar-win-dc.attackrange.local attempting to modify permissions.", risk_object="icacls.exe", risk_object_type="other", risk_score="80.0", savedsearch_description="The following analytic identifies excessive usage of `cacls.exe`, `xcacls.exe` or `icacls.exe` application to change file or folder permission. This behavior is commonly seen where the adversary attempts to impair some users from deleting or accessing its malware components or artifact from the compromised system.", user="Administrator" 1686749280, search_name="ESCU - Excessive Usage Of Cacls App - Rule", orig_time="1686749280", analyticstories="Azorult", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", analyticstories="XMRig", annotations="{\"analytic_story\":[\"XMRig\",\"Azorult\",\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":100,\"impact\":80,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1222\"],\"nist\":[\"DE.AE\"]}", annotations._all="Prestige Ransomware", annotations._all="DE.AE", annotations._all="CIS 10", annotations._all="T1222", annotations._all="XMRig", annotations._all="Azorult", annotations._all="Exploitation", annotations._all="Windows Post-Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="XMRig", annotations.analytic_story="Azorult", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1222", annotations.nist="DE.AE", count="62", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:00", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749562.211902000", lastTime="2023-06-14T13:28:00", parent_process="\"cmd.exe\" /s /k pushd \"C:\\Temp\"", parent_process_name="cmd.exe", process="icacls \"C:\\Documents and Settings\\Administrator\\Start Menu\\Programs\\Startup\"", process="icacls \"C:\\Documents and Settings\\Administrator\\Start Menu\\Programs\\Startup\\*\"", process="icacls \"C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\"", process="icacls \"C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\*\"", process="icacls \"C:\\Program Files\\Amazon\\SSM\\\\\"", process="icacls \"C:\\Program Files\\Amazon\\SSM\\amazon-ssm-agent.exe\"", process="icacls \"C:\\Program Files\\Amazon\\SSM\\ssm-agent-worker.exe\"", process="icacls \"C:\\Program Files\\Aurora-Agent\\\\\"", process="icacls \"C:\\Program Files\\Aurora-Agent\\aurora-agent.exe\"", process="icacls \"C:\\Program Files\\Aurora-Agent\\tools\\\\\"", process="icacls \"C:\\Program Files\\Aurora-Agent\\tools\\aurora-dashboard.exe\"", process="icacls \"C:\\Program Files\\Mozilla Firefox\\\\\"", process="icacls \"C:\\Program Files\\Mozilla Firefox\\firefox.exe\"", process="icacls \"C:\\Program Files\\Notepad++\\\\\"", process="icacls \"C:\\Program Files\\Notepad++\\notepad++.exe\"", process="icacls \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\\\\"", process="icacls \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\"", process="icacls \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe\"", process="icacls \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\"", process="icacls \"C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\"", process="icacls \"C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\*\"", process="icacls \"C:\\Users\\Administrator\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\"", process="icacls \"C:\\Users\\Administrator\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\*\"", process="icacls \"C:\\Windows\\ADWS\\Microsoft.ActiveDirectory.WebServices.exe\"", process="icacls \"C:\\Windows\\ADWS\\\\\"", process="icacls \"C:\\Windows\\Explorer.EXE\"", process="icacls \"C:\\Windows\\SystemApps\\Microsoft.Windows.Cortana_cw5n1h2txyewy\\SearchUI.exe\"", process="icacls \"C:\\Windows\\SystemApps\\Microsoft.Windows.Cortana_cw5n1h2txyewy\\\\\"", process="icacls \"C:\\Windows\\SystemApps\\ShellExperienceHost_cw5n1h2txyewy\\ShellExperienceHost.exe\"", process="icacls \"C:\\Windows\\SystemApps\\ShellExperienceHost_cw5n1h2txyewy\\\\\"", process="icacls \"C:\\Windows\\WinSxS\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.5771_none_7ee250a22208ec93\\\\\"", process="icacls \"C:\\Windows\\\\\"", process="icacls \"C:\\Windows\\servicing\\TrustedInstaller.exe\"", process="icacls \"C:\\Windows\\servicing\\\\\"", process="icacls \"C:\\Windows\\sysmon64.exe\"", process="icacls \"C:\\Windows\\winsxs\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.5771_none_7ee250a22208ec93\\TiWorker.exe\"", process_id="1032", process_id="1076", process_id="1644", process_id="1684", process_id="1704", process_id="2272", process_id="2284", process_id="288", process_id="2960", process_id="3112", process_id="3136", process_id="3224", process_id="3480", process_id="3584", process_id="3716", process_id="3880", process_id="4128", process_id="4172", process_id="4268", process_id="4408", process_id="4448", process_id="4452", process_id="4704", process_id="4816", process_id="5012", process_id="5056", process_id="5084", process_id="5240", process_id="532", process_id="5328", process_id="560", process_id="5656", process_id="5680", process_id="5748", process_id="5840", process_id="5872", process_id="6016", process_id="6088", process_id="6092", process_id="6212", process_id="6256", process_id="6404", process_id="6436", process_id="6540", process_id="6556", process_id="6652", process_id="6660", process_id="6696", process_id="6700", process_id="6704", process_id="6748", process_id="6764", process_id="6768", process_id="6792", process_id="6964", process_id="7016", process_id="7136", process_name="icacls.exe", risk_message="An excessive amount of icacls.exe was executed on ar-win-dc.attackrange.local attempting to modify permissions.", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="80.0", savedsearch_description="The following analytic identifies excessive usage of `cacls.exe`, `xcacls.exe` or `icacls.exe` application to change file or folder permission. This behavior is commonly seen where the adversary attempts to impair some users from deleting or accessing its malware components or artifact from the compromised system.", user="Administrator" 1686749548, search_name="ESCU - Windows WMI Process And Service List - Rule", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":20,\"impact\":20,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1047\"],\"nist\":[\"DE.AE\"]}", annotations._all="CIS 10", annotations._all="T1047", annotations._all="Windows Post-Exploitation", annotations._all="Installation", annotations._all="Prestige Ransomware", annotations._all="DE.AE", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1047", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:59", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749542.793823000", lastTime="2023-06-14T13:28:59", original_file_name="wmic.exe", parent_process="cmd.exe /c wmic service list full", parent_process_guid="{953948C6-C09B-6489-C00F-00000000F902}", parent_process_name="cmd.exe", process="wmic service list full", process_guid="{953948C6-C09B-6489-C30F-00000000F902}", process_id="7148", process_name="WMIC.exe", risk_message="wmi command wmic service list full to list processes and services in ar-win-dc.attackrange.local", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="4.0", savedsearch_description="The following analytic identifies suspicious process command line, where WMI is performing an event query looking for running processes or running services. This technique is commonly found where the adversary will identify services and system information on the compromised machine. During triage, review parallel processes within the same timeframe. Review the full script block to identify other related artifacts.", user="Administrator" 1686749548, search_name="ESCU - Windows WMI Process And Service List - Rule", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":20,\"impact\":20,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1047\"],\"nist\":[\"DE.AE\"]}", annotations._all="CIS 10", annotations._all="T1047", annotations._all="Windows Post-Exploitation", annotations._all="Installation", annotations._all="Prestige Ransomware", annotations._all="DE.AE", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1047", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:52", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749542.793823000", lastTime="2023-06-14T13:28:52", original_file_name="wmic.exe", parent_process="C:\\Windows\\system32\\cmd.exe /c wmic process list full|find /i \"executablepath\"|find /i /v \"system32\"|find \":\"", parent_process_guid="{953948C6-C094-6489-D30E-00000000F902}", parent_process_name="cmd.exe", process="wmic process list full", process_guid="{953948C6-C094-6489-D40E-00000000F902}", process_id="5660", process_name="WMIC.exe", risk_message="wmi command wmic process list full to list processes and services in ar-win-dc.attackrange.local", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="4.0", savedsearch_description="The following analytic identifies suspicious process command line, where WMI is performing an event query looking for running processes or running services. This technique is commonly found where the adversary will identify services and system information on the compromised machine. During triage, review parallel processes within the same timeframe. Review the full script block to identify other related artifacts.", user="Administrator" 1686749548, search_name="ESCU - Windows WMI Process And Service List - Rule", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":20,\"impact\":20,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1047\"],\"nist\":[\"DE.AE\"]}", annotations._all="CIS 10", annotations._all="T1047", annotations._all="Windows Post-Exploitation", annotations._all="Installation", annotations._all="Prestige Ransomware", annotations._all="DE.AE", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1047", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:51", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749542.793823000", lastTime="2023-06-14T13:28:51", original_file_name="wmic.exe", parent_process="C:\\Windows\\system32\\cmd.exe /c wmic process list full|find /i \"executablepath\"|find /i /v \"system32\"|find \":\"", parent_process_guid="{953948C6-C093-6489-660E-00000000F902}", parent_process_name="cmd.exe", process="wmic process list full", process_guid="{953948C6-C093-6489-670E-00000000F902}", process_id="4028", process_name="WMIC.exe", risk_message="wmi command wmic process list full to list processes and services in ar-win-dc.attackrange.local", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="4.0", savedsearch_description="The following analytic identifies suspicious process command line, where WMI is performing an event query looking for running processes or running services. This technique is commonly found where the adversary will identify services and system information on the compromised machine. During triage, review parallel processes within the same timeframe. Review the full script block to identify other related artifacts.", user="Administrator" 1686749548, search_name="ESCU - Windows WMI Process And Service List - Rule", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":20,\"impact\":20,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1047\"],\"nist\":[\"DE.AE\"]}", annotations._all="CIS 10", annotations._all="T1047", annotations._all="Windows Post-Exploitation", annotations._all="Installation", annotations._all="Prestige Ransomware", annotations._all="DE.AE", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1047", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:59", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749542.793823000", lastTime="2023-06-14T13:28:59", original_file_name="unknown", parent_process="C:\\Windows\\System32\\cmd.exe", parent_process_guid="null", parent_process_name="cmd.exe", process="C:\\Windows\\System32\\wbem\\WMIC.exe service list full", process_guid="null", process_id="0x1bec", process_name="WMIC.exe", risk_message="wmi command C:\\Windows\\System32\\wbem\\WMIC.exe service list full to list processes and services in ar-win-dc.attackrange.local", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="4.0", savedsearch_description="The following analytic identifies suspicious process command line, where WMI is performing an event query looking for running processes or running services. This technique is commonly found where the adversary will identify services and system information on the compromised machine. During triage, review parallel processes within the same timeframe. Review the full script block to identify other related artifacts.", user="Administrator" 1686749548, search_name="ESCU - Windows WMI Process And Service List - Rule", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":20,\"impact\":20,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1047\"],\"nist\":[\"DE.AE\"]}", annotations._all="CIS 10", annotations._all="T1047", annotations._all="Windows Post-Exploitation", annotations._all="Installation", annotations._all="Prestige Ransomware", annotations._all="DE.AE", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1047", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:51", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749542.793823000", lastTime="2023-06-14T13:28:51", original_file_name="unknown", parent_process="C:\\Windows\\System32\\cmd.exe", parent_process_guid="null", parent_process_name="cmd.exe", process="C:\\Windows\\System32\\wbem\\WMIC.exe process list full", process_guid="null", process_id="0xfbc", process_name="WMIC.exe", risk_message="wmi command C:\\Windows\\System32\\wbem\\WMIC.exe process list full to list processes and services in ar-win-dc.attackrange.local", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="4.0", savedsearch_description="The following analytic identifies suspicious process command line, where WMI is performing an event query looking for running processes or running services. This technique is commonly found where the adversary will identify services and system information on the compromised machine. During triage, review parallel processes within the same timeframe. Review the full script block to identify other related artifacts.", user="Administrator" 1686749548, search_name="ESCU - Windows WMI Process And Service List - Rule", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":20,\"impact\":20,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1047\"],\"nist\":[\"DE.AE\"]}", annotations._all="CIS 10", annotations._all="T1047", annotations._all="Windows Post-Exploitation", annotations._all="Installation", annotations._all="Prestige Ransomware", annotations._all="DE.AE", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1047", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:52", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749542.793823000", lastTime="2023-06-14T13:28:52", original_file_name="unknown", parent_process="C:\\Windows\\System32\\cmd.exe", parent_process_guid="null", parent_process_name="cmd.exe", process="C:\\Windows\\System32\\wbem\\WMIC.exe process list full", process_guid="null", process_id="0x161c", process_name="WMIC.exe", risk_message="wmi command C:\\Windows\\System32\\wbem\\WMIC.exe process list full to list processes and services in ar-win-dc.attackrange.local", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="4.0", savedsearch_description="The following analytic identifies suspicious process command line, where WMI is performing an event query looking for running processes or running services. This technique is commonly found where the adversary will identify services and system information on the compromised machine. During triage, review parallel processes within the same timeframe. Review the full script block to identify other related artifacts.", user="Administrator" 1686749280, search_name="ESCU - Windows Indirect Command Execution Via Series Of Forfiles - Rule", orig_time="1686749280", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":30,\"impact\":30,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.AE\"]}", annotations._all="DE.AE", annotations._all="T1202", annotations._all="Exploitation", annotations._all="Prestige Ransomware", annotations._all="Windows Post-Exploitation", annotations._all="CIS 10", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.AE", count="39", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:00", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749517.043454000", lastTime="2023-06-14T13:28:00", parent_process="C:\\Windows\\System32\\cmd.exe", parent_process_name="cmd.exe", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m ADMINISTRATORS GROUPS\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m ARP\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m AlwaysInstallElevated?\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Audit Settings\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m CURRENT CLIPBOARD\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m CURRENT LOGGED USERS\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m CURRENT SHARES\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m CURRENT USER\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Credential Guard?\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m DATE and TIME\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m DNS CACHE\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m ENVIRONMENT\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m FIREWALL\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m GROUPS\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Hosts file\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m INSTALLED SOFTWARE\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m INTERFACES\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Kerberos Tickets\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m LAPS installed?\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m LSA protection?\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m MOUNTED DISKS\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Number of cached creds\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m PowerShell settings\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m ROUTES\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m RUN AT STARTUP\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m RUNNING PROCESSES\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Registered Anti-Virus(AV)\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Remote Desktop Credentials Manager\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m SERVICE BINARY PERMISSIONS WITH WMIC and ICACLS\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m UAC Settings\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m USED PORTS\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m USERS\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m WDigest?\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m WEF Settings\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m WIFI\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m WSUS\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO.0x1B[32m[*]0x1B[97m BASIC USER INFO\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO.0x1B[32m[*]0x1B[97m NETWORK\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO.0x1B[32m[*]0x1B[97m SERVICE VULNERABILITIES\"", process_name="forfiles.exe", risk_message="excessive forfiles process execution in ar-win-dc.attackrange.local", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="9.0", savedsearch_description="This analytic is developed to detect suspicious excessive usage of forfiles.exe process. This event was seen in post exploitation tool WINPEAS that was used by Ransomware Prestige. Forfiles command lets you run a command on or pass arguments to multiple files. This Windows OS built-in tool being abused to list all files in specific directory or drive.", user="Administrator" 1686749492, search_name="ESCU - Windows Credentials in Registry Reg Query - Rule", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1552.002\",\"T1552\"],\"nist\":[\"DE.AE\"]}", annotations._all="Prestige Ransomware", annotations._all="T1552", annotations._all="Windows Post-Exploitation", annotations._all="CIS 10", annotations._all="T1552.002", annotations._all="Exploitation", annotations._all="DE.AE", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1552.002", annotations.mitre_attack="T1552", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:29:26", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749484.455125000", lastTime="2023-06-14T13:29:26", original_file_name="unknown", parent_process="C:\\Windows\\System32\\cmd.exe", parent_process_guid="null", parent_process_name="cmd.exe", process="C:\\Windows\\System32\\reg.exe query HKLM\\SYSTEM\\CurrentControlSet\\Services\\SNMP /s", process_guid="null", process_id="0x290", process_name="reg.exe", risk_message="reg query commandline C:\\Windows\\System32\\reg.exe query HKLM\\SYSTEM\\CurrentControlSet\\Services\\SNMP /s in ar-win-dc.attackrange.local", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="25.0", savedsearch_description="The following analytic identifies a process command line related to the discovery of possible password or credentials in the registry. This technique is being abused by adversaries or post exploitation tools like winpeas to steal credentials in the registry in the targeted host. Registry can contain several sensitive information like username and credentials that can be used for privilege escalation, persistence or even in lateral movement. This Anomaly detection can be a good pivot to detect a suspicious process querying a registry related to password or private keys.", user="Administrator" 1686749492, search_name="ESCU - Windows Credentials in Registry Reg Query - Rule", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1552.002\",\"T1552\"],\"nist\":[\"DE.AE\"]}", annotations._all="Prestige Ransomware", annotations._all="T1552", annotations._all="Windows Post-Exploitation", annotations._all="CIS 10", annotations._all="T1552.002", annotations._all="Exploitation", annotations._all="DE.AE", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1552.002", annotations.mitre_attack="T1552", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:29:26", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749484.455125000", lastTime="2023-06-14T13:29:26", original_file_name="unknown", parent_process="C:\\Windows\\System32\\cmd.exe", parent_process_guid="null", parent_process_name="cmd.exe", process="C:\\Windows\\System32\\reg.exe query HKEY_LOCAL_MACHINE\\SOFTWARE\\RealVNC\\WinVNC4 /v password", process_guid="null", process_id="0x14c0", process_name="reg.exe", risk_message="reg query commandline C:\\Windows\\System32\\reg.exe query HKEY_LOCAL_MACHINE\\SOFTWARE\\RealVNC\\WinVNC4 /v password in ar-win-dc.attackrange.local", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="25.0", savedsearch_description="The following analytic identifies a process command line related to the discovery of possible password or credentials in the registry. This technique is being abused by adversaries or post exploitation tools like winpeas to steal credentials in the registry in the targeted host. Registry can contain several sensitive information like username and credentials that can be used for privilege escalation, persistence or even in lateral movement. This Anomaly detection can be a good pivot to detect a suspicious process querying a registry related to password or private keys.", user="Administrator" 1686749492, search_name="ESCU - Windows Credentials in Registry Reg Query - Rule", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1552.002\",\"T1552\"],\"nist\":[\"DE.AE\"]}", annotations._all="Prestige Ransomware", annotations._all="T1552", annotations._all="Windows Post-Exploitation", annotations._all="CIS 10", annotations._all="T1552.002", annotations._all="Exploitation", annotations._all="DE.AE", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1552.002", annotations.mitre_attack="T1552", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:29:26", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749484.455125000", lastTime="2023-06-14T13:29:26", original_file_name="unknown", parent_process="C:\\Windows\\System32\\cmd.exe", parent_process_guid="null", parent_process_name="cmd.exe", process="C:\\Windows\\System32\\reg.exe query HKCU\\Software\\TightVNC\\Server", process_guid="null", process_id="0x1248", process_name="reg.exe", risk_message="reg query commandline C:\\Windows\\System32\\reg.exe query HKCU\\Software\\TightVNC\\Server in ar-win-dc.attackrange.local", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="25.0", savedsearch_description="The following analytic identifies a process command line related to the discovery of possible password or credentials in the registry. This technique is being abused by adversaries or post exploitation tools like winpeas to steal credentials in the registry in the targeted host. Registry can contain several sensitive information like username and credentials that can be used for privilege escalation, persistence or even in lateral movement. This Anomaly detection can be a good pivot to detect a suspicious process querying a registry related to password or private keys.", user="Administrator" 1686749492, search_name="ESCU - Windows Credentials in Registry Reg Query - Rule", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1552.002\",\"T1552\"],\"nist\":[\"DE.AE\"]}", annotations._all="Prestige Ransomware", annotations._all="T1552", annotations._all="Windows Post-Exploitation", annotations._all="CIS 10", annotations._all="T1552.002", annotations._all="Exploitation", annotations._all="DE.AE", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1552.002", annotations.mitre_attack="T1552", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:29:26", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749484.455125000", lastTime="2023-06-14T13:29:26", original_file_name="unknown", parent_process="C:\\Windows\\System32\\cmd.exe", parent_process_guid="null", parent_process_name="cmd.exe", process="C:\\Windows\\System32\\reg.exe query HKCU\\Software\\SimonTatham\\PuTTY\\Sessions /s", process_guid="null", process_id="0x6fc", process_name="reg.exe", risk_message="reg query commandline C:\\Windows\\System32\\reg.exe query HKCU\\Software\\SimonTatham\\PuTTY\\Sessions /s in ar-win-dc.attackrange.local", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="25.0", savedsearch_description="The following analytic identifies a process command line related to the discovery of possible password or credentials in the registry. This technique is being abused by adversaries or post exploitation tools like winpeas to steal credentials in the registry in the targeted host. Registry can contain several sensitive information like username and credentials that can be used for privilege escalation, persistence or even in lateral movement. This Anomaly detection can be a good pivot to detect a suspicious process querying a registry related to password or private keys.", user="Administrator" 1686749492, search_name="ESCU - Windows Credentials in Registry Reg Query - Rule", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1552.002\",\"T1552\"],\"nist\":[\"DE.AE\"]}", annotations._all="Prestige Ransomware", annotations._all="T1552", annotations._all="Windows Post-Exploitation", annotations._all="CIS 10", annotations._all="T1552.002", annotations._all="Exploitation", annotations._all="DE.AE", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1552.002", annotations.mitre_attack="T1552", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:29:26", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749484.455125000", lastTime="2023-06-14T13:29:26", original_file_name="unknown", parent_process="C:\\Windows\\System32\\cmd.exe", parent_process_guid="null", parent_process_name="cmd.exe", process="C:\\Windows\\System32\\reg.exe query HKCU\\Software\\OpenSSH\\Agent\\Keys /s", process_guid="null", process_id="0xb0c", process_name="reg.exe", risk_message="reg query commandline C:\\Windows\\System32\\reg.exe query HKCU\\Software\\OpenSSH\\Agent\\Keys /s in ar-win-dc.attackrange.local", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="25.0", savedsearch_description="The following analytic identifies a process command line related to the discovery of possible password or credentials in the registry. This technique is being abused by adversaries or post exploitation tools like winpeas to steal credentials in the registry in the targeted host. Registry can contain several sensitive information like username and credentials that can be used for privilege escalation, persistence or even in lateral movement. This Anomaly detection can be a good pivot to detect a suspicious process querying a registry related to password or private keys.", user="Administrator" 1686749492, search_name="ESCU - Windows Credentials in Registry Reg Query - Rule", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1552.002\",\"T1552\"],\"nist\":[\"DE.AE\"]}", annotations._all="Prestige Ransomware", annotations._all="T1552", annotations._all="Windows Post-Exploitation", annotations._all="CIS 10", annotations._all="T1552.002", annotations._all="Exploitation", annotations._all="DE.AE", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1552.002", annotations.mitre_attack="T1552", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:29:26", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749484.455125000", lastTime="2023-06-14T13:29:26", original_file_name="unknown", parent_process="C:\\Windows\\System32\\cmd.exe", parent_process_guid="null", parent_process_name="cmd.exe", process="C:\\Windows\\System32\\reg.exe query HKCU\\Software\\ORL\\WinVNC3\\Password", process_guid="null", process_id="0x938", process_name="reg.exe", risk_message="reg query commandline C:\\Windows\\System32\\reg.exe query HKCU\\Software\\ORL\\WinVNC3\\Password in ar-win-dc.attackrange.local", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="25.0", savedsearch_description="The following analytic identifies a process command line related to the discovery of possible password or credentials in the registry. This technique is being abused by adversaries or post exploitation tools like winpeas to steal credentials in the registry in the targeted host. Registry can contain several sensitive information like username and credentials that can be used for privilege escalation, persistence or even in lateral movement. This Anomaly detection can be a good pivot to detect a suspicious process querying a registry related to password or private keys.", user="Administrator" 1686749492, search_name="ESCU - Windows Credentials in Registry Reg Query - Rule", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1552.002\",\"T1552\"],\"nist\":[\"DE.AE\"]}", annotations._all="Prestige Ransomware", annotations._all="T1552", annotations._all="Windows Post-Exploitation", annotations._all="CIS 10", annotations._all="T1552.002", annotations._all="Exploitation", annotations._all="DE.AE", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1552.002", annotations.mitre_attack="T1552", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:29:26", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749484.455125000", lastTime="2023-06-14T13:29:26", original_file_name="reg.exe", parent_process="\"cmd.exe\" /s /k pushd \"C:\\Temp\"", parent_process_guid="{953948C6-BA8E-6489-C200-00000000F902}", parent_process_name="cmd.exe", process="reg query HKLM\\SYSTEM\\CurrentControlSet\\Services\\SNMP /s", process_guid="{953948C6-C0B6-6489-C718-00000000F902}", process_id="656", process_name="reg.exe", risk_message="reg query commandline reg query HKLM\\SYSTEM\\CurrentControlSet\\Services\\SNMP /s in ar-win-dc.attackrange.local", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="25.0", savedsearch_description="The following analytic identifies a process command line related to the discovery of possible password or credentials in the registry. This technique is being abused by adversaries or post exploitation tools like winpeas to steal credentials in the registry in the targeted host. Registry can contain several sensitive information like username and credentials that can be used for privilege escalation, persistence or even in lateral movement. This Anomaly detection can be a good pivot to detect a suspicious process querying a registry related to password or private keys.", user="Administrator" 1686749492, search_name="ESCU - Windows Credentials in Registry Reg Query - Rule", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1552.002\",\"T1552\"],\"nist\":[\"DE.AE\"]}", annotations._all="Prestige Ransomware", annotations._all="T1552", annotations._all="Windows Post-Exploitation", annotations._all="CIS 10", annotations._all="T1552.002", annotations._all="Exploitation", annotations._all="DE.AE", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1552.002", annotations.mitre_attack="T1552", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:29:26", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749484.455125000", lastTime="2023-06-14T13:29:26", original_file_name="reg.exe", parent_process="\"cmd.exe\" /s /k pushd \"C:\\Temp\"", parent_process_guid="{953948C6-BA8E-6489-C200-00000000F902}", parent_process_name="cmd.exe", process="reg query HKEY_LOCAL_MACHINE\\SOFTWARE\\RealVNC\\WinVNC4 /v password", process_guid="{953948C6-C0B6-6489-C418-00000000F902}", process_id="5312", process_name="reg.exe", risk_message="reg query commandline reg query HKEY_LOCAL_MACHINE\\SOFTWARE\\RealVNC\\WinVNC4 /v password in ar-win-dc.attackrange.local", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="25.0", savedsearch_description="The following analytic identifies a process command line related to the discovery of possible password or credentials in the registry. This technique is being abused by adversaries or post exploitation tools like winpeas to steal credentials in the registry in the targeted host. Registry can contain several sensitive information like username and credentials that can be used for privilege escalation, persistence or even in lateral movement. This Anomaly detection can be a good pivot to detect a suspicious process querying a registry related to password or private keys.", user="Administrator" 1686749492, search_name="ESCU - Windows Credentials in Registry Reg Query - Rule", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1552.002\",\"T1552\"],\"nist\":[\"DE.AE\"]}", annotations._all="Prestige Ransomware", annotations._all="T1552", annotations._all="Windows Post-Exploitation", annotations._all="CIS 10", annotations._all="T1552.002", annotations._all="Exploitation", annotations._all="DE.AE", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1552.002", annotations.mitre_attack="T1552", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:29:26", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749484.455125000", lastTime="2023-06-14T13:29:26", original_file_name="reg.exe", parent_process="\"cmd.exe\" /s /k pushd \"C:\\Temp\"", parent_process_guid="{953948C6-BA8E-6489-C200-00000000F902}", parent_process_name="cmd.exe", process="reg query HKCU\\Software\\TightVNC\\Server", process_guid="{953948C6-C0B6-6489-C818-00000000F902}", process_id="4680", process_name="reg.exe", risk_message="reg query commandline reg query HKCU\\Software\\TightVNC\\Server in ar-win-dc.attackrange.local", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="25.0", savedsearch_description="The following analytic identifies a process command line related to the discovery of possible password or credentials in the registry. This technique is being abused by adversaries or post exploitation tools like winpeas to steal credentials in the registry in the targeted host. Registry can contain several sensitive information like username and credentials that can be used for privilege escalation, persistence or even in lateral movement. This Anomaly detection can be a good pivot to detect a suspicious process querying a registry related to password or private keys.", user="Administrator" 1686749492, search_name="ESCU - Windows Credentials in Registry Reg Query - Rule", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1552.002\",\"T1552\"],\"nist\":[\"DE.AE\"]}", annotations._all="Prestige Ransomware", annotations._all="T1552", annotations._all="Windows Post-Exploitation", annotations._all="CIS 10", annotations._all="T1552.002", annotations._all="Exploitation", annotations._all="DE.AE", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1552.002", annotations.mitre_attack="T1552", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:29:26", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749484.455125000", lastTime="2023-06-14T13:29:26", original_file_name="reg.exe", parent_process="\"cmd.exe\" /s /k pushd \"C:\\Temp\"", parent_process_guid="{953948C6-BA8E-6489-C200-00000000F902}", parent_process_name="cmd.exe", process="reg query HKCU\\Software\\SimonTatham\\PuTTY\\Sessions /s", process_guid="{953948C6-C0B6-6489-C918-00000000F902}", process_id="1788", process_name="reg.exe", risk_message="reg query commandline reg query HKCU\\Software\\SimonTatham\\PuTTY\\Sessions /s in ar-win-dc.attackrange.local", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="25.0", savedsearch_description="The following analytic identifies a process command line related to the discovery of possible password or credentials in the registry. This technique is being abused by adversaries or post exploitation tools like winpeas to steal credentials in the registry in the targeted host. Registry can contain several sensitive information like username and credentials that can be used for privilege escalation, persistence or even in lateral movement. This Anomaly detection can be a good pivot to detect a suspicious process querying a registry related to password or private keys.", user="Administrator" 1686749492, search_name="ESCU - Windows Credentials in Registry Reg Query - Rule", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1552.002\",\"T1552\"],\"nist\":[\"DE.AE\"]}", annotations._all="Prestige Ransomware", annotations._all="T1552", annotations._all="Windows Post-Exploitation", annotations._all="CIS 10", annotations._all="T1552.002", annotations._all="Exploitation", annotations._all="DE.AE", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1552.002", annotations.mitre_attack="T1552", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:29:26", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749484.455125000", lastTime="2023-06-14T13:29:26", original_file_name="reg.exe", parent_process="\"cmd.exe\" /s /k pushd \"C:\\Temp\"", parent_process_guid="{953948C6-BA8E-6489-C200-00000000F902}", parent_process_name="cmd.exe", process="reg query HKCU\\Software\\OpenSSH\\Agent\\Keys /s", process_guid="{953948C6-C0B6-6489-CA18-00000000F902}", process_id="2828", process_name="reg.exe", risk_message="reg query commandline reg query HKCU\\Software\\OpenSSH\\Agent\\Keys /s in ar-win-dc.attackrange.local", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="25.0", savedsearch_description="The following analytic identifies a process command line related to the discovery of possible password or credentials in the registry. This technique is being abused by adversaries or post exploitation tools like winpeas to steal credentials in the registry in the targeted host. Registry can contain several sensitive information like username and credentials that can be used for privilege escalation, persistence or even in lateral movement. This Anomaly detection can be a good pivot to detect a suspicious process querying a registry related to password or private keys.", user="Administrator" 1686749492, search_name="ESCU - Windows Credentials in Registry Reg Query - Rule", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1552.002\",\"T1552\"],\"nist\":[\"DE.AE\"]}", annotations._all="Prestige Ransomware", annotations._all="T1552", annotations._all="Windows Post-Exploitation", annotations._all="CIS 10", annotations._all="T1552.002", annotations._all="Exploitation", annotations._all="DE.AE", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1552.002", annotations.mitre_attack="T1552", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:29:26", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749484.455125000", lastTime="2023-06-14T13:29:26", original_file_name="reg.exe", parent_process="\"cmd.exe\" /s /k pushd \"C:\\Temp\"", parent_process_guid="{953948C6-BA8E-6489-C200-00000000F902}", parent_process_name="cmd.exe", process="reg query HKCU\\Software\\ORL\\WinVNC3\\Password", process_guid="{953948C6-C0B6-6489-C318-00000000F902}", process_id="2360", process_name="reg.exe", risk_message="reg query commandline reg query HKCU\\Software\\ORL\\WinVNC3\\Password in ar-win-dc.attackrange.local", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="25.0", savedsearch_description="The following analytic identifies a process command line related to the discovery of possible password or credentials in the registry. This technique is being abused by adversaries or post exploitation tools like winpeas to steal credentials in the registry in the targeted host. Registry can contain several sensitive information like username and credentials that can be used for privilege escalation, persistence or even in lateral movement. This Anomaly detection can be a good pivot to detect a suspicious process querying a registry related to password or private keys.", user="Administrator" 1686749471, search_name="ESCU - Windows Credentials from Password Stores Query - Rule", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1555\"],\"nist\":[\"DE.AE\"]}", annotations._all="Windows Post-Exploitation", annotations._all="Exploitation", annotations._all="Prestige Ransomware", annotations._all="CIS 10", annotations._all="DE.AE", annotations._all="T1555", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1555", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:29:23", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749464.107628000", lastTime="2023-06-14T13:29:23", original_file_name="unknown", parent_process="C:\\Windows\\System32\\cmd.exe", parent_process_guid="null", parent_process_name="cmd.exe", process="C:\\Windows\\System32\\cmdkey.exe /list", process_guid="null", process_id="0x88c", process_name="cmdkey.exe", risk_message="a process cmdkey.exe was executed in ar-win-dc.attackrange.local to display stored username and credentials.", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="25.0", savedsearch_description="The following analytic identifies a process execution of Windows OS cmdkey.exe tool. This tool is being abused or used by several post exploitation tool such as winpeas that being used by ransomware prestige to list stored user names, passwords or credentials in the targeted Windows OS host. This information can be used by the attacker to gain privilege escalation and persistence in the targeted hosts for further attacks.", user="Administrator" 1686749471, search_name="ESCU - Windows Credentials from Password Stores Query - Rule", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1555\"],\"nist\":[\"DE.AE\"]}", annotations._all="Windows Post-Exploitation", annotations._all="Exploitation", annotations._all="Prestige Ransomware", annotations._all="CIS 10", annotations._all="DE.AE", annotations._all="T1555", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1555", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:29:23", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749464.107628000", lastTime="2023-06-14T13:29:23", original_file_name="cmdkey.exe", parent_process="\"cmd.exe\" /s /k pushd \"C:\\Temp\"", parent_process_guid="{953948C6-BA8E-6489-C200-00000000F902}", parent_process_name="cmd.exe", process="cmdkey /list", process_guid="{953948C6-C0B3-6489-A518-00000000F902}", process_id="2188", process_name="cmdkey.exe", risk_message="a process cmdkey.exe was executed in ar-win-dc.attackrange.local to display stored username and credentials.", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="25.0", savedsearch_description="The following analytic identifies a process execution of Windows OS cmdkey.exe tool. This tool is being abused or used by several post exploitation tool such as winpeas that being used by ransomware prestige to list stored user names, passwords or credentials in the targeted Windows OS host. This information can be used by the attacker to gain privilege escalation and persistence in the targeted hosts for further attacks.", user="Administrator" 1686749457, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Exploitation", annotations._all="Living Off The Land", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:59", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749452.000280000", lastTime="2023-06-14T13:28:59", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO.0x1B[32m[*]0x1B[97m SERVICE VULNERABILITIES\"", parent_process_id="6432", parent_process_name="forfiles.exe", process="/C ECHO.\\x1B[32m[*]\\x1B[97m SERVICE VULNERABILITIES", process_id="5860", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749457, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Exploitation", annotations._all="Living Off The Land", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:54", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749452.000280000", lastTime="2023-06-14T13:28:54", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO.0x1B[32m[*]0x1B[97m NETWORK\"", parent_process_id="1944", parent_process_name="forfiles.exe", process="/C ECHO.\\x1B[32m[*]\\x1B[97m NETWORK", process_id="5924", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749457, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Exploitation", annotations._all="Living Off The Land", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:29:23", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749452.000280000", lastTime="2023-06-14T13:29:23", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO.0x1B[32m[*]0x1B[97m DLL HIJACKING in PATHenv variable\"", parent_process_id="1932", parent_process_name="forfiles.exe", process="/C ECHO.\\x1B[32m[*]\\x1B[97m DLL HIJACKING in PATHenv variable", process_id="6908", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749457, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Exploitation", annotations._all="Living Off The Land", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:29:23", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749452.000280000", lastTime="2023-06-14T13:29:23", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO.0x1B[32m[*]0x1B[97m CREDENTIALS\"", parent_process_id="1764", parent_process_name="forfiles.exe", process="/C ECHO.\\x1B[32m[*]\\x1B[97m CREDENTIALS", process_id="912", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749457, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Exploitation", annotations._all="Living Off The Land", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:56", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749452.000280000", lastTime="2023-06-14T13:28:56", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO.0x1B[32m[*]0x1B[97m BASIC USER INFO\"", parent_process_id="5640", parent_process_name="forfiles.exe", process="/C ECHO.\\x1B[32m[*]\\x1B[97m BASIC USER INFO", process_id="7164", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749457, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Exploitation", annotations._all="Living Off The Land", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:51", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749452.000280000", lastTime="2023-06-14T13:28:51", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m WSUS\"", parent_process_id="4572", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m WSUS", process_id="6456", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749457, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Exploitation", annotations._all="Living Off The Land", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:29:23", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749452.000280000", lastTime="2023-06-14T13:29:23", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m WINDOWS VAULT\"", parent_process_id="4816", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m WINDOWS VAULT", process_id="3796", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749457, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Exploitation", annotations._all="Living Off The Land", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:56", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749452.000280000", lastTime="2023-06-14T13:28:56", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m WIFI\"", parent_process_id="6436", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m WIFI", process_id="5996", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749457, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Exploitation", annotations._all="Living Off The Land", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:50", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749452.000280000", lastTime="2023-06-14T13:28:50", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m WEF Settings\"", parent_process_id="3784", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m WEF Settings", process_id="6208", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749457, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Exploitation", annotations._all="Living Off The Land", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:50", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749452.000280000", lastTime="2023-06-14T13:28:50", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m WDigest?\"", parent_process_id="4736", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m WDigest?", process_id="4444", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749457, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Exploitation", annotations._all="Living Off The Land", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:29:24", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749452.000280000", lastTime="2023-06-14T13:29:24", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Unattended files\"", parent_process_id="5996", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m Unattended files", process_id="6228", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749457, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Exploitation", annotations._all="Living Off The Land", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:56", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749452.000280000", lastTime="2023-06-14T13:28:56", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m USERS\"", parent_process_id="6440", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m USERS", process_id="4112", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749457, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Exploitation", annotations._all="Living Off The Land", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:55", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749452.000280000", lastTime="2023-06-14T13:28:55", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m USED PORTS\"", parent_process_id="3796", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m USED PORTS", process_id="2336", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749457, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Exploitation", annotations._all="Living Off The Land", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:29:17", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749452.000280000", lastTime="2023-06-14T13:29:17", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m UNQUOTED SERVICE PATHS\"", parent_process_id="2108", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m UNQUOTED SERVICE PATHS", process_id="6908", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749457, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Exploitation", annotations._all="Living Off The Land", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:50", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749452.000280000", lastTime="2023-06-14T13:28:50", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m UAC Settings\"", parent_process_id="4880", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m UAC Settings", process_id="5724", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749457, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Exploitation", annotations._all="Living Off The Land", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:59", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749452.000280000", lastTime="2023-06-14T13:28:59", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m SERVICE BINARY PERMISSIONS WITH WMIC and ICACLS\"", parent_process_id="968", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m SERVICE BINARY PERMISSIONS WITH WMIC and ICACLS", process_id="4272", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749457, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Exploitation", annotations._all="Living Off The Land", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:29:24", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749452.000280000", lastTime="2023-06-14T13:29:24", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m SAM and SYSTEM backups\"", parent_process_id="2804", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m SAM and SYSTEM backups", process_id="1096", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749457, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Exploitation", annotations._all="Living Off The Land", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:51", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749452.000280000", lastTime="2023-06-14T13:28:51", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Remote Desktop Credentials Manager\"", parent_process_id="5544", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m Remote Desktop Credentials Manager", process_id="6708", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749457, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Exploitation", annotations._all="Living Off The Land", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:50", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749452.000280000", lastTime="2023-06-14T13:28:50", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Registered Anti-Virus(AV)\"", parent_process_id="5676", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m Registered Anti-Virus(AV)", process_id="6372", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749457, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Exploitation", annotations._all="Living Off The Land", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:51", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749452.000280000", lastTime="2023-06-14T13:28:51", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m RUNNING PROCESSES\"", parent_process_id="4280", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m RUNNING PROCESSES", process_id="6740", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749457, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Exploitation", annotations._all="Living Off The Land", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:54", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749452.000280000", lastTime="2023-06-14T13:28:54", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m RUN AT STARTUP\"", parent_process_id="1892", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m RUN AT STARTUP", process_id="4192", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749457, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Exploitation", annotations._all="Living Off The Land", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:55", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749452.000280000", lastTime="2023-06-14T13:28:55", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m ROUTES\"", parent_process_id="5012", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m ROUTES", process_id="4176", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749457, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Exploitation", annotations._all="Living Off The Land", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:50", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749452.000280000", lastTime="2023-06-14T13:28:50", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m PowerShell settings\"", parent_process_id="3540", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m PowerShell settings", process_id="6228", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749457, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Exploitation", annotations._all="Living Off The Land", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:50", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749452.000280000", lastTime="2023-06-14T13:28:50", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Number of cached creds\"", parent_process_id="4400", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m Number of cached creds", process_id="6348", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749457, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Exploitation", annotations._all="Living Off The Land", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:29:24", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749452.000280000", lastTime="2023-06-14T13:29:24", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m McAffee SiteList.xml\"", parent_process_id="4652", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m McAffee SiteList.xml", process_id="1620", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749457, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Exploitation", annotations._all="Living Off The Land", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:50", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749452.000280000", lastTime="2023-06-14T13:28:50", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m MOUNTED DISKS\"", parent_process_id="3244", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m MOUNTED DISKS", process_id="5640", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749457, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Exploitation", annotations._all="Living Off The Land", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:50", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749452.000280000", lastTime="2023-06-14T13:28:50", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m LSA protection?\"", parent_process_id="1268", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m LSA protection?", process_id="4036", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749457, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Exploitation", annotations._all="Living Off The Land", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:50", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749452.000280000", lastTime="2023-06-14T13:28:50", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m LAPS installed?\"", parent_process_id="6012", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m LAPS installed?", process_id="6756", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749457, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Exploitation", annotations._all="Living Off The Land", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:58", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749452.000280000", lastTime="2023-06-14T13:28:58", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Kerberos Tickets\"", parent_process_id="3440", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m Kerberos Tickets", process_id="4028", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749457, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Exploitation", annotations._all="Living Off The Land", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:54", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749452.000280000", lastTime="2023-06-14T13:28:54", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m INTERFACES\"", parent_process_id="2144", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m INTERFACES", process_id="4016", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749457, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Exploitation", annotations._all="Living Off The Land", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:51", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749452.000280000", lastTime="2023-06-14T13:28:51", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m INSTALLED SOFTWARE\"", parent_process_id="5312", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m INSTALLED SOFTWARE", process_id="6852", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749457, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Exploitation", annotations._all="Living Off The Land", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:56", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749452.000280000", lastTime="2023-06-14T13:28:56", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Hosts file\"", parent_process_id="6356", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m Hosts file", process_id="6448", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749457, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Exploitation", annotations._all="Living Off The Land", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:58", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749452.000280000", lastTime="2023-06-14T13:28:58", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m GROUPS\"", parent_process_id="6708", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m GROUPS", process_id="5544", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749457, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Exploitation", annotations._all="Living Off The Land", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:29:25", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749452.000280000", lastTime="2023-06-14T13:29:25", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m GPP Password\"", parent_process_id="6768", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m GPP Password", process_id="1820", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749457, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Exploitation", annotations._all="Living Off The Land", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:29:26", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749452.000280000", lastTime="2023-06-14T13:29:26", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Files in registry that may contain credentials\"", parent_process_id="464", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m Files in registry that may contain credentials", process_id="6340", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749457, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Exploitation", annotations._all="Living Off The Land", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:55", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749452.000280000", lastTime="2023-06-14T13:28:55", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m FIREWALL\"", parent_process_id="4268", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m FIREWALL", process_id="2188", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749457, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Exploitation", annotations._all="Living Off The Land", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:51", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749452.000280000", lastTime="2023-06-14T13:28:51", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m ENVIRONMENT\"", parent_process_id="2368", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m ENVIRONMENT", process_id="2252", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749457, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Exploitation", annotations._all="Living Off The Land", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:29:24", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749452.000280000", lastTime="2023-06-14T13:29:24", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m DPAPI MASTER KEYS\"", parent_process_id="4408", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m DPAPI MASTER KEYS", process_id="4168", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749457, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Exploitation", annotations._all="Living Off The Land", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:29:23", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749452.000280000", lastTime="2023-06-14T13:29:23", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m DPAPI MASTER KEYS\"", parent_process_id="396", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m DPAPI MASTER KEYS", process_id="4104", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749457, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Exploitation", annotations._all="Living Off The Land", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:56", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749452.000280000", lastTime="2023-06-14T13:28:56", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m DNS CACHE\"", parent_process_id="5728", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m DNS CACHE", process_id="2812", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749457, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Exploitation", annotations._all="Living Off The Land", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:50", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749452.000280000", lastTime="2023-06-14T13:28:50", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m DATE and TIME\"", parent_process_id="4272", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m DATE and TIME", process_id="5680", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749457, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Exploitation", annotations._all="Living Off The Land", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:50", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749452.000280000", lastTime="2023-06-14T13:28:50", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Credential Guard?\"", parent_process_id="1260", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m Credential Guard?", process_id="1604", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749457, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Exploitation", annotations._all="Living Off The Land", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:29:26", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749452.000280000", lastTime="2023-06-14T13:29:26", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Cloud Credentials\"", parent_process_id="2368", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m Cloud Credentials", process_id="6400", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749457, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Exploitation", annotations._all="Living Off The Land", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:56", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749452.000280000", lastTime="2023-06-14T13:28:56", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m CURRENT USER\"", parent_process_id="6340", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m CURRENT USER", process_id="7140", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749457, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Exploitation", annotations._all="Living Off The Land", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:54", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749452.000280000", lastTime="2023-06-14T13:28:54", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m CURRENT SHARES\"", parent_process_id="1132", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m CURRENT SHARES", process_id="5648", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749457, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Exploitation", annotations._all="Living Off The Land", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:58", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749452.000280000", lastTime="2023-06-14T13:28:58", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m CURRENT LOGGED USERS\"", parent_process_id="4956", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m CURRENT LOGGED USERS", process_id="4280", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749457, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Exploitation", annotations._all="Living Off The Land", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:59", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749452.000280000", lastTime="2023-06-14T13:28:59", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m CURRENT CLIPBOARD\"", parent_process_id="3016", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m CURRENT CLIPBOARD", process_id="1688", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749457, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Exploitation", annotations._all="Living Off The Land", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:29:00", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749452.000280000", lastTime="2023-06-14T13:29:00", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m CHECK IF YOU CAN MODIFY ANY SERVICE REGISTRY\"", parent_process_id="5728", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m CHECK IF YOU CAN MODIFY ANY SERVICE REGISTRY", process_id="6792", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749457, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Exploitation", annotations._all="Living Off The Land", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:50", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749452.000280000", lastTime="2023-06-14T13:28:50", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Audit Settings\"", parent_process_id="6136", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m Audit Settings", process_id="6380", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749457, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Exploitation", annotations._all="Living Off The Land", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:29:26", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749452.000280000", lastTime="2023-06-14T13:29:26", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m AppCmd\"", parent_process_id="5688", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m AppCmd", process_id="4704", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749457, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Exploitation", annotations._all="Living Off The Land", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:54", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749452.000280000", lastTime="2023-06-14T13:28:54", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m AlwaysInstallElevated?\"", parent_process_id="7156", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m AlwaysInstallElevated?", process_id="1920", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749457, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Exploitation", annotations._all="Living Off The Land", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:55", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749452.000280000", lastTime="2023-06-14T13:28:55", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m ARP\"", parent_process_id="4840", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m ARP", process_id="5824", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749457, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Exploitation", annotations._all="Living Off The Land", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:58", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749452.000280000", lastTime="2023-06-14T13:28:58", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m ADMINISTRATORS GROUPS\"", parent_process_id="1804", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m ADMINISTRATORS GROUPS", process_id="4116", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749457, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Exploitation", annotations._all="Living Off The Land", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:59", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749452.000280000", lastTime="2023-06-14T13:28:59", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO.0x1B[32m[*]0x1B[97m SERVICE VULNERABILITIES\"", parent_process_id="6572", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO.0x1B[32m[*]0x1B[97m SERVICE VULNERABILITIES\"", process_id="6432", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749457, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Exploitation", annotations._all="Living Off The Land", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:54", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749452.000280000", lastTime="2023-06-14T13:28:54", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO.0x1B[32m[*]0x1B[97m NETWORK\"", parent_process_id="1428", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO.0x1B[32m[*]0x1B[97m NETWORK\"", process_id="1944", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749457, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Exploitation", annotations._all="Living Off The Land", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:29:23", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749452.000280000", lastTime="2023-06-14T13:29:23", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO.0x1B[32m[*]0x1B[97m DLL HIJACKING in PATHenv variable\"", parent_process_id="6948", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO.0x1B[32m[*]0x1B[97m DLL HIJACKING in PATHenv variable\"", process_id="1932", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749457, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Exploitation", annotations._all="Living Off The Land", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:29:23", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749452.000280000", lastTime="2023-06-14T13:29:23", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO.0x1B[32m[*]0x1B[97m CREDENTIALS\"", parent_process_id="4804", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO.0x1B[32m[*]0x1B[97m CREDENTIALS\"", process_id="1764", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749457, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Exploitation", annotations._all="Living Off The Land", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:56", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749452.000280000", lastTime="2023-06-14T13:28:56", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO.0x1B[32m[*]0x1B[97m BASIC USER INFO\"", parent_process_id="5964", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO.0x1B[32m[*]0x1B[97m BASIC USER INFO\"", process_id="5640", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749457, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Exploitation", annotations._all="Living Off The Land", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:51", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749452.000280000", lastTime="2023-06-14T13:28:51", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m WSUS\"", parent_process_id="1168", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m WSUS\"", process_id="4572", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749457, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Exploitation", annotations._all="Living Off The Land", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:29:23", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749452.000280000", lastTime="2023-06-14T13:29:23", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m WINDOWS VAULT\"", parent_process_id="2960", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m WINDOWS VAULT\"", process_id="4816", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749457, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Exploitation", annotations._all="Living Off The Land", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:56", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749452.000280000", lastTime="2023-06-14T13:28:56", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m WIFI\"", parent_process_id="4264", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m WIFI\"", process_id="6436", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749457, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Exploitation", annotations._all="Living Off The Land", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:50", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749452.000280000", lastTime="2023-06-14T13:28:50", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m WEF Settings\"", parent_process_id="5648", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m WEF Settings\"", process_id="3784", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749457, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Exploitation", annotations._all="Living Off The Land", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:50", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749452.000280000", lastTime="2023-06-14T13:28:50", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m WDigest?\"", parent_process_id="6532", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m WDigest?\"", process_id="4736", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749457, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Exploitation", annotations._all="Living Off The Land", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:29:24", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749452.000280000", lastTime="2023-06-14T13:29:24", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Unattended files\"", parent_process_id="1100", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Unattended files\"", process_id="5996", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749457, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Exploitation", annotations._all="Living Off The Land", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:56", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749452.000280000", lastTime="2023-06-14T13:28:56", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m USERS\"", parent_process_id="1516", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m USERS\"", process_id="6440", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749457, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Exploitation", annotations._all="Living Off The Land", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:54", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749452.000280000", lastTime="2023-06-14T13:28:54", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m USED PORTS\"", parent_process_id="2460", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m USED PORTS\"", process_id="3796", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749457, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Exploitation", annotations._all="Living Off The Land", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:29:17", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749452.000280000", lastTime="2023-06-14T13:29:17", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m UNQUOTED SERVICE PATHS\"", parent_process_id="3668", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m UNQUOTED SERVICE PATHS\"", process_id="2108", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749457, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Exploitation", annotations._all="Living Off The Land", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:50", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749452.000280000", lastTime="2023-06-14T13:28:50", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m UAC Settings\"", parent_process_id="3584", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m UAC Settings\"", process_id="4880", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749457, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Exploitation", annotations._all="Living Off The Land", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:59", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749452.000280000", lastTime="2023-06-14T13:28:59", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m SERVICE BINARY PERMISSIONS WITH WMIC and ICACLS\"", parent_process_id="816", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m SERVICE BINARY PERMISSIONS WITH WMIC and ICACLS\"", process_id="968", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749457, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Exploitation", annotations._all="Living Off The Land", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:29:24", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749452.000280000", lastTime="2023-06-14T13:29:24", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m SAM and SYSTEM backups\"", parent_process_id="2284", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m SAM and SYSTEM backups\"", process_id="2804", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749457, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Exploitation", annotations._all="Living Off The Land", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:51", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749452.000280000", lastTime="2023-06-14T13:28:51", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Remote Desktop Credentials Manager\"", parent_process_id="600", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Remote Desktop Credentials Manager\"", process_id="5544", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749457, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Exploitation", annotations._all="Living Off The Land", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:50", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749452.000280000", lastTime="2023-06-14T13:28:50", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Registered Anti-Virus(AV)\"", parent_process_id="6556", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Registered Anti-Virus(AV)\"", process_id="5676", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749457, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Exploitation", annotations._all="Living Off The Land", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:51", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749452.000280000", lastTime="2023-06-14T13:28:51", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m RUNNING PROCESSES\"", parent_process_id="8", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m RUNNING PROCESSES\"", process_id="4280", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749457, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Exploitation", annotations._all="Living Off The Land", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:53", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749452.000280000", lastTime="2023-06-14T13:28:53", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m RUN AT STARTUP\"", parent_process_id="4572", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m RUN AT STARTUP\"", process_id="1892", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749457, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Exploitation", annotations._all="Living Off The Land", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:55", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749452.000280000", lastTime="2023-06-14T13:28:55", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m ROUTES\"", parent_process_id="6420", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m ROUTES\"", process_id="5012", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749457, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Exploitation", annotations._all="Living Off The Land", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:50", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749452.000280000", lastTime="2023-06-14T13:28:50", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m PowerShell settings\"", parent_process_id="3472", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m PowerShell settings\"", process_id="3540", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749457, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Exploitation", annotations._all="Living Off The Land", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:50", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749452.000280000", lastTime="2023-06-14T13:28:50", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Number of cached creds\"", parent_process_id="4388", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Number of cached creds\"", process_id="4400", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749457, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Exploitation", annotations._all="Living Off The Land", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:29:24", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749452.000280000", lastTime="2023-06-14T13:29:24", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m McAffee SiteList.xml\"", parent_process_id="6336", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m McAffee SiteList.xml\"", process_id="4652", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749457, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Exploitation", annotations._all="Living Off The Land", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:50", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749452.000280000", lastTime="2023-06-14T13:28:50", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m MOUNTED DISKS\"", parent_process_id="3880", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m MOUNTED DISKS\"", process_id="3244", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749457, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Exploitation", annotations._all="Living Off The Land", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:50", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749452.000280000", lastTime="2023-06-14T13:28:50", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m LSA protection?\"", parent_process_id="1880", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m LSA protection?\"", process_id="1268", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749457, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Exploitation", annotations._all="Living Off The Land", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:50", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749452.000280000", lastTime="2023-06-14T13:28:50", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m LAPS installed?\"", parent_process_id="1912", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m LAPS installed?\"", process_id="6012", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749457, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Exploitation", annotations._all="Living Off The Land", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:58", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749452.000280000", lastTime="2023-06-14T13:28:58", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Kerberos Tickets\"", parent_process_id="1980", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Kerberos Tickets\"", process_id="3440", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749457, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Exploitation", annotations._all="Living Off The Land", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:54", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749452.000280000", lastTime="2023-06-14T13:28:54", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m INTERFACES\"", parent_process_id="3136", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m INTERFACES\"", process_id="2144", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749457, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Exploitation", annotations._all="Living Off The Land", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:51", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749452.000280000", lastTime="2023-06-14T13:28:51", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m INSTALLED SOFTWARE\"", parent_process_id="5708", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m INSTALLED SOFTWARE\"", process_id="5312", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749457, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Exploitation", annotations._all="Living Off The Land", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:56", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749452.000280000", lastTime="2023-06-14T13:28:56", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Hosts file\"", parent_process_id="3584", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Hosts file\"", process_id="6356", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749457, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Exploitation", annotations._all="Living Off The Land", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:58", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749452.000280000", lastTime="2023-06-14T13:28:58", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m GROUPS\"", parent_process_id="524", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m GROUPS\"", process_id="6708", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749457, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Exploitation", annotations._all="Living Off The Land", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:29:25", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749452.000280000", lastTime="2023-06-14T13:29:25", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m GPP Password\"", parent_process_id="7068", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m GPP Password\"", process_id="6768", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749457, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Exploitation", annotations._all="Living Off The Land", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:29:26", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749452.000280000", lastTime="2023-06-14T13:29:26", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Files in registry that may contain credentials\"", parent_process_id="6976", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Files in registry that may contain credentials\"", process_id="464", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749457, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Exploitation", annotations._all="Living Off The Land", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:55", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749452.000280000", lastTime="2023-06-14T13:28:55", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m FIREWALL\"", parent_process_id="1260", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m FIREWALL\"", process_id="4268", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749457, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Exploitation", annotations._all="Living Off The Land", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:51", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749452.000280000", lastTime="2023-06-14T13:28:51", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m ENVIRONMENT\"", parent_process_id="6944", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m ENVIRONMENT\"", process_id="2368", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749457, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Exploitation", annotations._all="Living Off The Land", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:29:24", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749452.000280000", lastTime="2023-06-14T13:29:24", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m DPAPI MASTER KEYS\"", parent_process_id="6016", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m DPAPI MASTER KEYS\"", process_id="4408", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749457, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Exploitation", annotations._all="Living Off The Land", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:29:23", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749452.000280000", lastTime="2023-06-14T13:29:23", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m DPAPI MASTER KEYS\"", parent_process_id="2336", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m DPAPI MASTER KEYS\"", process_id="396", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749457, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Exploitation", annotations._all="Living Off The Land", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:56", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749452.000280000", lastTime="2023-06-14T13:28:56", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m DNS CACHE\"", parent_process_id="4172", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m DNS CACHE\"", process_id="5728", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749457, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Exploitation", annotations._all="Living Off The Land", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:50", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749452.000280000", lastTime="2023-06-14T13:28:50", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m DATE and TIME\"", parent_process_id="3652", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m DATE and TIME\"", process_id="4272", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749457, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Exploitation", annotations._all="Living Off The Land", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:50", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749452.000280000", lastTime="2023-06-14T13:28:50", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Credential Guard?\"", parent_process_id="4088", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Credential Guard?\"", process_id="1260", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749457, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Exploitation", annotations._all="Living Off The Land", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:29:26", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749452.000280000", lastTime="2023-06-14T13:29:26", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Cloud Credentials\"", parent_process_id="5992", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Cloud Credentials\"", process_id="2368", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749457, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Exploitation", annotations._all="Living Off The Land", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:56", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749452.000280000", lastTime="2023-06-14T13:28:56", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m CURRENT USER\"", parent_process_id="6932", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m CURRENT USER\"", process_id="6340", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749457, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Exploitation", annotations._all="Living Off The Land", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:54", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749452.000280000", lastTime="2023-06-14T13:28:54", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m CURRENT SHARES\"", parent_process_id="1876", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m CURRENT SHARES\"", process_id="1132", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749457, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Exploitation", annotations._all="Living Off The Land", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:58", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749452.000280000", lastTime="2023-06-14T13:28:58", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m CURRENT LOGGED USERS\"", parent_process_id="6328", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m CURRENT LOGGED USERS\"", process_id="4956", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749457, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Exploitation", annotations._all="Living Off The Land", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:59", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749452.000280000", lastTime="2023-06-14T13:28:59", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m CURRENT CLIPBOARD\"", parent_process_id="2016", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m CURRENT CLIPBOARD\"", process_id="3016", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749457, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Exploitation", annotations._all="Living Off The Land", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:29:00", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749452.000280000", lastTime="2023-06-14T13:29:00", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m CHECK IF YOU CAN MODIFY ANY SERVICE REGISTRY\"", parent_process_id="1472", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m CHECK IF YOU CAN MODIFY ANY SERVICE REGISTRY\"", process_id="5728", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749457, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Exploitation", annotations._all="Living Off The Land", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:50", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749452.000280000", lastTime="2023-06-14T13:28:50", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Audit Settings\"", parent_process_id="6824", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Audit Settings\"", process_id="6136", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749457, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Exploitation", annotations._all="Living Off The Land", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:29:26", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749452.000280000", lastTime="2023-06-14T13:29:26", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m AppCmd\"", parent_process_id="7164", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m AppCmd\"", process_id="5688", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749457, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Exploitation", annotations._all="Living Off The Land", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:54", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749452.000280000", lastTime="2023-06-14T13:28:54", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m AlwaysInstallElevated?\"", parent_process_id="6912", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m AlwaysInstallElevated?\"", process_id="7156", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749457, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Exploitation", annotations._all="Living Off The Land", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:55", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749452.000280000", lastTime="2023-06-14T13:28:55", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m ARP\"", parent_process_id="3404", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m ARP\"", process_id="4840", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749457, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Exploitation", annotations._all="Living Off The Land", annotations._all="DE.CM", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:58", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749452.000280000", lastTime="2023-06-14T13:28:58", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m ADMINISTRATORS GROUPS\"", parent_process_id="1892", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m ADMINISTRATORS GROUPS\"", process_id="1804", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749437, search_name="ESCU - Windows Cached Domain Credentials Reg Query - Rule", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":30,\"impact\":30,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1003.005\",\"T1003\"],\"nist\":[\"DE.AE\"]}", annotations._all="T1003.005", annotations._all="DE.AE", annotations._all="Prestige Ransomware", annotations._all="Windows Post-Exploitation", annotations._all="T1003", annotations._all="Exploitation", annotations._all="CIS 10", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1003.005", annotations.mitre_attack="T1003", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:50", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749431.237554000", lastTime="2023-06-14T13:28:50", original_file_name="unknown", parent_process="C:\\Windows\\System32\\cmd.exe", parent_process_guid="null", parent_process_name="cmd.exe", process="C:\\Windows\\System32\\reg.exe query \"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\" /v CACHEDLOGONSCOUNT", process_guid="null", process_id="0x14c4", process_name="reg.exe", risk_message="a process with commandline C:\\Windows\\System32\\reg.exe query \"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\" /v CACHEDLOGONSCOUNT tries to retrieve cache domain credential logon count in ar-win-dc.attackrange.local", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="9.0", savedsearch_description="The following analytic identifies a process command line related to the discovery of cache domain credential logon count in the registry. This Technique was being abused by several post exploitation tool like Winpeas where it query CachedLogonsCount registry value in Winlogon registry. This value can be good information about the login caching setting on the Windows OS target host. A value of 0 means login caching is disable and values > 50 caches only 50 login attempts. By default all versions of Windows 10 save cached logins except Windows Server 2008.", user="Administrator" 1686749437, search_name="ESCU - Windows Cached Domain Credentials Reg Query - Rule", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":30,\"impact\":30,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1003.005\",\"T1003\"],\"nist\":[\"DE.AE\"]}", annotations._all="T1003.005", annotations._all="DE.AE", annotations._all="Prestige Ransomware", annotations._all="Windows Post-Exploitation", annotations._all="T1003", annotations._all="Exploitation", annotations._all="CIS 10", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1003.005", annotations.mitre_attack="T1003", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:28:50", info_max_time="1686749400.000000000", info_min_time="1686748800.000000000", info_search_time="1686749431.237554000", lastTime="2023-06-14T13:28:50", original_file_name="reg.exe", parent_process="\"cmd.exe\" /s /k pushd \"C:\\Temp\"", parent_process_guid="{953948C6-BA8E-6489-C200-00000000F902}", parent_process_name="cmd.exe", process="reg query \"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\" /v CACHEDLOGONSCOUNT", process_guid="{953948C6-C092-6489-330E-00000000F902}", process_id="5316", process_name="reg.exe", risk_message="a process with commandline reg query \"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\" /v CACHEDLOGONSCOUNT tries to retrieve cache domain credential logon count in ar-win-dc.attackrange.local", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="9.0", savedsearch_description="The following analytic identifies a process command line related to the discovery of cache domain credential logon count in the registry. This Technique was being abused by several post exploitation tool like Winpeas where it query CachedLogonsCount registry value in Winlogon registry. This value can be good information about the login caching setting on the Windows OS target host. A value of 0 means login caching is disable and values > 50 caches only 50 login attempts. By default all versions of Windows 10 save cached logins except Windows Server 2008.", user="Administrator" 1686748560, search_name="ESCU - Windows Indirect Command Execution Via Series Of Forfiles - Rule", orig_time="1686748560", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":30,\"impact\":30,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.AE\"]}", annotations._all="Prestige Ransomware", annotations._all="Exploitation", annotations._all="CIS 10", annotations._all="DE.AE", annotations._all="Windows Post-Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.AE", count="31", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:25", info_max_time="1686749100.000000000", info_min_time="1686748500.000000000", info_search_time="1686749217.163385000", lastTime="2023-06-14T13:16:26", parent_process="C:\\Windows\\System32\\cmd.exe", parent_process_name="cmd.exe", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m(((((((((((((((((((((((((((/0x1B[97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m(((((((((/,. 0x1B[92m,*//////*,.0x1B[32m ./(((((((((((.0x1B[97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m((,.,/((((((((((((((((((((/, */0x1B[97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m(((((((((/, 0x1B[92m,####################(0x1B[32m/..((((((((((.0x1B[97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m,/*,..*(((((((((((((((((((((((((((((((((,0x1B[97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m((((((((((((((((* 0x1B[94m*****0x1B[32m,,,/########## 0x1B[32m.(* ,((((((0x1B[97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m(((((((((((/* 0x1B[94m******************0x1B[32m/####### 0x1B[32m.(. ((((((0x1B[97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m(((((((((. ,0x1B[92m(############################(0x1B[32m../(((((((((.0x1B[97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m((((((.0x1B[92m.0x1B[94m******************0x1B[97m/@@@@@/0x1B[94m***0x1B[92m/######0x1B[32m /((((((0x1B[97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m, ,0x1B[92m0x1B[94m**********************0x1B[97m#@@@@@#@@@@0x1B[94m*********0x1B[92m##0x1B[32m((/ /((((0x1B[97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m,*/((((((((((((((((((/, 0x1B[92m.*//((//**,0x1B[32m .*((((((*0x1B[97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m,,.0x1B[92m.0x1B[94m**********************0x1B[97m@@@@@@@@@@(0x1B[94m***0x1B[92m,####0x1B[32m ../(((((0x1B[97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.((((0x1B[92m(############################################/0x1B[32m /((0x1B[97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.((0x1B[92m(####################/*******(###################0x1B[32m.((((0x1B[97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.((0x1B[92m(################(/0x1B[94m******0x1B[97m/@@@@@#0x1B[94m****************0x1B[32m.. /((0x1B[97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.(0x1B[92m(######################################(0x1B[94m************0x1B[32m..(0x1B[97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.(0x1B[92m(##################################(/0x1B[94m***************0x1B[32m..(0x1B[97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.(0x1B[92m(#############################(/0x1B[94m********************0x1B[32m.,(0x1B[97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.(0x1B[92m(########################(/0x1B[94m************************0x1B[32m..*(0x1B[97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.(0x1B[92m(##################(/**********(################(0x1B[94m**0x1B[32m...(0x1B[97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.(0x1B[92m(######(,.***.,(###################(..***(/0x1B[94m*********0x1B[32m..(0x1B[97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.(0x1B[92m(######*(#####((##################((######/(0x1B[94m********0x1B[32m..(0x1B[97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m..((((0x1B[92m(#########################################(0x1B[32m..(((((.0x1B[97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m..((0x1B[92m(##########0x1B[94m*********0x1B[97m/#@@@@@@@@@/0x1B[94m*************0x1B[32m,,..((((0x1B[97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m....((((0x1B[92m(#####################################(0x1B[32m .((((((.0x1B[97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m......((((0x1B[92m(#################################(0x1B[32m .(((((((.0x1B[97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[41mAny misuse of this software will not be the responsibility of the author or of any other collaborator.0x1B[40;97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[41mUse it at your own networks and/or with the network owner's permission.0x1B[40;97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[41mWinPEAS should be used for authorized penetration testing and/or educational purposes only.0x1B[40;97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m WINDOWS OS\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO.0x1B[32m[*]0x1B[97m BASIC SYSTEM INFO\"", process_name="forfiles.exe", risk_message="excessive forfiles process execution in ar-win-dc.attackrange.local", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="9.0", savedsearch_description="This analytic is developed to detect suspicious excessive usage of forfiles.exe process. This event was seen in post exploitation tool WINPEAS that was used by Ransomware Prestige. Forfiles command lets you run a command on or pass arguments to multiple files. This Windows OS built-in tool being abused to list all files in specific directory or drive.", user="Administrator" 1686749157, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Exploitation", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:26", info_max_time="1686749100.000000000", info_min_time="1686748500.000000000", info_search_time="1686749151.985108000", lastTime="2023-06-14T13:16:26", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO.0x1B[32m[*]0x1B[97m BASIC SYSTEM INFO\"", parent_process_id="5588", parent_process_name="forfiles.exe", process="/C ECHO.\\x1B[32m[*]\\x1B[97m BASIC SYSTEM INFO", process_id="6872", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749157, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Exploitation", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:26", info_max_time="1686749100.000000000", info_min_time="1686748500.000000000", info_search_time="1686749151.985108000", lastTime="2023-06-14T13:16:26", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m WINDOWS OS\"", parent_process_id="2300", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m WINDOWS OS", process_id="2924", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749157, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Exploitation", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:26", info_max_time="1686749100.000000000", info_min_time="1686748500.000000000", info_search_time="1686749151.985108000", lastTime="2023-06-14T13:16:26", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[41mWinPEAS should be used for authorized penetration testing and/or educational purposes only.0x1B[40;97m\"", parent_process_id="2876", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[41mWinPEAS should be used for authorized penetration testing and/or educational purposes only.\\x1B[40;97m", process_id="824", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749157, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Exploitation", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:26", info_max_time="1686749100.000000000", info_min_time="1686748500.000000000", info_search_time="1686749151.985108000", lastTime="2023-06-14T13:16:26", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[41mUse it at your own networks and/or with the network owner's permission.0x1B[40;97m\"", parent_process_id="5652", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[41mUse it at your own networks and/or with the network owner's permission.\\x1B[40;97m", process_id="6480", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749157, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Exploitation", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:26", info_max_time="1686749100.000000000", info_min_time="1686748500.000000000", info_search_time="1686749151.985108000", lastTime="2023-06-14T13:16:26", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[41mAny misuse of this software will not be the responsibility of the author or of any other collaborator.0x1B[40;97m\"", parent_process_id="7032", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[41mAny misuse of this software will not be the responsibility of the author or of any other collaborator.\\x1B[40;97m", process_id="4020", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749157, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Exploitation", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:26", info_max_time="1686749100.000000000", info_min_time="1686748500.000000000", info_search_time="1686749151.985108000", lastTime="2023-06-14T13:16:26", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m......((((0x1B[92m(#################################(0x1B[32m .(((((((.0x1B[97m\"", parent_process_id="3540", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[32m......((((\\x1B[92m(#################################(\\x1B[32m .(((((((.\\x1B[97m", process_id="3572", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749157, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Exploitation", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:26", info_max_time="1686749100.000000000", info_min_time="1686748500.000000000", info_search_time="1686749151.985108000", lastTime="2023-06-14T13:16:26", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m....((((0x1B[92m(#####################################(0x1B[32m .((((((.0x1B[97m\"", parent_process_id="5888", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[32m....((((\\x1B[92m(#####################################(\\x1B[32m .((((((.\\x1B[97m", process_id="4892", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749157, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Exploitation", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:25", info_max_time="1686749100.000000000", info_min_time="1686748500.000000000", info_search_time="1686749151.985108000", lastTime="2023-06-14T13:16:25", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m..((0x1B[92m(##########0x1B[94m*********0x1B[97m/#@@@@@@@@@/0x1B[94m*************0x1B[32m,,..((((0x1B[97m\"", parent_process_id="6980", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[32m..((\\x1B[92m(##########\\x1B[94m*********\\x1B[97m/#@@@@@@@@@/\\x1B[94m*************\\x1B[32m,,..((((\\x1B[97m", process_id="7124", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749157, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Exploitation", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:26", info_max_time="1686749100.000000000", info_min_time="1686748500.000000000", info_search_time="1686749151.985108000", lastTime="2023-06-14T13:16:26", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m..((((0x1B[92m(#########################################(0x1B[32m..(((((.0x1B[97m\"", parent_process_id="7064", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[32m..((((\\x1B[92m(#########################################(\\x1B[32m..(((((.\\x1B[97m", process_id="6400", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749157, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Exploitation", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:26", info_max_time="1686749100.000000000", info_min_time="1686748500.000000000", info_search_time="1686749151.985108000", lastTime="2023-06-14T13:16:26", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.(0x1B[92m(######*(#####((##################((######/(0x1B[94m********0x1B[32m..(0x1B[97m\"", parent_process_id="4268", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[32m.(\\x1B[92m(######*(#####((##################((######/(\\x1B[94m********\\x1B[32m..(\\x1B[97m", process_id="6912", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749157, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Exploitation", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:26", info_max_time="1686749100.000000000", info_min_time="1686748500.000000000", info_search_time="1686749151.985108000", lastTime="2023-06-14T13:16:26", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.(0x1B[92m(######(,.***.,(###################(..***(/0x1B[94m*********0x1B[32m..(0x1B[97m\"", parent_process_id="6696", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[32m.(\\x1B[92m(######(,.***.,(###################(..***(/\\x1B[94m*********\\x1B[32m..(\\x1B[97m", process_id="6012", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749157, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Exploitation", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:26", info_max_time="1686749100.000000000", info_min_time="1686748500.000000000", info_search_time="1686749151.985108000", lastTime="2023-06-14T13:16:26", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.(0x1B[92m(##################(/**********(################(0x1B[94m**0x1B[32m...(0x1B[97m\"", parent_process_id="6372", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[32m.(\\x1B[92m(##################(/**********(################(\\x1B[94m**\\x1B[32m...(\\x1B[97m", process_id="6692", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749157, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Exploitation", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:26", info_max_time="1686749100.000000000", info_min_time="1686748500.000000000", info_search_time="1686749151.985108000", lastTime="2023-06-14T13:16:26", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.(0x1B[92m(########################(/0x1B[94m************************0x1B[32m..*(0x1B[97m\"", parent_process_id="6088", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[32m.(\\x1B[92m(########################(/\\x1B[94m************************\\x1B[32m..*(\\x1B[97m", process_id="5648", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749157, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Exploitation", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:26", info_max_time="1686749100.000000000", info_min_time="1686748500.000000000", info_search_time="1686749151.985108000", lastTime="2023-06-14T13:16:26", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.(0x1B[92m(#############################(/0x1B[94m********************0x1B[32m.,(0x1B[97m\"", parent_process_id="6212", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[32m.(\\x1B[92m(#############################(/\\x1B[94m********************\\x1B[32m.,(\\x1B[97m", process_id="3700", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749157, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Exploitation", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:26", info_max_time="1686749100.000000000", info_min_time="1686748500.000000000", info_search_time="1686749151.985108000", lastTime="2023-06-14T13:16:26", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.(0x1B[92m(##################################(/0x1B[94m***************0x1B[32m..(0x1B[97m\"", parent_process_id="4824", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[32m.(\\x1B[92m(##################################(/\\x1B[94m***************\\x1B[32m..(\\x1B[97m", process_id="4032", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749157, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Exploitation", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:26", info_max_time="1686749100.000000000", info_min_time="1686748500.000000000", info_search_time="1686749151.985108000", lastTime="2023-06-14T13:16:26", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.(0x1B[92m(######################################(0x1B[94m************0x1B[32m..(0x1B[97m\"", parent_process_id="7020", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[32m.(\\x1B[92m(######################################(\\x1B[94m************\\x1B[32m..(\\x1B[97m", process_id="5756", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749157, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Exploitation", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:26", info_max_time="1686749100.000000000", info_min_time="1686748500.000000000", info_search_time="1686749151.985108000", lastTime="2023-06-14T13:16:26", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.((0x1B[92m(################(/0x1B[94m******0x1B[97m/@@@@@#0x1B[94m****************0x1B[32m.. /((0x1B[97m\"", parent_process_id="6928", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[32m.((\\x1B[92m(################(/\\x1B[94m******\\x1B[97m/@@@@@#\\x1B[94m****************\\x1B[32m.. /((\\x1B[97m", process_id="5780", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749157, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Exploitation", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:26", info_max_time="1686749100.000000000", info_min_time="1686748500.000000000", info_search_time="1686749151.985108000", lastTime="2023-06-14T13:16:26", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.((0x1B[92m(####################/*******(###################0x1B[32m.((((0x1B[97m\"", parent_process_id="7132", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[32m.((\\x1B[92m(####################/*******(###################\\x1B[32m.((((\\x1B[97m", process_id="6740", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749157, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Exploitation", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:26", info_max_time="1686749100.000000000", info_min_time="1686748500.000000000", info_search_time="1686749151.985108000", lastTime="2023-06-14T13:16:26", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.((((0x1B[92m(############################################/0x1B[32m /((0x1B[97m\"", parent_process_id="3084", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[32m.((((\\x1B[92m(############################################/\\x1B[32m /((\\x1B[97m", process_id="4688", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749157, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Exploitation", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:25", info_max_time="1686749100.000000000", info_min_time="1686748500.000000000", info_search_time="1686749151.985108000", lastTime="2023-06-14T13:16:25", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m,,.0x1B[92m.0x1B[94m**********************0x1B[97m@@@@@@@@@@(0x1B[94m***0x1B[92m,####0x1B[32m ../(((((0x1B[97m\"", parent_process_id="6532", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[32m,,.\\x1B[92m.\\x1B[94m**********************\\x1B[97m@@@@@@@@@@(\\x1B[94m***\\x1B[92m,####\\x1B[32m ../(((((\\x1B[97m", process_id="5844", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749157, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Exploitation", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:25", info_max_time="1686749100.000000000", info_min_time="1686748500.000000000", info_search_time="1686749151.985108000", lastTime="2023-06-14T13:16:25", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m,*/((((((((((((((((((/, 0x1B[92m.*//((//**,0x1B[32m .*((((((*0x1B[97m\"", parent_process_id="2256", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[32m,*/((((((((((((((((((/, \\x1B[92m.*//((//**,\\x1B[32m .*((((((*\\x1B[97m", process_id="836", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749157, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Exploitation", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:25", info_max_time="1686749100.000000000", info_min_time="1686748500.000000000", info_search_time="1686749151.985108000", lastTime="2023-06-14T13:16:25", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m, ,0x1B[92m0x1B[94m**********************0x1B[97m#@@@@@#@@@@0x1B[94m*********0x1B[92m##0x1B[32m((/ /((((0x1B[97m\"", parent_process_id="5560", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[32m, ,\\x1B[92m\\x1B[94m**********************\\x1B[97m#@@@@@#@@@@\\x1B[94m*********\\x1B[92m##\\x1B[32m((/ /((((\\x1B[97m", process_id="5748", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749157, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Exploitation", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:25", info_max_time="1686749100.000000000", info_min_time="1686748500.000000000", info_search_time="1686749151.985108000", lastTime="2023-06-14T13:16:25", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m((((((.0x1B[92m.0x1B[94m******************0x1B[97m/@@@@@/0x1B[94m***0x1B[92m/######0x1B[32m /((((((0x1B[97m\"", parent_process_id="5000", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[32m((((((.\\x1B[92m.\\x1B[94m******************\\x1B[97m/@@@@@/\\x1B[94m***\\x1B[92m/######\\x1B[32m /((((((\\x1B[97m", process_id="160", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749157, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Exploitation", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:26", info_max_time="1686749100.000000000", info_min_time="1686748500.000000000", info_search_time="1686749151.985108000", lastTime="2023-06-14T13:16:26", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m(((((((((. ,0x1B[92m(############################(0x1B[32m../(((((((((.0x1B[97m\"", parent_process_id="404", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[32m(((((((((. ,\\x1B[92m(############################(\\x1B[32m../(((((((((.\\x1B[97m", process_id="6996", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749157, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Exploitation", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:25", info_max_time="1686749100.000000000", info_min_time="1686748500.000000000", info_search_time="1686749151.985108000", lastTime="2023-06-14T13:16:25", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m(((((((((((/* 0x1B[94m******************0x1B[32m/####### 0x1B[32m.(. ((((((0x1B[97m\"", parent_process_id="6964", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[32m(((((((((((/* \\x1B[94m******************\\x1B[32m/####### \\x1B[32m.(. ((((((\\x1B[97m", process_id="7072", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749157, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Exploitation", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:25", info_max_time="1686749100.000000000", info_min_time="1686748500.000000000", info_search_time="1686749151.985108000", lastTime="2023-06-14T13:16:25", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m((((((((((((((((* 0x1B[94m*****0x1B[32m,,,/########## 0x1B[32m.(* ,((((((0x1B[97m\"", parent_process_id="5860", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[32m((((((((((((((((* \\x1B[94m*****\\x1B[32m,,,/########## \\x1B[32m.(* ,((((((\\x1B[97m", process_id="7104", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749157, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Exploitation", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:25", info_max_time="1686749100.000000000", info_min_time="1686748500.000000000", info_search_time="1686749151.985108000", lastTime="2023-06-14T13:16:25", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m,/*,..*(((((((((((((((((((((((((((((((((,0x1B[97m\"", parent_process_id="5832", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[32m,/*,..*(((((((((((((((((((((((((((((((((,\\x1B[97m", process_id="6876", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749157, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Exploitation", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:26", info_max_time="1686749100.000000000", info_min_time="1686748500.000000000", info_search_time="1686749151.985108000", lastTime="2023-06-14T13:16:26", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m(((((((((/, 0x1B[92m,####################(0x1B[32m/..((((((((((.0x1B[97m\"", parent_process_id="6768", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[32m(((((((((/, \\x1B[92m,####################(\\x1B[32m/..((((((((((.\\x1B[97m", process_id="6652", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749157, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Exploitation", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:25", info_max_time="1686749100.000000000", info_min_time="1686748500.000000000", info_search_time="1686749151.985108000", lastTime="2023-06-14T13:16:25", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m((,.,/((((((((((((((((((((/, */0x1B[97m\"", parent_process_id="4308", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[32m((,.,/((((((((((((((((((((/, */\\x1B[97m", process_id="4984", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749157, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Exploitation", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:26", info_max_time="1686749100.000000000", info_min_time="1686748500.000000000", info_search_time="1686749151.985108000", lastTime="2023-06-14T13:16:26", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m(((((((((/,. 0x1B[92m,*//////*,.0x1B[32m ./(((((((((((.0x1B[97m\"", parent_process_id="5964", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[32m(((((((((/,. \\x1B[92m,*//////*,.\\x1B[32m ./(((((((((((.\\x1B[97m", process_id="6352", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749157, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Exploitation", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:26", info_max_time="1686749100.000000000", info_min_time="1686748500.000000000", info_search_time="1686749151.985108000", lastTime="2023-06-14T13:16:26", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m(((((((((((((((((((((((((((/0x1B[97m\"", parent_process_id="6488", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[32m(((((((((((((((((((((((((((/\\x1B[97m", process_id="4464", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749157, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Exploitation", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:26", info_max_time="1686749100.000000000", info_min_time="1686748500.000000000", info_search_time="1686749151.985108000", lastTime="2023-06-14T13:16:26", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO.0x1B[32m[*]0x1B[97m BASIC SYSTEM INFO\"", parent_process_id="836", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO.0x1B[32m[*]0x1B[97m BASIC SYSTEM INFO\"", process_id="5588", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749157, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Exploitation", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:26", info_max_time="1686749100.000000000", info_min_time="1686748500.000000000", info_search_time="1686749151.985108000", lastTime="2023-06-14T13:16:26", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m WINDOWS OS\"", parent_process_id="1292", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m WINDOWS OS\"", process_id="2300", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749157, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Exploitation", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:26", info_max_time="1686749100.000000000", info_min_time="1686748500.000000000", info_search_time="1686749151.985108000", lastTime="2023-06-14T13:16:26", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[41mWinPEAS should be used for authorized penetration testing and/or educational purposes only.0x1B[40;97m\"", parent_process_id="4664", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[41mWinPEAS should be used for authorized penetration testing and/or educational purposes only.0x1B[40;97m\"", process_id="2876", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749157, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Exploitation", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:26", info_max_time="1686749100.000000000", info_min_time="1686748500.000000000", info_search_time="1686749151.985108000", lastTime="2023-06-14T13:16:26", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[41mUse it at your own networks and/or with the network owner's permission.0x1B[40;97m\"", parent_process_id="6876", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[41mUse it at your own networks and/or with the network owner's permission.0x1B[40;97m\"", process_id="5652", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749157, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Exploitation", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:26", info_max_time="1686749100.000000000", info_min_time="1686748500.000000000", info_search_time="1686749151.985108000", lastTime="2023-06-14T13:16:26", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[41mAny misuse of this software will not be the responsibility of the author or of any other collaborator.0x1B[40;97m\"", parent_process_id="4984", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[41mAny misuse of this software will not be the responsibility of the author or of any other collaborator.0x1B[40;97m\"", process_id="7032", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749157, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Exploitation", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:26", info_max_time="1686749100.000000000", info_min_time="1686748500.000000000", info_search_time="1686749151.985108000", lastTime="2023-06-14T13:16:26", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m......((((0x1B[92m(#################################(0x1B[32m .(((((((.0x1B[97m\"", parent_process_id="6840", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m......((((0x1B[92m(#################################(0x1B[32m .(((((((.0x1B[97m\"", process_id="3540", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749157, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Exploitation", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:26", info_max_time="1686749100.000000000", info_min_time="1686748500.000000000", info_search_time="1686749151.985108000", lastTime="2023-06-14T13:16:26", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m....((((0x1B[92m(#####################################(0x1B[32m .((((((.0x1B[97m\"", parent_process_id="5312", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m....((((0x1B[92m(#####################################(0x1B[32m .((((((.0x1B[97m\"", process_id="5888", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749157, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Exploitation", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:25", info_max_time="1686749100.000000000", info_min_time="1686748500.000000000", info_search_time="1686749151.985108000", lastTime="2023-06-14T13:16:25", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m..((0x1B[92m(##########0x1B[94m*********0x1B[97m/#@@@@@@@@@/0x1B[94m*************0x1B[32m,,..((((0x1B[97m\"", parent_process_id="6732", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m..((0x1B[92m(##########0x1B[94m*********0x1B[97m/#@@@@@@@@@/0x1B[94m*************0x1B[32m,,..((((0x1B[97m\"", process_id="6980", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749157, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Exploitation", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:26", info_max_time="1686749100.000000000", info_min_time="1686748500.000000000", info_search_time="1686749151.985108000", lastTime="2023-06-14T13:16:26", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m..((((0x1B[92m(#########################################(0x1B[32m..(((((.0x1B[97m\"", parent_process_id="3444", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m..((((0x1B[92m(#########################################(0x1B[32m..(((((.0x1B[97m\"", process_id="7064", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749157, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Exploitation", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:26", info_max_time="1686749100.000000000", info_min_time="1686748500.000000000", info_search_time="1686749151.985108000", lastTime="2023-06-14T13:16:26", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.(0x1B[92m(######*(#####((##################((######/(0x1B[94m********0x1B[32m..(0x1B[97m\"", parent_process_id="4880", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.(0x1B[92m(######*(#####((##################((######/(0x1B[94m********0x1B[32m..(0x1B[97m\"", process_id="4268", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749157, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Exploitation", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:26", info_max_time="1686749100.000000000", info_min_time="1686748500.000000000", info_search_time="1686749151.985108000", lastTime="2023-06-14T13:16:26", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.(0x1B[92m(######(,.***.,(###################(..***(/0x1B[94m*********0x1B[32m..(0x1B[97m\"", parent_process_id="5980", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.(0x1B[92m(######(,.***.,(###################(..***(/0x1B[94m*********0x1B[32m..(0x1B[97m\"", process_id="6696", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749157, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Exploitation", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:26", info_max_time="1686749100.000000000", info_min_time="1686748500.000000000", info_search_time="1686749151.985108000", lastTime="2023-06-14T13:16:26", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.(0x1B[92m(##################(/**********(################(0x1B[94m**0x1B[32m...(0x1B[97m\"", parent_process_id="1376", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.(0x1B[92m(##################(/**********(################(0x1B[94m**0x1B[32m...(0x1B[97m\"", process_id="6372", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749157, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Exploitation", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:26", info_max_time="1686749100.000000000", info_min_time="1686748500.000000000", info_search_time="1686749151.985108000", lastTime="2023-06-14T13:16:26", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.(0x1B[92m(########################(/0x1B[94m************************0x1B[32m..*(0x1B[97m\"", parent_process_id="5144", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.(0x1B[92m(########################(/0x1B[94m************************0x1B[32m..*(0x1B[97m\"", process_id="6088", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749157, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Exploitation", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:26", info_max_time="1686749100.000000000", info_min_time="1686748500.000000000", info_search_time="1686749151.985108000", lastTime="2023-06-14T13:16:26", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.(0x1B[92m(#############################(/0x1B[94m********************0x1B[32m.,(0x1B[97m\"", parent_process_id="3088", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.(0x1B[92m(#############################(/0x1B[94m********************0x1B[32m.,(0x1B[97m\"", process_id="6212", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749157, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Exploitation", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:26", info_max_time="1686749100.000000000", info_min_time="1686748500.000000000", info_search_time="1686749151.985108000", lastTime="2023-06-14T13:16:26", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.(0x1B[92m(##################################(/0x1B[94m***************0x1B[32m..(0x1B[97m\"", parent_process_id="3016", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.(0x1B[92m(##################################(/0x1B[94m***************0x1B[32m..(0x1B[97m\"", process_id="4824", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749157, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Exploitation", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:26", info_max_time="1686749100.000000000", info_min_time="1686748500.000000000", info_search_time="1686749151.985108000", lastTime="2023-06-14T13:16:26", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.(0x1B[92m(######################################(0x1B[94m************0x1B[32m..(0x1B[97m\"", parent_process_id="7028", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.(0x1B[92m(######################################(0x1B[94m************0x1B[32m..(0x1B[97m\"", process_id="7020", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749157, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Exploitation", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:26", info_max_time="1686749100.000000000", info_min_time="1686748500.000000000", info_search_time="1686749151.985108000", lastTime="2023-06-14T13:16:26", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.((0x1B[92m(################(/0x1B[94m******0x1B[97m/@@@@@#0x1B[94m****************0x1B[32m.. /((0x1B[97m\"", parent_process_id="4296", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.((0x1B[92m(################(/0x1B[94m******0x1B[97m/@@@@@#0x1B[94m****************0x1B[32m.. /((0x1B[97m\"", process_id="6928", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749157, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Exploitation", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:26", info_max_time="1686749100.000000000", info_min_time="1686748500.000000000", info_search_time="1686749151.985108000", lastTime="2023-06-14T13:16:26", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.((0x1B[92m(####################/*******(###################0x1B[32m.((((0x1B[97m\"", parent_process_id="4540", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.((0x1B[92m(####################/*******(###################0x1B[32m.((((0x1B[97m\"", process_id="7132", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749157, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Exploitation", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:26", info_max_time="1686749100.000000000", info_min_time="1686748500.000000000", info_search_time="1686749151.985108000", lastTime="2023-06-14T13:16:26", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.((((0x1B[92m(############################################/0x1B[32m /((0x1B[97m\"", parent_process_id="4016", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.((((0x1B[92m(############################################/0x1B[32m /((0x1B[97m\"", process_id="3084", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749157, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Exploitation", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:25", info_max_time="1686749100.000000000", info_min_time="1686748500.000000000", info_search_time="1686749151.985108000", lastTime="2023-06-14T13:16:25", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m,,.0x1B[92m.0x1B[94m**********************0x1B[97m@@@@@@@@@@(0x1B[94m***0x1B[92m,####0x1B[32m ../(((((0x1B[97m\"", parent_process_id="2024", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m,,.0x1B[92m.0x1B[94m**********************0x1B[97m@@@@@@@@@@(0x1B[94m***0x1B[92m,####0x1B[32m ../(((((0x1B[97m\"", process_id="6532", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749157, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Exploitation", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:25", info_max_time="1686749100.000000000", info_min_time="1686748500.000000000", info_search_time="1686749151.985108000", lastTime="2023-06-14T13:16:25", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m,*/((((((((((((((((((/, 0x1B[92m.*//((//**,0x1B[32m .*((((((*0x1B[97m\"", parent_process_id="6460", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m,*/((((((((((((((((((/, 0x1B[92m.*//((//**,0x1B[32m .*((((((*0x1B[97m\"", process_id="2256", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749157, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Exploitation", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:25", info_max_time="1686749100.000000000", info_min_time="1686748500.000000000", info_search_time="1686749151.985108000", lastTime="2023-06-14T13:16:25", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m, ,0x1B[92m0x1B[94m**********************0x1B[97m#@@@@@#@@@@0x1B[94m*********0x1B[92m##0x1B[32m((/ /((((0x1B[97m\"", parent_process_id="5736", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m, ,0x1B[92m0x1B[94m**********************0x1B[97m#@@@@@#@@@@0x1B[94m*********0x1B[92m##0x1B[32m((/ /((((0x1B[97m\"", process_id="5560", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749157, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Exploitation", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:25", info_max_time="1686749100.000000000", info_min_time="1686748500.000000000", info_search_time="1686749151.985108000", lastTime="2023-06-14T13:16:25", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m((((((.0x1B[92m.0x1B[94m******************0x1B[97m/@@@@@/0x1B[94m***0x1B[92m/######0x1B[32m /((((((0x1B[97m\"", parent_process_id="1260", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m((((((.0x1B[92m.0x1B[94m******************0x1B[97m/@@@@@/0x1B[94m***0x1B[92m/######0x1B[32m /((((((0x1B[97m\"", process_id="5000", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749157, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Exploitation", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:26", info_max_time="1686749100.000000000", info_min_time="1686748500.000000000", info_search_time="1686749151.985108000", lastTime="2023-06-14T13:16:26", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m(((((((((. ,0x1B[92m(############################(0x1B[32m../(((((((((.0x1B[97m\"", parent_process_id="6812", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m(((((((((. ,0x1B[92m(############################(0x1B[32m../(((((((((.0x1B[97m\"", process_id="404", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749157, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Exploitation", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:25", info_max_time="1686749100.000000000", info_min_time="1686748500.000000000", info_search_time="1686749151.985108000", lastTime="2023-06-14T13:16:25", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m(((((((((((/* 0x1B[94m******************0x1B[32m/####### 0x1B[32m.(. ((((((0x1B[97m\"", parent_process_id="7092", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m(((((((((((/* 0x1B[94m******************0x1B[32m/####### 0x1B[32m.(. ((((((0x1B[97m\"", process_id="6964", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749157, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Exploitation", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:25", info_max_time="1686749100.000000000", info_min_time="1686748500.000000000", info_search_time="1686749151.985108000", lastTime="2023-06-14T13:16:25", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m((((((((((((((((* 0x1B[94m*****0x1B[32m,,,/########## 0x1B[32m.(* ,((((((0x1B[97m\"", parent_process_id="2300", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m((((((((((((((((* 0x1B[94m*****0x1B[32m,,,/########## 0x1B[32m.(* ,((((((0x1B[97m\"", process_id="5860", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749157, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Exploitation", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:25", info_max_time="1686749100.000000000", info_min_time="1686748500.000000000", info_search_time="1686749151.985108000", lastTime="2023-06-14T13:16:25", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m,/*,..*(((((((((((((((((((((((((((((((((,0x1B[97m\"", parent_process_id="7136", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m,/*,..*(((((((((((((((((((((((((((((((((,0x1B[97m\"", process_id="5832", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749157, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Exploitation", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:26", info_max_time="1686749100.000000000", info_min_time="1686748500.000000000", info_search_time="1686749151.985108000", lastTime="2023-06-14T13:16:26", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m(((((((((/, 0x1B[92m,####################(0x1B[32m/..((((((((((.0x1B[97m\"", parent_process_id="5836", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m(((((((((/, 0x1B[92m,####################(0x1B[32m/..((((((((((.0x1B[97m\"", process_id="6768", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749157, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Exploitation", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:25", info_max_time="1686749100.000000000", info_min_time="1686748500.000000000", info_search_time="1686749151.985108000", lastTime="2023-06-14T13:16:25", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m((,.,/((((((((((((((((((((/, */0x1B[97m\"", parent_process_id="1596", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m((,.,/((((((((((((((((((((/, */0x1B[97m\"", process_id="4308", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749157, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Exploitation", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:26", info_max_time="1686749100.000000000", info_min_time="1686748500.000000000", info_search_time="1686749151.985108000", lastTime="2023-06-14T13:16:26", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m(((((((((/,. 0x1B[92m,*//////*,.0x1B[32m ./(((((((((((.0x1B[97m\"", parent_process_id="2252", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m(((((((((/,. 0x1B[92m,*//////*,.0x1B[32m ./(((((((((((.0x1B[97m\"", process_id="5964", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686749157, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Exploitation", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:26", info_max_time="1686749100.000000000", info_min_time="1686748500.000000000", info_search_time="1686749151.985108000", lastTime="2023-06-14T13:16:26", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m(((((((((((((((((((((((((((/0x1B[97m\"", parent_process_id="2268", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m(((((((((((((((((((((((((((/0x1B[97m\"", process_id="6488", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748560, search_name="ESCU - Windows Indirect Command Execution Via Series Of Forfiles - Rule", orig_time="1686748560", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":30,\"impact\":30,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.AE\"]}", annotations._all="Prestige Ransomware", annotations._all="T1202", annotations._all="DE.AE", annotations._all="Windows Post-Exploitation", annotations._all="Exploitation", annotations._all="CIS 10", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.AE", count="31", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:25", info_max_time="1686748800.000000000", info_min_time="1686748200.000000000", info_search_time="1686748917.890697000", lastTime="2023-06-14T13:16:26", parent_process="C:\\Windows\\System32\\cmd.exe", parent_process_name="cmd.exe", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m(((((((((((((((((((((((((((/0x1B[97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m(((((((((/,. 0x1B[92m,*//////*,.0x1B[32m ./(((((((((((.0x1B[97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m((,.,/((((((((((((((((((((/, */0x1B[97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m(((((((((/, 0x1B[92m,####################(0x1B[32m/..((((((((((.0x1B[97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m,/*,..*(((((((((((((((((((((((((((((((((,0x1B[97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m((((((((((((((((* 0x1B[94m*****0x1B[32m,,,/########## 0x1B[32m.(* ,((((((0x1B[97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m(((((((((((/* 0x1B[94m******************0x1B[32m/####### 0x1B[32m.(. ((((((0x1B[97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m(((((((((. ,0x1B[92m(############################(0x1B[32m../(((((((((.0x1B[97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m((((((.0x1B[92m.0x1B[94m******************0x1B[97m/@@@@@/0x1B[94m***0x1B[92m/######0x1B[32m /((((((0x1B[97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m, ,0x1B[92m0x1B[94m**********************0x1B[97m#@@@@@#@@@@0x1B[94m*********0x1B[92m##0x1B[32m((/ /((((0x1B[97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m,*/((((((((((((((((((/, 0x1B[92m.*//((//**,0x1B[32m .*((((((*0x1B[97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m,,.0x1B[92m.0x1B[94m**********************0x1B[97m@@@@@@@@@@(0x1B[94m***0x1B[92m,####0x1B[32m ../(((((0x1B[97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.((((0x1B[92m(############################################/0x1B[32m /((0x1B[97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.((0x1B[92m(####################/*******(###################0x1B[32m.((((0x1B[97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.((0x1B[92m(################(/0x1B[94m******0x1B[97m/@@@@@#0x1B[94m****************0x1B[32m.. /((0x1B[97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.(0x1B[92m(######################################(0x1B[94m************0x1B[32m..(0x1B[97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.(0x1B[92m(##################################(/0x1B[94m***************0x1B[32m..(0x1B[97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.(0x1B[92m(#############################(/0x1B[94m********************0x1B[32m.,(0x1B[97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.(0x1B[92m(########################(/0x1B[94m************************0x1B[32m..*(0x1B[97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.(0x1B[92m(##################(/**********(################(0x1B[94m**0x1B[32m...(0x1B[97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.(0x1B[92m(######(,.***.,(###################(..***(/0x1B[94m*********0x1B[32m..(0x1B[97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.(0x1B[92m(######*(#####((##################((######/(0x1B[94m********0x1B[32m..(0x1B[97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m..((((0x1B[92m(#########################################(0x1B[32m..(((((.0x1B[97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m..((0x1B[92m(##########0x1B[94m*********0x1B[97m/#@@@@@@@@@/0x1B[94m*************0x1B[32m,,..((((0x1B[97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m....((((0x1B[92m(#####################################(0x1B[32m .((((((.0x1B[97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m......((((0x1B[92m(#################################(0x1B[32m .(((((((.0x1B[97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[41mAny misuse of this software will not be the responsibility of the author or of any other collaborator.0x1B[40;97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[41mUse it at your own networks and/or with the network owner's permission.0x1B[40;97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[41mWinPEAS should be used for authorized penetration testing and/or educational purposes only.0x1B[40;97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m WINDOWS OS\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO.0x1B[32m[*]0x1B[97m BASIC SYSTEM INFO\"", process_name="forfiles.exe", risk_message="excessive forfiles process execution in ar-win-dc.attackrange.local", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="9.0", savedsearch_description="This analytic is developed to detect suspicious excessive usage of forfiles.exe process. This event was seen in post exploitation tool WINPEAS that was used by Ransomware Prestige. Forfiles command lets you run a command on or pass arguments to multiple files. This Windows OS built-in tool being abused to list all files in specific directory or drive.", user="Administrator" 1686748856, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Exploitation", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:26", info_max_time="1686748800.000000000", info_min_time="1686748200.000000000", info_search_time="1686748851.712291000", lastTime="2023-06-14T13:16:26", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO.0x1B[32m[*]0x1B[97m BASIC SYSTEM INFO\"", parent_process_id="5588", parent_process_name="forfiles.exe", process="/C ECHO.\\x1B[32m[*]\\x1B[97m BASIC SYSTEM INFO", process_id="6872", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748856, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Exploitation", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:26", info_max_time="1686748800.000000000", info_min_time="1686748200.000000000", info_search_time="1686748851.712291000", lastTime="2023-06-14T13:16:26", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m WINDOWS OS\"", parent_process_id="2300", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m WINDOWS OS", process_id="2924", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748856, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Exploitation", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:26", info_max_time="1686748800.000000000", info_min_time="1686748200.000000000", info_search_time="1686748851.712291000", lastTime="2023-06-14T13:16:26", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[41mWinPEAS should be used for authorized penetration testing and/or educational purposes only.0x1B[40;97m\"", parent_process_id="2876", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[41mWinPEAS should be used for authorized penetration testing and/or educational purposes only.\\x1B[40;97m", process_id="824", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748856, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Exploitation", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:26", info_max_time="1686748800.000000000", info_min_time="1686748200.000000000", info_search_time="1686748851.712291000", lastTime="2023-06-14T13:16:26", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[41mUse it at your own networks and/or with the network owner's permission.0x1B[40;97m\"", parent_process_id="5652", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[41mUse it at your own networks and/or with the network owner's permission.\\x1B[40;97m", process_id="6480", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748856, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Exploitation", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:26", info_max_time="1686748800.000000000", info_min_time="1686748200.000000000", info_search_time="1686748851.712291000", lastTime="2023-06-14T13:16:26", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[41mAny misuse of this software will not be the responsibility of the author or of any other collaborator.0x1B[40;97m\"", parent_process_id="7032", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[41mAny misuse of this software will not be the responsibility of the author or of any other collaborator.\\x1B[40;97m", process_id="4020", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748856, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Exploitation", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:26", info_max_time="1686748800.000000000", info_min_time="1686748200.000000000", info_search_time="1686748851.712291000", lastTime="2023-06-14T13:16:26", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m......((((0x1B[92m(#################################(0x1B[32m .(((((((.0x1B[97m\"", parent_process_id="3540", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[32m......((((\\x1B[92m(#################################(\\x1B[32m .(((((((.\\x1B[97m", process_id="3572", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748856, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Exploitation", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:26", info_max_time="1686748800.000000000", info_min_time="1686748200.000000000", info_search_time="1686748851.712291000", lastTime="2023-06-14T13:16:26", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m....((((0x1B[92m(#####################################(0x1B[32m .((((((.0x1B[97m\"", parent_process_id="5888", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[32m....((((\\x1B[92m(#####################################(\\x1B[32m .((((((.\\x1B[97m", process_id="4892", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748856, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Exploitation", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:25", info_max_time="1686748800.000000000", info_min_time="1686748200.000000000", info_search_time="1686748851.712291000", lastTime="2023-06-14T13:16:25", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m..((0x1B[92m(##########0x1B[94m*********0x1B[97m/#@@@@@@@@@/0x1B[94m*************0x1B[32m,,..((((0x1B[97m\"", parent_process_id="6980", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[32m..((\\x1B[92m(##########\\x1B[94m*********\\x1B[97m/#@@@@@@@@@/\\x1B[94m*************\\x1B[32m,,..((((\\x1B[97m", process_id="7124", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748856, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Exploitation", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:26", info_max_time="1686748800.000000000", info_min_time="1686748200.000000000", info_search_time="1686748851.712291000", lastTime="2023-06-14T13:16:26", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m..((((0x1B[92m(#########################################(0x1B[32m..(((((.0x1B[97m\"", parent_process_id="7064", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[32m..((((\\x1B[92m(#########################################(\\x1B[32m..(((((.\\x1B[97m", process_id="6400", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748856, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Exploitation", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:26", info_max_time="1686748800.000000000", info_min_time="1686748200.000000000", info_search_time="1686748851.712291000", lastTime="2023-06-14T13:16:26", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.(0x1B[92m(######*(#####((##################((######/(0x1B[94m********0x1B[32m..(0x1B[97m\"", parent_process_id="4268", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[32m.(\\x1B[92m(######*(#####((##################((######/(\\x1B[94m********\\x1B[32m..(\\x1B[97m", process_id="6912", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748856, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Exploitation", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:26", info_max_time="1686748800.000000000", info_min_time="1686748200.000000000", info_search_time="1686748851.712291000", lastTime="2023-06-14T13:16:26", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.(0x1B[92m(######(,.***.,(###################(..***(/0x1B[94m*********0x1B[32m..(0x1B[97m\"", parent_process_id="6696", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[32m.(\\x1B[92m(######(,.***.,(###################(..***(/\\x1B[94m*********\\x1B[32m..(\\x1B[97m", process_id="6012", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748856, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Exploitation", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:26", info_max_time="1686748800.000000000", info_min_time="1686748200.000000000", info_search_time="1686748851.712291000", lastTime="2023-06-14T13:16:26", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.(0x1B[92m(##################(/**********(################(0x1B[94m**0x1B[32m...(0x1B[97m\"", parent_process_id="6372", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[32m.(\\x1B[92m(##################(/**********(################(\\x1B[94m**\\x1B[32m...(\\x1B[97m", process_id="6692", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748856, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Exploitation", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:26", info_max_time="1686748800.000000000", info_min_time="1686748200.000000000", info_search_time="1686748851.712291000", lastTime="2023-06-14T13:16:26", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.(0x1B[92m(########################(/0x1B[94m************************0x1B[32m..*(0x1B[97m\"", parent_process_id="6088", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[32m.(\\x1B[92m(########################(/\\x1B[94m************************\\x1B[32m..*(\\x1B[97m", process_id="5648", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748856, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Exploitation", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:26", info_max_time="1686748800.000000000", info_min_time="1686748200.000000000", info_search_time="1686748851.712291000", lastTime="2023-06-14T13:16:26", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.(0x1B[92m(#############################(/0x1B[94m********************0x1B[32m.,(0x1B[97m\"", parent_process_id="6212", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[32m.(\\x1B[92m(#############################(/\\x1B[94m********************\\x1B[32m.,(\\x1B[97m", process_id="3700", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748856, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Exploitation", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:26", info_max_time="1686748800.000000000", info_min_time="1686748200.000000000", info_search_time="1686748851.712291000", lastTime="2023-06-14T13:16:26", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.(0x1B[92m(##################################(/0x1B[94m***************0x1B[32m..(0x1B[97m\"", parent_process_id="4824", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[32m.(\\x1B[92m(##################################(/\\x1B[94m***************\\x1B[32m..(\\x1B[97m", process_id="4032", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748856, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Exploitation", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:26", info_max_time="1686748800.000000000", info_min_time="1686748200.000000000", info_search_time="1686748851.712291000", lastTime="2023-06-14T13:16:26", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.(0x1B[92m(######################################(0x1B[94m************0x1B[32m..(0x1B[97m\"", parent_process_id="7020", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[32m.(\\x1B[92m(######################################(\\x1B[94m************\\x1B[32m..(\\x1B[97m", process_id="5756", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748856, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Exploitation", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:26", info_max_time="1686748800.000000000", info_min_time="1686748200.000000000", info_search_time="1686748851.712291000", lastTime="2023-06-14T13:16:26", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.((0x1B[92m(################(/0x1B[94m******0x1B[97m/@@@@@#0x1B[94m****************0x1B[32m.. /((0x1B[97m\"", parent_process_id="6928", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[32m.((\\x1B[92m(################(/\\x1B[94m******\\x1B[97m/@@@@@#\\x1B[94m****************\\x1B[32m.. /((\\x1B[97m", process_id="5780", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748856, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Exploitation", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:26", info_max_time="1686748800.000000000", info_min_time="1686748200.000000000", info_search_time="1686748851.712291000", lastTime="2023-06-14T13:16:26", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.((0x1B[92m(####################/*******(###################0x1B[32m.((((0x1B[97m\"", parent_process_id="7132", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[32m.((\\x1B[92m(####################/*******(###################\\x1B[32m.((((\\x1B[97m", process_id="6740", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748856, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Exploitation", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:26", info_max_time="1686748800.000000000", info_min_time="1686748200.000000000", info_search_time="1686748851.712291000", lastTime="2023-06-14T13:16:26", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.((((0x1B[92m(############################################/0x1B[32m /((0x1B[97m\"", parent_process_id="3084", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[32m.((((\\x1B[92m(############################################/\\x1B[32m /((\\x1B[97m", process_id="4688", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748856, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Exploitation", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:25", info_max_time="1686748800.000000000", info_min_time="1686748200.000000000", info_search_time="1686748851.712291000", lastTime="2023-06-14T13:16:25", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m,,.0x1B[92m.0x1B[94m**********************0x1B[97m@@@@@@@@@@(0x1B[94m***0x1B[92m,####0x1B[32m ../(((((0x1B[97m\"", parent_process_id="6532", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[32m,,.\\x1B[92m.\\x1B[94m**********************\\x1B[97m@@@@@@@@@@(\\x1B[94m***\\x1B[92m,####\\x1B[32m ../(((((\\x1B[97m", process_id="5844", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748856, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Exploitation", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:25", info_max_time="1686748800.000000000", info_min_time="1686748200.000000000", info_search_time="1686748851.712291000", lastTime="2023-06-14T13:16:25", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m,*/((((((((((((((((((/, 0x1B[92m.*//((//**,0x1B[32m .*((((((*0x1B[97m\"", parent_process_id="2256", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[32m,*/((((((((((((((((((/, \\x1B[92m.*//((//**,\\x1B[32m .*((((((*\\x1B[97m", process_id="836", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748856, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Exploitation", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:25", info_max_time="1686748800.000000000", info_min_time="1686748200.000000000", info_search_time="1686748851.712291000", lastTime="2023-06-14T13:16:25", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m, ,0x1B[92m0x1B[94m**********************0x1B[97m#@@@@@#@@@@0x1B[94m*********0x1B[92m##0x1B[32m((/ /((((0x1B[97m\"", parent_process_id="5560", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[32m, ,\\x1B[92m\\x1B[94m**********************\\x1B[97m#@@@@@#@@@@\\x1B[94m*********\\x1B[92m##\\x1B[32m((/ /((((\\x1B[97m", process_id="5748", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748856, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Exploitation", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:25", info_max_time="1686748800.000000000", info_min_time="1686748200.000000000", info_search_time="1686748851.712291000", lastTime="2023-06-14T13:16:25", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m((((((.0x1B[92m.0x1B[94m******************0x1B[97m/@@@@@/0x1B[94m***0x1B[92m/######0x1B[32m /((((((0x1B[97m\"", parent_process_id="5000", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[32m((((((.\\x1B[92m.\\x1B[94m******************\\x1B[97m/@@@@@/\\x1B[94m***\\x1B[92m/######\\x1B[32m /((((((\\x1B[97m", process_id="160", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748856, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Exploitation", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:26", info_max_time="1686748800.000000000", info_min_time="1686748200.000000000", info_search_time="1686748851.712291000", lastTime="2023-06-14T13:16:26", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m(((((((((. ,0x1B[92m(############################(0x1B[32m../(((((((((.0x1B[97m\"", parent_process_id="404", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[32m(((((((((. ,\\x1B[92m(############################(\\x1B[32m../(((((((((.\\x1B[97m", process_id="6996", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748856, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Exploitation", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:25", info_max_time="1686748800.000000000", info_min_time="1686748200.000000000", info_search_time="1686748851.712291000", lastTime="2023-06-14T13:16:25", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m(((((((((((/* 0x1B[94m******************0x1B[32m/####### 0x1B[32m.(. ((((((0x1B[97m\"", parent_process_id="6964", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[32m(((((((((((/* \\x1B[94m******************\\x1B[32m/####### \\x1B[32m.(. ((((((\\x1B[97m", process_id="7072", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748856, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Exploitation", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:25", info_max_time="1686748800.000000000", info_min_time="1686748200.000000000", info_search_time="1686748851.712291000", lastTime="2023-06-14T13:16:25", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m((((((((((((((((* 0x1B[94m*****0x1B[32m,,,/########## 0x1B[32m.(* ,((((((0x1B[97m\"", parent_process_id="5860", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[32m((((((((((((((((* \\x1B[94m*****\\x1B[32m,,,/########## \\x1B[32m.(* ,((((((\\x1B[97m", process_id="7104", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748856, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Exploitation", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:25", info_max_time="1686748800.000000000", info_min_time="1686748200.000000000", info_search_time="1686748851.712291000", lastTime="2023-06-14T13:16:25", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m,/*,..*(((((((((((((((((((((((((((((((((,0x1B[97m\"", parent_process_id="5832", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[32m,/*,..*(((((((((((((((((((((((((((((((((,\\x1B[97m", process_id="6876", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748856, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Exploitation", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:26", info_max_time="1686748800.000000000", info_min_time="1686748200.000000000", info_search_time="1686748851.712291000", lastTime="2023-06-14T13:16:26", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m(((((((((/, 0x1B[92m,####################(0x1B[32m/..((((((((((.0x1B[97m\"", parent_process_id="6768", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[32m(((((((((/, \\x1B[92m,####################(\\x1B[32m/..((((((((((.\\x1B[97m", process_id="6652", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748856, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Exploitation", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:25", info_max_time="1686748800.000000000", info_min_time="1686748200.000000000", info_search_time="1686748851.712291000", lastTime="2023-06-14T13:16:25", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m((,.,/((((((((((((((((((((/, */0x1B[97m\"", parent_process_id="4308", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[32m((,.,/((((((((((((((((((((/, */\\x1B[97m", process_id="4984", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748856, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Exploitation", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:26", info_max_time="1686748800.000000000", info_min_time="1686748200.000000000", info_search_time="1686748851.712291000", lastTime="2023-06-14T13:16:26", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m(((((((((/,. 0x1B[92m,*//////*,.0x1B[32m ./(((((((((((.0x1B[97m\"", parent_process_id="5964", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[32m(((((((((/,. \\x1B[92m,*//////*,.\\x1B[32m ./(((((((((((.\\x1B[97m", process_id="6352", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748856, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Exploitation", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:26", info_max_time="1686748800.000000000", info_min_time="1686748200.000000000", info_search_time="1686748851.712291000", lastTime="2023-06-14T13:16:26", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m(((((((((((((((((((((((((((/0x1B[97m\"", parent_process_id="6488", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[32m(((((((((((((((((((((((((((/\\x1B[97m", process_id="4464", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748856, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Exploitation", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:26", info_max_time="1686748800.000000000", info_min_time="1686748200.000000000", info_search_time="1686748851.712291000", lastTime="2023-06-14T13:16:26", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO.0x1B[32m[*]0x1B[97m BASIC SYSTEM INFO\"", parent_process_id="836", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO.0x1B[32m[*]0x1B[97m BASIC SYSTEM INFO\"", process_id="5588", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748856, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Exploitation", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:26", info_max_time="1686748800.000000000", info_min_time="1686748200.000000000", info_search_time="1686748851.712291000", lastTime="2023-06-14T13:16:26", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m WINDOWS OS\"", parent_process_id="1292", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m WINDOWS OS\"", process_id="2300", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748856, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Exploitation", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:26", info_max_time="1686748800.000000000", info_min_time="1686748200.000000000", info_search_time="1686748851.712291000", lastTime="2023-06-14T13:16:26", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[41mWinPEAS should be used for authorized penetration testing and/or educational purposes only.0x1B[40;97m\"", parent_process_id="4664", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[41mWinPEAS should be used for authorized penetration testing and/or educational purposes only.0x1B[40;97m\"", process_id="2876", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748856, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Exploitation", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:26", info_max_time="1686748800.000000000", info_min_time="1686748200.000000000", info_search_time="1686748851.712291000", lastTime="2023-06-14T13:16:26", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[41mUse it at your own networks and/or with the network owner's permission.0x1B[40;97m\"", parent_process_id="6876", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[41mUse it at your own networks and/or with the network owner's permission.0x1B[40;97m\"", process_id="5652", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748856, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Exploitation", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:26", info_max_time="1686748800.000000000", info_min_time="1686748200.000000000", info_search_time="1686748851.712291000", lastTime="2023-06-14T13:16:26", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[41mAny misuse of this software will not be the responsibility of the author or of any other collaborator.0x1B[40;97m\"", parent_process_id="4984", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[41mAny misuse of this software will not be the responsibility of the author or of any other collaborator.0x1B[40;97m\"", process_id="7032", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748856, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Exploitation", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:26", info_max_time="1686748800.000000000", info_min_time="1686748200.000000000", info_search_time="1686748851.712291000", lastTime="2023-06-14T13:16:26", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m......((((0x1B[92m(#################################(0x1B[32m .(((((((.0x1B[97m\"", parent_process_id="6840", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m......((((0x1B[92m(#################################(0x1B[32m .(((((((.0x1B[97m\"", process_id="3540", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748856, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Exploitation", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:26", info_max_time="1686748800.000000000", info_min_time="1686748200.000000000", info_search_time="1686748851.712291000", lastTime="2023-06-14T13:16:26", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m....((((0x1B[92m(#####################################(0x1B[32m .((((((.0x1B[97m\"", parent_process_id="5312", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m....((((0x1B[92m(#####################################(0x1B[32m .((((((.0x1B[97m\"", process_id="5888", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748856, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Exploitation", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:25", info_max_time="1686748800.000000000", info_min_time="1686748200.000000000", info_search_time="1686748851.712291000", lastTime="2023-06-14T13:16:25", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m..((0x1B[92m(##########0x1B[94m*********0x1B[97m/#@@@@@@@@@/0x1B[94m*************0x1B[32m,,..((((0x1B[97m\"", parent_process_id="6732", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m..((0x1B[92m(##########0x1B[94m*********0x1B[97m/#@@@@@@@@@/0x1B[94m*************0x1B[32m,,..((((0x1B[97m\"", process_id="6980", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748856, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Exploitation", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:26", info_max_time="1686748800.000000000", info_min_time="1686748200.000000000", info_search_time="1686748851.712291000", lastTime="2023-06-14T13:16:26", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m..((((0x1B[92m(#########################################(0x1B[32m..(((((.0x1B[97m\"", parent_process_id="3444", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m..((((0x1B[92m(#########################################(0x1B[32m..(((((.0x1B[97m\"", process_id="7064", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748856, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Exploitation", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:26", info_max_time="1686748800.000000000", info_min_time="1686748200.000000000", info_search_time="1686748851.712291000", lastTime="2023-06-14T13:16:26", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.(0x1B[92m(######*(#####((##################((######/(0x1B[94m********0x1B[32m..(0x1B[97m\"", parent_process_id="4880", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.(0x1B[92m(######*(#####((##################((######/(0x1B[94m********0x1B[32m..(0x1B[97m\"", process_id="4268", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748856, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Exploitation", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:26", info_max_time="1686748800.000000000", info_min_time="1686748200.000000000", info_search_time="1686748851.712291000", lastTime="2023-06-14T13:16:26", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.(0x1B[92m(######(,.***.,(###################(..***(/0x1B[94m*********0x1B[32m..(0x1B[97m\"", parent_process_id="5980", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.(0x1B[92m(######(,.***.,(###################(..***(/0x1B[94m*********0x1B[32m..(0x1B[97m\"", process_id="6696", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748856, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Exploitation", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:26", info_max_time="1686748800.000000000", info_min_time="1686748200.000000000", info_search_time="1686748851.712291000", lastTime="2023-06-14T13:16:26", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.(0x1B[92m(##################(/**********(################(0x1B[94m**0x1B[32m...(0x1B[97m\"", parent_process_id="1376", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.(0x1B[92m(##################(/**********(################(0x1B[94m**0x1B[32m...(0x1B[97m\"", process_id="6372", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748856, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Exploitation", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:26", info_max_time="1686748800.000000000", info_min_time="1686748200.000000000", info_search_time="1686748851.712291000", lastTime="2023-06-14T13:16:26", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.(0x1B[92m(########################(/0x1B[94m************************0x1B[32m..*(0x1B[97m\"", parent_process_id="5144", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.(0x1B[92m(########################(/0x1B[94m************************0x1B[32m..*(0x1B[97m\"", process_id="6088", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748856, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Exploitation", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:26", info_max_time="1686748800.000000000", info_min_time="1686748200.000000000", info_search_time="1686748851.712291000", lastTime="2023-06-14T13:16:26", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.(0x1B[92m(#############################(/0x1B[94m********************0x1B[32m.,(0x1B[97m\"", parent_process_id="3088", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.(0x1B[92m(#############################(/0x1B[94m********************0x1B[32m.,(0x1B[97m\"", process_id="6212", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748856, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Exploitation", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:26", info_max_time="1686748800.000000000", info_min_time="1686748200.000000000", info_search_time="1686748851.712291000", lastTime="2023-06-14T13:16:26", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.(0x1B[92m(##################################(/0x1B[94m***************0x1B[32m..(0x1B[97m\"", parent_process_id="3016", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.(0x1B[92m(##################################(/0x1B[94m***************0x1B[32m..(0x1B[97m\"", process_id="4824", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748856, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Exploitation", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:26", info_max_time="1686748800.000000000", info_min_time="1686748200.000000000", info_search_time="1686748851.712291000", lastTime="2023-06-14T13:16:26", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.(0x1B[92m(######################################(0x1B[94m************0x1B[32m..(0x1B[97m\"", parent_process_id="7028", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.(0x1B[92m(######################################(0x1B[94m************0x1B[32m..(0x1B[97m\"", process_id="7020", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748856, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Exploitation", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:26", info_max_time="1686748800.000000000", info_min_time="1686748200.000000000", info_search_time="1686748851.712291000", lastTime="2023-06-14T13:16:26", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.((0x1B[92m(################(/0x1B[94m******0x1B[97m/@@@@@#0x1B[94m****************0x1B[32m.. /((0x1B[97m\"", parent_process_id="4296", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.((0x1B[92m(################(/0x1B[94m******0x1B[97m/@@@@@#0x1B[94m****************0x1B[32m.. /((0x1B[97m\"", process_id="6928", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748856, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Exploitation", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:26", info_max_time="1686748800.000000000", info_min_time="1686748200.000000000", info_search_time="1686748851.712291000", lastTime="2023-06-14T13:16:26", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.((0x1B[92m(####################/*******(###################0x1B[32m.((((0x1B[97m\"", parent_process_id="4540", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.((0x1B[92m(####################/*******(###################0x1B[32m.((((0x1B[97m\"", process_id="7132", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748856, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Exploitation", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:26", info_max_time="1686748800.000000000", info_min_time="1686748200.000000000", info_search_time="1686748851.712291000", lastTime="2023-06-14T13:16:26", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.((((0x1B[92m(############################################/0x1B[32m /((0x1B[97m\"", parent_process_id="4016", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.((((0x1B[92m(############################################/0x1B[32m /((0x1B[97m\"", process_id="3084", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748856, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Exploitation", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:25", info_max_time="1686748800.000000000", info_min_time="1686748200.000000000", info_search_time="1686748851.712291000", lastTime="2023-06-14T13:16:25", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m,,.0x1B[92m.0x1B[94m**********************0x1B[97m@@@@@@@@@@(0x1B[94m***0x1B[92m,####0x1B[32m ../(((((0x1B[97m\"", parent_process_id="2024", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m,,.0x1B[92m.0x1B[94m**********************0x1B[97m@@@@@@@@@@(0x1B[94m***0x1B[92m,####0x1B[32m ../(((((0x1B[97m\"", process_id="6532", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748856, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Exploitation", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:25", info_max_time="1686748800.000000000", info_min_time="1686748200.000000000", info_search_time="1686748851.712291000", lastTime="2023-06-14T13:16:25", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m,*/((((((((((((((((((/, 0x1B[92m.*//((//**,0x1B[32m .*((((((*0x1B[97m\"", parent_process_id="6460", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m,*/((((((((((((((((((/, 0x1B[92m.*//((//**,0x1B[32m .*((((((*0x1B[97m\"", process_id="2256", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748856, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Exploitation", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:25", info_max_time="1686748800.000000000", info_min_time="1686748200.000000000", info_search_time="1686748851.712291000", lastTime="2023-06-14T13:16:25", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m, ,0x1B[92m0x1B[94m**********************0x1B[97m#@@@@@#@@@@0x1B[94m*********0x1B[92m##0x1B[32m((/ /((((0x1B[97m\"", parent_process_id="5736", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m, ,0x1B[92m0x1B[94m**********************0x1B[97m#@@@@@#@@@@0x1B[94m*********0x1B[92m##0x1B[32m((/ /((((0x1B[97m\"", process_id="5560", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748856, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Exploitation", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:25", info_max_time="1686748800.000000000", info_min_time="1686748200.000000000", info_search_time="1686748851.712291000", lastTime="2023-06-14T13:16:25", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m((((((.0x1B[92m.0x1B[94m******************0x1B[97m/@@@@@/0x1B[94m***0x1B[92m/######0x1B[32m /((((((0x1B[97m\"", parent_process_id="1260", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m((((((.0x1B[92m.0x1B[94m******************0x1B[97m/@@@@@/0x1B[94m***0x1B[92m/######0x1B[32m /((((((0x1B[97m\"", process_id="5000", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748856, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Exploitation", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:26", info_max_time="1686748800.000000000", info_min_time="1686748200.000000000", info_search_time="1686748851.712291000", lastTime="2023-06-14T13:16:26", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m(((((((((. ,0x1B[92m(############################(0x1B[32m../(((((((((.0x1B[97m\"", parent_process_id="6812", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m(((((((((. ,0x1B[92m(############################(0x1B[32m../(((((((((.0x1B[97m\"", process_id="404", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748856, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Exploitation", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:25", info_max_time="1686748800.000000000", info_min_time="1686748200.000000000", info_search_time="1686748851.712291000", lastTime="2023-06-14T13:16:25", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m(((((((((((/* 0x1B[94m******************0x1B[32m/####### 0x1B[32m.(. ((((((0x1B[97m\"", parent_process_id="7092", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m(((((((((((/* 0x1B[94m******************0x1B[32m/####### 0x1B[32m.(. ((((((0x1B[97m\"", process_id="6964", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748856, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Exploitation", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:25", info_max_time="1686748800.000000000", info_min_time="1686748200.000000000", info_search_time="1686748851.712291000", lastTime="2023-06-14T13:16:25", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m((((((((((((((((* 0x1B[94m*****0x1B[32m,,,/########## 0x1B[32m.(* ,((((((0x1B[97m\"", parent_process_id="2300", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m((((((((((((((((* 0x1B[94m*****0x1B[32m,,,/########## 0x1B[32m.(* ,((((((0x1B[97m\"", process_id="5860", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748856, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Exploitation", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:25", info_max_time="1686748800.000000000", info_min_time="1686748200.000000000", info_search_time="1686748851.712291000", lastTime="2023-06-14T13:16:25", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m,/*,..*(((((((((((((((((((((((((((((((((,0x1B[97m\"", parent_process_id="7136", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m,/*,..*(((((((((((((((((((((((((((((((((,0x1B[97m\"", process_id="5832", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748856, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Exploitation", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:26", info_max_time="1686748800.000000000", info_min_time="1686748200.000000000", info_search_time="1686748851.712291000", lastTime="2023-06-14T13:16:26", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m(((((((((/, 0x1B[92m,####################(0x1B[32m/..((((((((((.0x1B[97m\"", parent_process_id="5836", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m(((((((((/, 0x1B[92m,####################(0x1B[32m/..((((((((((.0x1B[97m\"", process_id="6768", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748856, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Exploitation", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:25", info_max_time="1686748800.000000000", info_min_time="1686748200.000000000", info_search_time="1686748851.712291000", lastTime="2023-06-14T13:16:25", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m((,.,/((((((((((((((((((((/, */0x1B[97m\"", parent_process_id="1596", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m((,.,/((((((((((((((((((((/, */0x1B[97m\"", process_id="4308", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748856, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Exploitation", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:26", info_max_time="1686748800.000000000", info_min_time="1686748200.000000000", info_search_time="1686748851.712291000", lastTime="2023-06-14T13:16:26", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m(((((((((/,. 0x1B[92m,*//////*,.0x1B[32m ./(((((((((((.0x1B[97m\"", parent_process_id="2252", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m(((((((((/,. 0x1B[92m,*//////*,.0x1B[32m ./(((((((((((.0x1B[97m\"", process_id="5964", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748856, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Exploitation", annotations._all="T1202", annotations._all="Living Off The Land", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:16:26", info_max_time="1686748800.000000000", info_min_time="1686748200.000000000", info_search_time="1686748851.712291000", lastTime="2023-06-14T13:16:26", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m(((((((((((((((((((((((((((/0x1B[97m\"", parent_process_id="2268", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m(((((((((((((((((((((((((((/0x1B[97m\"", process_id="6488", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748792, search_name="ESCU - Processes launching netsh - Rule", analyticstories="Azorult", analyticstories="DHS Report TA18-074A", analyticstories="Disabling Security Tools", analyticstories="Netsh Abuse", annotations="{\"analytic_story\":[\"Netsh Abuse\",\"Disabling Security Tools\",\"DHS Report TA18-074A\",\"Azorult\"],\"cis20\":[\"CIS 10\"],\"confidence\":70,\"impact\":20,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1562.004\",\"T1562\"],\"nist\":[\"DE.AE\"]}", annotations._all="Exploitation", annotations._all="T1562", annotations._all="Azorult", annotations._all="DHS Report TA18-074A", annotations._all="T1562.004", annotations._all="Netsh Abuse", annotations._all="CIS 10", annotations._all="DE.AE", annotations._all="Disabling Security Tools", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Netsh Abuse", annotations.analytic_story="Disabling Security Tools", annotations.analytic_story="DHS Report TA18-074A", annotations.analytic_story="Azorult", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1562.004", annotations.mitre_attack="T1562", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:07", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748788.439210000", lastTime="2023-06-14T13:04:07", original_file_name="netsh.exe", parent_process="C:\\Windows\\system32\\cmd.exe /c netsh wlan show profiles | find \"Profile \"", parent_process_name="cmd.exe", process="netsh wlan show profiles", process_name="netsh.exe", risk_message="A process netsh.exe has launched netsh with command-line netsh wlan show profiles on ar-win-dc.attackrange.local.", risk_object="Administrator", risk_object_type="user", risk_score="14.0", savedsearch_description="This search looks for processes launching netsh.exe. Netsh is a command-line scripting utility that allows you to, either locally or remotely, display or modify the network configuration of a computer that is currently running. Netsh can be used as a persistence proxy technique to execute a helper DLL when netsh.exe is executed. In this search, we are looking for processes spawned by netsh.exe and executing commands via the command line.", user="Administrator" 1686748792, search_name="ESCU - Processes launching netsh - Rule", analyticstories="Azorult", analyticstories="DHS Report TA18-074A", analyticstories="Disabling Security Tools", analyticstories="Netsh Abuse", annotations="{\"analytic_story\":[\"Netsh Abuse\",\"Disabling Security Tools\",\"DHS Report TA18-074A\",\"Azorult\"],\"cis20\":[\"CIS 10\"],\"confidence\":70,\"impact\":20,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1562.004\",\"T1562\"],\"nist\":[\"DE.AE\"]}", annotations._all="Exploitation", annotations._all="T1562", annotations._all="Azorult", annotations._all="DHS Report TA18-074A", annotations._all="T1562.004", annotations._all="Netsh Abuse", annotations._all="CIS 10", annotations._all="DE.AE", annotations._all="Disabling Security Tools", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Netsh Abuse", annotations.analytic_story="Disabling Security Tools", annotations.analytic_story="DHS Report TA18-074A", annotations.analytic_story="Azorult", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1562.004", annotations.mitre_attack="T1562", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:07", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748788.439210000", lastTime="2023-06-14T13:04:07", original_file_name="netsh.exe", parent_process="C:\\Windows\\system32\\cmd.exe /c netsh wlan show profiles | find \"Profile \"", parent_process_name="cmd.exe", process="netsh wlan show profiles", process_name="netsh.exe", risk_message="A process netsh.exe has launched netsh with command-line netsh wlan show profiles on ar-win-dc.attackrange.local.", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="14.0", savedsearch_description="This search looks for processes launching netsh.exe. Netsh is a command-line scripting utility that allows you to, either locally or remotely, display or modify the network configuration of a computer that is currently running. Netsh can be used as a persistence proxy technique to execute a helper DLL when netsh.exe is executed. In this search, we are looking for processes spawned by netsh.exe and executing commands via the command line.", user="Administrator" 1686748792, search_name="ESCU - Processes launching netsh - Rule", analyticstories="Azorult", analyticstories="DHS Report TA18-074A", analyticstories="Disabling Security Tools", analyticstories="Netsh Abuse", annotations="{\"analytic_story\":[\"Netsh Abuse\",\"Disabling Security Tools\",\"DHS Report TA18-074A\",\"Azorult\"],\"cis20\":[\"CIS 10\"],\"confidence\":70,\"impact\":20,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1562.004\",\"T1562\"],\"nist\":[\"DE.AE\"]}", annotations._all="Exploitation", annotations._all="T1562", annotations._all="Azorult", annotations._all="DHS Report TA18-074A", annotations._all="T1562.004", annotations._all="Netsh Abuse", annotations._all="CIS 10", annotations._all="DE.AE", annotations._all="Disabling Security Tools", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Netsh Abuse", annotations.analytic_story="Disabling Security Tools", annotations.analytic_story="DHS Report TA18-074A", annotations.analytic_story="Azorult", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1562.004", annotations.mitre_attack="T1562", annotations.nist="DE.AE", count="3", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:06", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748788.439210000", lastTime="2023-06-14T13:04:07", original_file_name="unknown", parent_process="C:\\Windows\\System32\\cmd.exe", parent_process_name="cmd.exe", process="C:\\Windows\\System32\\netsh.exe firewall show config", process="C:\\Windows\\System32\\netsh.exe firewall show state", process="C:\\Windows\\System32\\netsh.exe wlan show profiles", process_name="netsh.exe", risk_message="A process netsh.exe has launched netsh with command-line C:\\Windows\\System32\\netsh.exe firewall show config C:\\Windows\\System32\\netsh.exe firewall show state C:\\Windows\\System32\\netsh.exe wlan show profiles on ar-win-dc.attackrange.local.", risk_object="Administrator", risk_object_type="user", risk_score="14.0", savedsearch_description="This search looks for processes launching netsh.exe. Netsh is a command-line scripting utility that allows you to, either locally or remotely, display or modify the network configuration of a computer that is currently running. Netsh can be used as a persistence proxy technique to execute a helper DLL when netsh.exe is executed. In this search, we are looking for processes spawned by netsh.exe and executing commands via the command line.", user="Administrator" 1686748792, search_name="ESCU - Processes launching netsh - Rule", analyticstories="Azorult", analyticstories="DHS Report TA18-074A", analyticstories="Disabling Security Tools", analyticstories="Netsh Abuse", annotations="{\"analytic_story\":[\"Netsh Abuse\",\"Disabling Security Tools\",\"DHS Report TA18-074A\",\"Azorult\"],\"cis20\":[\"CIS 10\"],\"confidence\":70,\"impact\":20,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1562.004\",\"T1562\"],\"nist\":[\"DE.AE\"]}", annotations._all="Exploitation", annotations._all="T1562", annotations._all="Azorult", annotations._all="DHS Report TA18-074A", annotations._all="T1562.004", annotations._all="Netsh Abuse", annotations._all="CIS 10", annotations._all="DE.AE", annotations._all="Disabling Security Tools", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Netsh Abuse", annotations.analytic_story="Disabling Security Tools", annotations.analytic_story="DHS Report TA18-074A", annotations.analytic_story="Azorult", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1562.004", annotations.mitre_attack="T1562", annotations.nist="DE.AE", count="3", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:06", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748788.439210000", lastTime="2023-06-14T13:04:07", original_file_name="unknown", parent_process="C:\\Windows\\System32\\cmd.exe", parent_process_name="cmd.exe", process="C:\\Windows\\System32\\netsh.exe firewall show config", process="C:\\Windows\\System32\\netsh.exe firewall show state", process="C:\\Windows\\System32\\netsh.exe wlan show profiles", process_name="netsh.exe", risk_message="A process netsh.exe has launched netsh with command-line C:\\Windows\\System32\\netsh.exe firewall show config C:\\Windows\\System32\\netsh.exe firewall show state C:\\Windows\\System32\\netsh.exe wlan show profiles on ar-win-dc.attackrange.local.", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="14.0", savedsearch_description="This search looks for processes launching netsh.exe. Netsh is a command-line scripting utility that allows you to, either locally or remotely, display or modify the network configuration of a computer that is currently running. Netsh can be used as a persistence proxy technique to execute a helper DLL when netsh.exe is executed. In this search, we are looking for processes spawned by netsh.exe and executing commands via the command line.", user="Administrator" 1686748792, search_name="ESCU - Processes launching netsh - Rule", analyticstories="Azorult", analyticstories="DHS Report TA18-074A", analyticstories="Disabling Security Tools", analyticstories="Netsh Abuse", annotations="{\"analytic_story\":[\"Netsh Abuse\",\"Disabling Security Tools\",\"DHS Report TA18-074A\",\"Azorult\"],\"cis20\":[\"CIS 10\"],\"confidence\":70,\"impact\":20,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1562.004\",\"T1562\"],\"nist\":[\"DE.AE\"]}", annotations._all="Exploitation", annotations._all="T1562", annotations._all="Azorult", annotations._all="DHS Report TA18-074A", annotations._all="T1562.004", annotations._all="Netsh Abuse", annotations._all="CIS 10", annotations._all="DE.AE", annotations._all="Disabling Security Tools", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Netsh Abuse", annotations.analytic_story="Disabling Security Tools", annotations.analytic_story="DHS Report TA18-074A", annotations.analytic_story="Azorult", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1562.004", annotations.mitre_attack="T1562", annotations.nist="DE.AE", count="2", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:06", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748788.439210000", lastTime="2023-06-14T13:04:06", original_file_name="netsh.exe", parent_process="\"cmd.exe\" /s /k pushd \"C:\\Temp\"", parent_process_name="cmd.exe", process="netsh firewall show config", process="netsh firewall show state", process_name="netsh.exe", risk_message="A process netsh.exe has launched netsh with command-line netsh firewall show config netsh firewall show state on ar-win-dc.attackrange.local.", risk_object="Administrator", risk_object_type="user", risk_score="14.0", savedsearch_description="This search looks for processes launching netsh.exe. Netsh is a command-line scripting utility that allows you to, either locally or remotely, display or modify the network configuration of a computer that is currently running. Netsh can be used as a persistence proxy technique to execute a helper DLL when netsh.exe is executed. In this search, we are looking for processes spawned by netsh.exe and executing commands via the command line.", user="Administrator" 1686748792, search_name="ESCU - Processes launching netsh - Rule", analyticstories="Azorult", analyticstories="DHS Report TA18-074A", analyticstories="Disabling Security Tools", analyticstories="Netsh Abuse", annotations="{\"analytic_story\":[\"Netsh Abuse\",\"Disabling Security Tools\",\"DHS Report TA18-074A\",\"Azorult\"],\"cis20\":[\"CIS 10\"],\"confidence\":70,\"impact\":20,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1562.004\",\"T1562\"],\"nist\":[\"DE.AE\"]}", annotations._all="Exploitation", annotations._all="T1562", annotations._all="Azorult", annotations._all="DHS Report TA18-074A", annotations._all="T1562.004", annotations._all="Netsh Abuse", annotations._all="CIS 10", annotations._all="DE.AE", annotations._all="Disabling Security Tools", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Netsh Abuse", annotations.analytic_story="Disabling Security Tools", annotations.analytic_story="DHS Report TA18-074A", annotations.analytic_story="Azorult", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1562.004", annotations.mitre_attack="T1562", annotations.nist="DE.AE", count="2", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:06", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748788.439210000", lastTime="2023-06-14T13:04:06", original_file_name="netsh.exe", parent_process="\"cmd.exe\" /s /k pushd \"C:\\Temp\"", parent_process_name="cmd.exe", process="netsh firewall show config", process="netsh firewall show state", process_name="netsh.exe", risk_message="A process netsh.exe has launched netsh with command-line netsh firewall show config netsh firewall show state on ar-win-dc.attackrange.local.", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="14.0", savedsearch_description="This search looks for processes launching netsh.exe. Netsh is a command-line scripting utility that allows you to, either locally or remotely, display or modify the network configuration of a computer that is currently running. Netsh can be used as a persistence proxy technique to execute a helper DLL when netsh.exe is executed. In this search, we are looking for processes spawned by netsh.exe and executing commands via the command line.", user="Administrator" 1686748442, search_name="ESCU - Cmdline Tool Not Executed In CMD Shell - Rule", analyticstories="CISA AA22-277A", analyticstories="FIN7", analyticstories="Qakbot", annotations="{\"analytic_story\":[\"FIN7\",\"Qakbot\",\"CISA AA22-277A\",\"Qakbot\"],\"cis20\":[\"CIS 10\"],\"confidence\":80,\"impact\":70,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1059\",\"T1059.007\"],\"nist\":[\"DE.CM\"]}", annotations._all="Installation", annotations._all="CISA AA22-277A", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="FIN7", annotations._all="Qakbot", annotations._all="T1059.007", annotations._all="T1059", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="FIN7", annotations.analytic_story="Qakbot", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Qakbot", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1059", annotations.mitre_attack="T1059.007", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:08", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748438.701389000", lastTime="2023-06-14T13:04:08", original_file_name="net1.exe", parent_process="net user Administrator /domain", parent_process_name="net.exe", process="C:\\Windows\\system32\\net1 user Administrator /domain", process_id="5676", process_name="net1.exe", risk_message="A non-standard parent process net.exe spawned child process net1.exe to execute command-line tool on ar-win-dc.attackrange.local.", risk_object="net1.exe", risk_object_type="other", risk_score="56.0", savedsearch_description="The following analytic identifies a non-standard parent process (not matching CMD, PowerShell, or Explorer) spawning `ipconfig.exe` or `systeminfo.exe`. This particular behavior was seen in FIN7's JSSLoader .NET payload. This is also typically seen when an adversary is injected into another process performing different discovery techniques. This event stands out as a TTP since these tools are commonly executed with a shell application or Explorer parent, and not by another application. This TTP is a good indicator for an adversary gathering host information, but one possible false positive might be an automated tool used by a system administator.", user="Administrator" 1686748442, search_name="ESCU - Cmdline Tool Not Executed In CMD Shell - Rule", analyticstories="CISA AA22-277A", analyticstories="FIN7", analyticstories="Qakbot", annotations="{\"analytic_story\":[\"FIN7\",\"Qakbot\",\"CISA AA22-277A\",\"Qakbot\"],\"cis20\":[\"CIS 10\"],\"confidence\":80,\"impact\":70,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1059\",\"T1059.007\"],\"nist\":[\"DE.CM\"]}", annotations._all="Installation", annotations._all="CISA AA22-277A", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="FIN7", annotations._all="Qakbot", annotations._all="T1059.007", annotations._all="T1059", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="FIN7", annotations.analytic_story="Qakbot", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Qakbot", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1059", annotations.mitre_attack="T1059.007", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:08", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748438.701389000", lastTime="2023-06-14T13:04:08", original_file_name="net1.exe", parent_process="net user Administrator /domain", parent_process_name="net.exe", process="C:\\Windows\\system32\\net1 user Administrator /domain", process_id="5676", process_name="net1.exe", risk_message="A non-standard parent process net.exe spawned child process net1.exe to execute command-line tool on ar-win-dc.attackrange.local.", risk_object="net.exe", risk_object_type="other", risk_score="56.0", savedsearch_description="The following analytic identifies a non-standard parent process (not matching CMD, PowerShell, or Explorer) spawning `ipconfig.exe` or `systeminfo.exe`. This particular behavior was seen in FIN7's JSSLoader .NET payload. This is also typically seen when an adversary is injected into another process performing different discovery techniques. This event stands out as a TTP since these tools are commonly executed with a shell application or Explorer parent, and not by another application. This TTP is a good indicator for an adversary gathering host information, but one possible false positive might be an automated tool used by a system administator.", user="Administrator" 1686748442, search_name="ESCU - Cmdline Tool Not Executed In CMD Shell - Rule", analyticstories="CISA AA22-277A", analyticstories="FIN7", analyticstories="Qakbot", annotations="{\"analytic_story\":[\"FIN7\",\"Qakbot\",\"CISA AA22-277A\",\"Qakbot\"],\"cis20\":[\"CIS 10\"],\"confidence\":80,\"impact\":70,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1059\",\"T1059.007\"],\"nist\":[\"DE.CM\"]}", annotations._all="Installation", annotations._all="CISA AA22-277A", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="FIN7", annotations._all="Qakbot", annotations._all="T1059.007", annotations._all="T1059", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="FIN7", annotations.analytic_story="Qakbot", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Qakbot", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1059", annotations.mitre_attack="T1059.007", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:08", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748438.701389000", lastTime="2023-06-14T13:04:08", original_file_name="net1.exe", parent_process="net user Administrator /domain", parent_process_name="net.exe", process="C:\\Windows\\system32\\net1 user Administrator /domain", process_id="5676", process_name="net1.exe", risk_message="A non-standard parent process net.exe spawned child process net1.exe to execute command-line tool on ar-win-dc.attackrange.local.", risk_object="Administrator", risk_object_type="user", risk_score="56.0", savedsearch_description="The following analytic identifies a non-standard parent process (not matching CMD, PowerShell, or Explorer) spawning `ipconfig.exe` or `systeminfo.exe`. This particular behavior was seen in FIN7's JSSLoader .NET payload. This is also typically seen when an adversary is injected into another process performing different discovery techniques. This event stands out as a TTP since these tools are commonly executed with a shell application or Explorer parent, and not by another application. This TTP is a good indicator for an adversary gathering host information, but one possible false positive might be an automated tool used by a system administator.", user="Administrator" 1686748442, search_name="ESCU - Cmdline Tool Not Executed In CMD Shell - Rule", analyticstories="CISA AA22-277A", analyticstories="FIN7", analyticstories="Qakbot", annotations="{\"analytic_story\":[\"FIN7\",\"Qakbot\",\"CISA AA22-277A\",\"Qakbot\"],\"cis20\":[\"CIS 10\"],\"confidence\":80,\"impact\":70,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1059\",\"T1059.007\"],\"nist\":[\"DE.CM\"]}", annotations._all="Installation", annotations._all="CISA AA22-277A", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="FIN7", annotations._all="Qakbot", annotations._all="T1059.007", annotations._all="T1059", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="FIN7", annotations.analytic_story="Qakbot", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Qakbot", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1059", annotations.mitre_attack="T1059.007", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:08", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748438.701389000", lastTime="2023-06-14T13:04:08", original_file_name="net1.exe", parent_process="net user Administrator /domain", parent_process_name="net.exe", process="C:\\Windows\\system32\\net1 user Administrator /domain", process_id="5676", process_name="net1.exe", risk_message="A non-standard parent process net.exe spawned child process net1.exe to execute command-line tool on ar-win-dc.attackrange.local.", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="56.0", savedsearch_description="The following analytic identifies a non-standard parent process (not matching CMD, PowerShell, or Explorer) spawning `ipconfig.exe` or `systeminfo.exe`. This particular behavior was seen in FIN7's JSSLoader .NET payload. This is also typically seen when an adversary is injected into another process performing different discovery techniques. This event stands out as a TTP since these tools are commonly executed with a shell application or Explorer parent, and not by another application. This TTP is a good indicator for an adversary gathering host information, but one possible false positive might be an automated tool used by a system administator.", user="Administrator" 1686748442, search_name="ESCU - Cmdline Tool Not Executed In CMD Shell - Rule", analyticstories="CISA AA22-277A", analyticstories="FIN7", analyticstories="Qakbot", annotations="{\"analytic_story\":[\"FIN7\",\"Qakbot\",\"CISA AA22-277A\",\"Qakbot\"],\"cis20\":[\"CIS 10\"],\"confidence\":80,\"impact\":70,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1059\",\"T1059.007\"],\"nist\":[\"DE.CM\"]}", annotations._all="Installation", annotations._all="CISA AA22-277A", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="FIN7", annotations._all="Qakbot", annotations._all="T1059.007", annotations._all="T1059", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="FIN7", annotations.analytic_story="Qakbot", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Qakbot", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1059", annotations.mitre_attack="T1059.007", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:08", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748438.701389000", lastTime="2023-06-14T13:04:08", original_file_name="net1.exe", parent_process="net user Administrator", parent_process_name="net.exe", process="C:\\Windows\\system32\\net1 user Administrator", process_id="6088", process_name="net1.exe", risk_message="A non-standard parent process net.exe spawned child process net1.exe to execute command-line tool on ar-win-dc.attackrange.local.", risk_object="net1.exe", risk_object_type="other", risk_score="56.0", savedsearch_description="The following analytic identifies a non-standard parent process (not matching CMD, PowerShell, or Explorer) spawning `ipconfig.exe` or `systeminfo.exe`. This particular behavior was seen in FIN7's JSSLoader .NET payload. This is also typically seen when an adversary is injected into another process performing different discovery techniques. This event stands out as a TTP since these tools are commonly executed with a shell application or Explorer parent, and not by another application. This TTP is a good indicator for an adversary gathering host information, but one possible false positive might be an automated tool used by a system administator.", user="Administrator" 1686748442, search_name="ESCU - Cmdline Tool Not Executed In CMD Shell - Rule", analyticstories="CISA AA22-277A", analyticstories="FIN7", analyticstories="Qakbot", annotations="{\"analytic_story\":[\"FIN7\",\"Qakbot\",\"CISA AA22-277A\",\"Qakbot\"],\"cis20\":[\"CIS 10\"],\"confidence\":80,\"impact\":70,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1059\",\"T1059.007\"],\"nist\":[\"DE.CM\"]}", annotations._all="Installation", annotations._all="CISA AA22-277A", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="FIN7", annotations._all="Qakbot", annotations._all="T1059.007", annotations._all="T1059", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="FIN7", annotations.analytic_story="Qakbot", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Qakbot", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1059", annotations.mitre_attack="T1059.007", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:08", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748438.701389000", lastTime="2023-06-14T13:04:08", original_file_name="net1.exe", parent_process="net user Administrator", parent_process_name="net.exe", process="C:\\Windows\\system32\\net1 user Administrator", process_id="6088", process_name="net1.exe", risk_message="A non-standard parent process net.exe spawned child process net1.exe to execute command-line tool on ar-win-dc.attackrange.local.", risk_object="net.exe", risk_object_type="other", risk_score="56.0", savedsearch_description="The following analytic identifies a non-standard parent process (not matching CMD, PowerShell, or Explorer) spawning `ipconfig.exe` or `systeminfo.exe`. This particular behavior was seen in FIN7's JSSLoader .NET payload. This is also typically seen when an adversary is injected into another process performing different discovery techniques. This event stands out as a TTP since these tools are commonly executed with a shell application or Explorer parent, and not by another application. This TTP is a good indicator for an adversary gathering host information, but one possible false positive might be an automated tool used by a system administator.", user="Administrator" 1686748442, search_name="ESCU - Cmdline Tool Not Executed In CMD Shell - Rule", analyticstories="CISA AA22-277A", analyticstories="FIN7", analyticstories="Qakbot", annotations="{\"analytic_story\":[\"FIN7\",\"Qakbot\",\"CISA AA22-277A\",\"Qakbot\"],\"cis20\":[\"CIS 10\"],\"confidence\":80,\"impact\":70,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1059\",\"T1059.007\"],\"nist\":[\"DE.CM\"]}", annotations._all="Installation", annotations._all="CISA AA22-277A", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="FIN7", annotations._all="Qakbot", annotations._all="T1059.007", annotations._all="T1059", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="FIN7", annotations.analytic_story="Qakbot", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Qakbot", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1059", annotations.mitre_attack="T1059.007", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:08", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748438.701389000", lastTime="2023-06-14T13:04:08", original_file_name="net1.exe", parent_process="net user Administrator", parent_process_name="net.exe", process="C:\\Windows\\system32\\net1 user Administrator", process_id="6088", process_name="net1.exe", risk_message="A non-standard parent process net.exe spawned child process net1.exe to execute command-line tool on ar-win-dc.attackrange.local.", risk_object="Administrator", risk_object_type="user", risk_score="56.0", savedsearch_description="The following analytic identifies a non-standard parent process (not matching CMD, PowerShell, or Explorer) spawning `ipconfig.exe` or `systeminfo.exe`. This particular behavior was seen in FIN7's JSSLoader .NET payload. This is also typically seen when an adversary is injected into another process performing different discovery techniques. This event stands out as a TTP since these tools are commonly executed with a shell application or Explorer parent, and not by another application. This TTP is a good indicator for an adversary gathering host information, but one possible false positive might be an automated tool used by a system administator.", user="Administrator" 1686748442, search_name="ESCU - Cmdline Tool Not Executed In CMD Shell - Rule", analyticstories="CISA AA22-277A", analyticstories="FIN7", analyticstories="Qakbot", annotations="{\"analytic_story\":[\"FIN7\",\"Qakbot\",\"CISA AA22-277A\",\"Qakbot\"],\"cis20\":[\"CIS 10\"],\"confidence\":80,\"impact\":70,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1059\",\"T1059.007\"],\"nist\":[\"DE.CM\"]}", annotations._all="Installation", annotations._all="CISA AA22-277A", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="FIN7", annotations._all="Qakbot", annotations._all="T1059.007", annotations._all="T1059", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="FIN7", annotations.analytic_story="Qakbot", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Qakbot", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1059", annotations.mitre_attack="T1059.007", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:08", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748438.701389000", lastTime="2023-06-14T13:04:08", original_file_name="net1.exe", parent_process="net user Administrator", parent_process_name="net.exe", process="C:\\Windows\\system32\\net1 user Administrator", process_id="6088", process_name="net1.exe", risk_message="A non-standard parent process net.exe spawned child process net1.exe to execute command-line tool on ar-win-dc.attackrange.local.", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="56.0", savedsearch_description="The following analytic identifies a non-standard parent process (not matching CMD, PowerShell, or Explorer) spawning `ipconfig.exe` or `systeminfo.exe`. This particular behavior was seen in FIN7's JSSLoader .NET payload. This is also typically seen when an adversary is injected into another process performing different discovery techniques. This event stands out as a TTP since these tools are commonly executed with a shell application or Explorer parent, and not by another application. This TTP is a good indicator for an adversary gathering host information, but one possible false positive might be an automated tool used by a system administator.", user="Administrator" 1686748442, search_name="ESCU - Cmdline Tool Not Executed In CMD Shell - Rule", analyticstories="CISA AA22-277A", analyticstories="FIN7", analyticstories="Qakbot", annotations="{\"analytic_story\":[\"FIN7\",\"Qakbot\",\"CISA AA22-277A\",\"Qakbot\"],\"cis20\":[\"CIS 10\"],\"confidence\":80,\"impact\":70,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1059\",\"T1059.007\"],\"nist\":[\"DE.CM\"]}", annotations._all="Installation", annotations._all="CISA AA22-277A", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="FIN7", annotations._all="Qakbot", annotations._all="T1059.007", annotations._all="T1059", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="FIN7", annotations.analytic_story="Qakbot", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Qakbot", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1059", annotations.mitre_attack="T1059.007", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:08", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748438.701389000", lastTime="2023-06-14T13:04:08", original_file_name="net1.exe", parent_process="net user", parent_process_name="net.exe", process="C:\\Windows\\system32\\net1 user", process_id="2616", process_name="net1.exe", risk_message="A non-standard parent process net.exe spawned child process net1.exe to execute command-line tool on ar-win-dc.attackrange.local.", risk_object="net1.exe", risk_object_type="other", risk_score="56.0", savedsearch_description="The following analytic identifies a non-standard parent process (not matching CMD, PowerShell, or Explorer) spawning `ipconfig.exe` or `systeminfo.exe`. This particular behavior was seen in FIN7's JSSLoader .NET payload. This is also typically seen when an adversary is injected into another process performing different discovery techniques. This event stands out as a TTP since these tools are commonly executed with a shell application or Explorer parent, and not by another application. This TTP is a good indicator for an adversary gathering host information, but one possible false positive might be an automated tool used by a system administator.", user="Administrator" 1686748442, search_name="ESCU - Cmdline Tool Not Executed In CMD Shell - Rule", analyticstories="CISA AA22-277A", analyticstories="FIN7", analyticstories="Qakbot", annotations="{\"analytic_story\":[\"FIN7\",\"Qakbot\",\"CISA AA22-277A\",\"Qakbot\"],\"cis20\":[\"CIS 10\"],\"confidence\":80,\"impact\":70,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1059\",\"T1059.007\"],\"nist\":[\"DE.CM\"]}", annotations._all="Installation", annotations._all="CISA AA22-277A", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="FIN7", annotations._all="Qakbot", annotations._all="T1059.007", annotations._all="T1059", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="FIN7", annotations.analytic_story="Qakbot", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Qakbot", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1059", annotations.mitre_attack="T1059.007", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:08", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748438.701389000", lastTime="2023-06-14T13:04:08", original_file_name="net1.exe", parent_process="net user", parent_process_name="net.exe", process="C:\\Windows\\system32\\net1 user", process_id="2616", process_name="net1.exe", risk_message="A non-standard parent process net.exe spawned child process net1.exe to execute command-line tool on ar-win-dc.attackrange.local.", risk_object="net.exe", risk_object_type="other", risk_score="56.0", savedsearch_description="The following analytic identifies a non-standard parent process (not matching CMD, PowerShell, or Explorer) spawning `ipconfig.exe` or `systeminfo.exe`. This particular behavior was seen in FIN7's JSSLoader .NET payload. This is also typically seen when an adversary is injected into another process performing different discovery techniques. This event stands out as a TTP since these tools are commonly executed with a shell application or Explorer parent, and not by another application. This TTP is a good indicator for an adversary gathering host information, but one possible false positive might be an automated tool used by a system administator.", user="Administrator" 1686748442, search_name="ESCU - Cmdline Tool Not Executed In CMD Shell - Rule", analyticstories="CISA AA22-277A", analyticstories="FIN7", analyticstories="Qakbot", annotations="{\"analytic_story\":[\"FIN7\",\"Qakbot\",\"CISA AA22-277A\",\"Qakbot\"],\"cis20\":[\"CIS 10\"],\"confidence\":80,\"impact\":70,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1059\",\"T1059.007\"],\"nist\":[\"DE.CM\"]}", annotations._all="Installation", annotations._all="CISA AA22-277A", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="FIN7", annotations._all="Qakbot", annotations._all="T1059.007", annotations._all="T1059", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="FIN7", annotations.analytic_story="Qakbot", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Qakbot", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1059", annotations.mitre_attack="T1059.007", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:08", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748438.701389000", lastTime="2023-06-14T13:04:08", original_file_name="net1.exe", parent_process="net user", parent_process_name="net.exe", process="C:\\Windows\\system32\\net1 user", process_id="2616", process_name="net1.exe", risk_message="A non-standard parent process net.exe spawned child process net1.exe to execute command-line tool on ar-win-dc.attackrange.local.", risk_object="Administrator", risk_object_type="user", risk_score="56.0", savedsearch_description="The following analytic identifies a non-standard parent process (not matching CMD, PowerShell, or Explorer) spawning `ipconfig.exe` or `systeminfo.exe`. This particular behavior was seen in FIN7's JSSLoader .NET payload. This is also typically seen when an adversary is injected into another process performing different discovery techniques. This event stands out as a TTP since these tools are commonly executed with a shell application or Explorer parent, and not by another application. This TTP is a good indicator for an adversary gathering host information, but one possible false positive might be an automated tool used by a system administator.", user="Administrator" 1686748442, search_name="ESCU - Cmdline Tool Not Executed In CMD Shell - Rule", analyticstories="CISA AA22-277A", analyticstories="FIN7", analyticstories="Qakbot", annotations="{\"analytic_story\":[\"FIN7\",\"Qakbot\",\"CISA AA22-277A\",\"Qakbot\"],\"cis20\":[\"CIS 10\"],\"confidence\":80,\"impact\":70,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1059\",\"T1059.007\"],\"nist\":[\"DE.CM\"]}", annotations._all="Installation", annotations._all="CISA AA22-277A", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="FIN7", annotations._all="Qakbot", annotations._all="T1059.007", annotations._all="T1059", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="FIN7", annotations.analytic_story="Qakbot", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Qakbot", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1059", annotations.mitre_attack="T1059.007", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:08", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748438.701389000", lastTime="2023-06-14T13:04:08", original_file_name="net1.exe", parent_process="net user", parent_process_name="net.exe", process="C:\\Windows\\system32\\net1 user", process_id="2616", process_name="net1.exe", risk_message="A non-standard parent process net.exe spawned child process net1.exe to execute command-line tool on ar-win-dc.attackrange.local.", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="56.0", savedsearch_description="The following analytic identifies a non-standard parent process (not matching CMD, PowerShell, or Explorer) spawning `ipconfig.exe` or `systeminfo.exe`. This particular behavior was seen in FIN7's JSSLoader .NET payload. This is also typically seen when an adversary is injected into another process performing different discovery techniques. This event stands out as a TTP since these tools are commonly executed with a shell application or Explorer parent, and not by another application. This TTP is a good indicator for an adversary gathering host information, but one possible false positive might be an automated tool used by a system administator.", user="Administrator" 1686748442, search_name="ESCU - Cmdline Tool Not Executed In CMD Shell - Rule", analyticstories="CISA AA22-277A", analyticstories="FIN7", analyticstories="Qakbot", annotations="{\"analytic_story\":[\"FIN7\",\"Qakbot\",\"CISA AA22-277A\",\"Qakbot\"],\"cis20\":[\"CIS 10\"],\"confidence\":80,\"impact\":70,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1059\",\"T1059.007\"],\"nist\":[\"DE.CM\"]}", annotations._all="Installation", annotations._all="CISA AA22-277A", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="FIN7", annotations._all="Qakbot", annotations._all="T1059.007", annotations._all="T1059", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="FIN7", annotations.analytic_story="Qakbot", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Qakbot", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1059", annotations.mitre_attack="T1059.007", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:06", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748438.701389000", lastTime="2023-06-14T13:04:06", original_file_name="net1.exe", parent_process="net share", parent_process_name="net.exe", process="C:\\Windows\\system32\\net1 share", process_id="6688", process_name="net1.exe", risk_message="A non-standard parent process net.exe spawned child process net1.exe to execute command-line tool on ar-win-dc.attackrange.local.", risk_object="net1.exe", risk_object_type="other", risk_score="56.0", savedsearch_description="The following analytic identifies a non-standard parent process (not matching CMD, PowerShell, or Explorer) spawning `ipconfig.exe` or `systeminfo.exe`. This particular behavior was seen in FIN7's JSSLoader .NET payload. This is also typically seen when an adversary is injected into another process performing different discovery techniques. This event stands out as a TTP since these tools are commonly executed with a shell application or Explorer parent, and not by another application. This TTP is a good indicator for an adversary gathering host information, but one possible false positive might be an automated tool used by a system administator.", user="Administrator" 1686748442, search_name="ESCU - Cmdline Tool Not Executed In CMD Shell - Rule", analyticstories="CISA AA22-277A", analyticstories="FIN7", analyticstories="Qakbot", annotations="{\"analytic_story\":[\"FIN7\",\"Qakbot\",\"CISA AA22-277A\",\"Qakbot\"],\"cis20\":[\"CIS 10\"],\"confidence\":80,\"impact\":70,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1059\",\"T1059.007\"],\"nist\":[\"DE.CM\"]}", annotations._all="Installation", annotations._all="CISA AA22-277A", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="FIN7", annotations._all="Qakbot", annotations._all="T1059.007", annotations._all="T1059", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="FIN7", annotations.analytic_story="Qakbot", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Qakbot", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1059", annotations.mitre_attack="T1059.007", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:06", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748438.701389000", lastTime="2023-06-14T13:04:06", original_file_name="net1.exe", parent_process="net share", parent_process_name="net.exe", process="C:\\Windows\\system32\\net1 share", process_id="6688", process_name="net1.exe", risk_message="A non-standard parent process net.exe spawned child process net1.exe to execute command-line tool on ar-win-dc.attackrange.local.", risk_object="net.exe", risk_object_type="other", risk_score="56.0", savedsearch_description="The following analytic identifies a non-standard parent process (not matching CMD, PowerShell, or Explorer) spawning `ipconfig.exe` or `systeminfo.exe`. This particular behavior was seen in FIN7's JSSLoader .NET payload. This is also typically seen when an adversary is injected into another process performing different discovery techniques. This event stands out as a TTP since these tools are commonly executed with a shell application or Explorer parent, and not by another application. This TTP is a good indicator for an adversary gathering host information, but one possible false positive might be an automated tool used by a system administator.", user="Administrator" 1686748442, search_name="ESCU - Cmdline Tool Not Executed In CMD Shell - Rule", analyticstories="CISA AA22-277A", analyticstories="FIN7", analyticstories="Qakbot", annotations="{\"analytic_story\":[\"FIN7\",\"Qakbot\",\"CISA AA22-277A\",\"Qakbot\"],\"cis20\":[\"CIS 10\"],\"confidence\":80,\"impact\":70,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1059\",\"T1059.007\"],\"nist\":[\"DE.CM\"]}", annotations._all="Installation", annotations._all="CISA AA22-277A", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="FIN7", annotations._all="Qakbot", annotations._all="T1059.007", annotations._all="T1059", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="FIN7", annotations.analytic_story="Qakbot", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Qakbot", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1059", annotations.mitre_attack="T1059.007", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:06", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748438.701389000", lastTime="2023-06-14T13:04:06", original_file_name="net1.exe", parent_process="net share", parent_process_name="net.exe", process="C:\\Windows\\system32\\net1 share", process_id="6688", process_name="net1.exe", risk_message="A non-standard parent process net.exe spawned child process net1.exe to execute command-line tool on ar-win-dc.attackrange.local.", risk_object="Administrator", risk_object_type="user", risk_score="56.0", savedsearch_description="The following analytic identifies a non-standard parent process (not matching CMD, PowerShell, or Explorer) spawning `ipconfig.exe` or `systeminfo.exe`. This particular behavior was seen in FIN7's JSSLoader .NET payload. This is also typically seen when an adversary is injected into another process performing different discovery techniques. This event stands out as a TTP since these tools are commonly executed with a shell application or Explorer parent, and not by another application. This TTP is a good indicator for an adversary gathering host information, but one possible false positive might be an automated tool used by a system administator.", user="Administrator" 1686748442, search_name="ESCU - Cmdline Tool Not Executed In CMD Shell - Rule", analyticstories="CISA AA22-277A", analyticstories="FIN7", analyticstories="Qakbot", annotations="{\"analytic_story\":[\"FIN7\",\"Qakbot\",\"CISA AA22-277A\",\"Qakbot\"],\"cis20\":[\"CIS 10\"],\"confidence\":80,\"impact\":70,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1059\",\"T1059.007\"],\"nist\":[\"DE.CM\"]}", annotations._all="Installation", annotations._all="CISA AA22-277A", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="FIN7", annotations._all="Qakbot", annotations._all="T1059.007", annotations._all="T1059", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="FIN7", annotations.analytic_story="Qakbot", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Qakbot", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1059", annotations.mitre_attack="T1059.007", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:06", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748438.701389000", lastTime="2023-06-14T13:04:06", original_file_name="net1.exe", parent_process="net share", parent_process_name="net.exe", process="C:\\Windows\\system32\\net1 share", process_id="6688", process_name="net1.exe", risk_message="A non-standard parent process net.exe spawned child process net1.exe to execute command-line tool on ar-win-dc.attackrange.local.", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="56.0", savedsearch_description="The following analytic identifies a non-standard parent process (not matching CMD, PowerShell, or Explorer) spawning `ipconfig.exe` or `systeminfo.exe`. This particular behavior was seen in FIN7's JSSLoader .NET payload. This is also typically seen when an adversary is injected into another process performing different discovery techniques. This event stands out as a TTP since these tools are commonly executed with a shell application or Explorer parent, and not by another application. This TTP is a good indicator for an adversary gathering host information, but one possible false positive might be an automated tool used by a system administator.", user="Administrator" 1686748442, search_name="ESCU - Cmdline Tool Not Executed In CMD Shell - Rule", analyticstories="CISA AA22-277A", analyticstories="FIN7", analyticstories="Qakbot", annotations="{\"analytic_story\":[\"FIN7\",\"Qakbot\",\"CISA AA22-277A\",\"Qakbot\"],\"cis20\":[\"CIS 10\"],\"confidence\":80,\"impact\":70,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1059\",\"T1059.007\"],\"nist\":[\"DE.CM\"]}", annotations._all="Installation", annotations._all="CISA AA22-277A", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="FIN7", annotations._all="Qakbot", annotations._all="T1059.007", annotations._all="T1059", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="FIN7", annotations.analytic_story="Qakbot", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Qakbot", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1059", annotations.mitre_attack="T1059.007", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:09", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748438.701389000", lastTime="2023-06-14T13:04:09", original_file_name="net1.exe", parent_process="net localgroup Administrators", parent_process_name="net.exe", process="C:\\Windows\\system32\\net1 localgroup Administrators", process_id="7104", process_name="net1.exe", risk_message="A non-standard parent process net.exe spawned child process net1.exe to execute command-line tool on ar-win-dc.attackrange.local.", risk_object="net1.exe", risk_object_type="other", risk_score="56.0", savedsearch_description="The following analytic identifies a non-standard parent process (not matching CMD, PowerShell, or Explorer) spawning `ipconfig.exe` or `systeminfo.exe`. This particular behavior was seen in FIN7's JSSLoader .NET payload. This is also typically seen when an adversary is injected into another process performing different discovery techniques. This event stands out as a TTP since these tools are commonly executed with a shell application or Explorer parent, and not by another application. This TTP is a good indicator for an adversary gathering host information, but one possible false positive might be an automated tool used by a system administator.", user="Administrator" 1686748442, search_name="ESCU - Cmdline Tool Not Executed In CMD Shell - Rule", analyticstories="CISA AA22-277A", analyticstories="FIN7", analyticstories="Qakbot", annotations="{\"analytic_story\":[\"FIN7\",\"Qakbot\",\"CISA AA22-277A\",\"Qakbot\"],\"cis20\":[\"CIS 10\"],\"confidence\":80,\"impact\":70,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1059\",\"T1059.007\"],\"nist\":[\"DE.CM\"]}", annotations._all="Installation", annotations._all="CISA AA22-277A", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="FIN7", annotations._all="Qakbot", annotations._all="T1059.007", annotations._all="T1059", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="FIN7", annotations.analytic_story="Qakbot", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Qakbot", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1059", annotations.mitre_attack="T1059.007", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:09", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748438.701389000", lastTime="2023-06-14T13:04:09", original_file_name="net1.exe", parent_process="net localgroup Administrators", parent_process_name="net.exe", process="C:\\Windows\\system32\\net1 localgroup Administrators", process_id="7104", process_name="net1.exe", risk_message="A non-standard parent process net.exe spawned child process net1.exe to execute command-line tool on ar-win-dc.attackrange.local.", risk_object="net.exe", risk_object_type="other", risk_score="56.0", savedsearch_description="The following analytic identifies a non-standard parent process (not matching CMD, PowerShell, or Explorer) spawning `ipconfig.exe` or `systeminfo.exe`. This particular behavior was seen in FIN7's JSSLoader .NET payload. This is also typically seen when an adversary is injected into another process performing different discovery techniques. This event stands out as a TTP since these tools are commonly executed with a shell application or Explorer parent, and not by another application. This TTP is a good indicator for an adversary gathering host information, but one possible false positive might be an automated tool used by a system administator.", user="Administrator" 1686748442, search_name="ESCU - Cmdline Tool Not Executed In CMD Shell - Rule", analyticstories="CISA AA22-277A", analyticstories="FIN7", analyticstories="Qakbot", annotations="{\"analytic_story\":[\"FIN7\",\"Qakbot\",\"CISA AA22-277A\",\"Qakbot\"],\"cis20\":[\"CIS 10\"],\"confidence\":80,\"impact\":70,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1059\",\"T1059.007\"],\"nist\":[\"DE.CM\"]}", annotations._all="Installation", annotations._all="CISA AA22-277A", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="FIN7", annotations._all="Qakbot", annotations._all="T1059.007", annotations._all="T1059", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="FIN7", annotations.analytic_story="Qakbot", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Qakbot", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1059", annotations.mitre_attack="T1059.007", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:09", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748438.701389000", lastTime="2023-06-14T13:04:09", original_file_name="net1.exe", parent_process="net localgroup Administrators", parent_process_name="net.exe", process="C:\\Windows\\system32\\net1 localgroup Administrators", process_id="7104", process_name="net1.exe", risk_message="A non-standard parent process net.exe spawned child process net1.exe to execute command-line tool on ar-win-dc.attackrange.local.", risk_object="Administrator", risk_object_type="user", risk_score="56.0", savedsearch_description="The following analytic identifies a non-standard parent process (not matching CMD, PowerShell, or Explorer) spawning `ipconfig.exe` or `systeminfo.exe`. This particular behavior was seen in FIN7's JSSLoader .NET payload. This is also typically seen when an adversary is injected into another process performing different discovery techniques. This event stands out as a TTP since these tools are commonly executed with a shell application or Explorer parent, and not by another application. This TTP is a good indicator for an adversary gathering host information, but one possible false positive might be an automated tool used by a system administator.", user="Administrator" 1686748442, search_name="ESCU - Cmdline Tool Not Executed In CMD Shell - Rule", analyticstories="CISA AA22-277A", analyticstories="FIN7", analyticstories="Qakbot", annotations="{\"analytic_story\":[\"FIN7\",\"Qakbot\",\"CISA AA22-277A\",\"Qakbot\"],\"cis20\":[\"CIS 10\"],\"confidence\":80,\"impact\":70,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1059\",\"T1059.007\"],\"nist\":[\"DE.CM\"]}", annotations._all="Installation", annotations._all="CISA AA22-277A", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="FIN7", annotations._all="Qakbot", annotations._all="T1059.007", annotations._all="T1059", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="FIN7", annotations.analytic_story="Qakbot", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Qakbot", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1059", annotations.mitre_attack="T1059.007", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:09", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748438.701389000", lastTime="2023-06-14T13:04:09", original_file_name="net1.exe", parent_process="net localgroup Administrators", parent_process_name="net.exe", process="C:\\Windows\\system32\\net1 localgroup Administrators", process_id="7104", process_name="net1.exe", risk_message="A non-standard parent process net.exe spawned child process net1.exe to execute command-line tool on ar-win-dc.attackrange.local.", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="56.0", savedsearch_description="The following analytic identifies a non-standard parent process (not matching CMD, PowerShell, or Explorer) spawning `ipconfig.exe` or `systeminfo.exe`. This particular behavior was seen in FIN7's JSSLoader .NET payload. This is also typically seen when an adversary is injected into another process performing different discovery techniques. This event stands out as a TTP since these tools are commonly executed with a shell application or Explorer parent, and not by another application. This TTP is a good indicator for an adversary gathering host information, but one possible false positive might be an automated tool used by a system administator.", user="Administrator" 1686748442, search_name="ESCU - Cmdline Tool Not Executed In CMD Shell - Rule", analyticstories="CISA AA22-277A", analyticstories="FIN7", analyticstories="Qakbot", annotations="{\"analytic_story\":[\"FIN7\",\"Qakbot\",\"CISA AA22-277A\",\"Qakbot\"],\"cis20\":[\"CIS 10\"],\"confidence\":80,\"impact\":70,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1059\",\"T1059.007\"],\"nist\":[\"DE.CM\"]}", annotations._all="Installation", annotations._all="CISA AA22-277A", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="FIN7", annotations._all="Qakbot", annotations._all="T1059.007", annotations._all="T1059", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="FIN7", annotations.analytic_story="Qakbot", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Qakbot", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1059", annotations.mitre_attack="T1059.007", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:09", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748438.701389000", lastTime="2023-06-14T13:04:09", original_file_name="net1.exe", parent_process="net localgroup Administradores", parent_process_name="net.exe", process="C:\\Windows\\system32\\net1 localgroup Administradores", process_id="6844", process_name="net1.exe", risk_message="A non-standard parent process net.exe spawned child process net1.exe to execute command-line tool on ar-win-dc.attackrange.local.", risk_object="net1.exe", risk_object_type="other", risk_score="56.0", savedsearch_description="The following analytic identifies a non-standard parent process (not matching CMD, PowerShell, or Explorer) spawning `ipconfig.exe` or `systeminfo.exe`. This particular behavior was seen in FIN7's JSSLoader .NET payload. This is also typically seen when an adversary is injected into another process performing different discovery techniques. This event stands out as a TTP since these tools are commonly executed with a shell application or Explorer parent, and not by another application. This TTP is a good indicator for an adversary gathering host information, but one possible false positive might be an automated tool used by a system administator.", user="Administrator" 1686748442, search_name="ESCU - Cmdline Tool Not Executed In CMD Shell - Rule", analyticstories="CISA AA22-277A", analyticstories="FIN7", analyticstories="Qakbot", annotations="{\"analytic_story\":[\"FIN7\",\"Qakbot\",\"CISA AA22-277A\",\"Qakbot\"],\"cis20\":[\"CIS 10\"],\"confidence\":80,\"impact\":70,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1059\",\"T1059.007\"],\"nist\":[\"DE.CM\"]}", annotations._all="Installation", annotations._all="CISA AA22-277A", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="FIN7", annotations._all="Qakbot", annotations._all="T1059.007", annotations._all="T1059", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="FIN7", annotations.analytic_story="Qakbot", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Qakbot", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1059", annotations.mitre_attack="T1059.007", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:09", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748438.701389000", lastTime="2023-06-14T13:04:09", original_file_name="net1.exe", parent_process="net localgroup Administradores", parent_process_name="net.exe", process="C:\\Windows\\system32\\net1 localgroup Administradores", process_id="6844", process_name="net1.exe", risk_message="A non-standard parent process net.exe spawned child process net1.exe to execute command-line tool on ar-win-dc.attackrange.local.", risk_object="net.exe", risk_object_type="other", risk_score="56.0", savedsearch_description="The following analytic identifies a non-standard parent process (not matching CMD, PowerShell, or Explorer) spawning `ipconfig.exe` or `systeminfo.exe`. This particular behavior was seen in FIN7's JSSLoader .NET payload. This is also typically seen when an adversary is injected into another process performing different discovery techniques. This event stands out as a TTP since these tools are commonly executed with a shell application or Explorer parent, and not by another application. This TTP is a good indicator for an adversary gathering host information, but one possible false positive might be an automated tool used by a system administator.", user="Administrator" 1686748442, search_name="ESCU - Cmdline Tool Not Executed In CMD Shell - Rule", analyticstories="CISA AA22-277A", analyticstories="FIN7", analyticstories="Qakbot", annotations="{\"analytic_story\":[\"FIN7\",\"Qakbot\",\"CISA AA22-277A\",\"Qakbot\"],\"cis20\":[\"CIS 10\"],\"confidence\":80,\"impact\":70,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1059\",\"T1059.007\"],\"nist\":[\"DE.CM\"]}", annotations._all="Installation", annotations._all="CISA AA22-277A", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="FIN7", annotations._all="Qakbot", annotations._all="T1059.007", annotations._all="T1059", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="FIN7", annotations.analytic_story="Qakbot", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Qakbot", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1059", annotations.mitre_attack="T1059.007", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:09", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748438.701389000", lastTime="2023-06-14T13:04:09", original_file_name="net1.exe", parent_process="net localgroup Administradores", parent_process_name="net.exe", process="C:\\Windows\\system32\\net1 localgroup Administradores", process_id="6844", process_name="net1.exe", risk_message="A non-standard parent process net.exe spawned child process net1.exe to execute command-line tool on ar-win-dc.attackrange.local.", risk_object="Administrator", risk_object_type="user", risk_score="56.0", savedsearch_description="The following analytic identifies a non-standard parent process (not matching CMD, PowerShell, or Explorer) spawning `ipconfig.exe` or `systeminfo.exe`. This particular behavior was seen in FIN7's JSSLoader .NET payload. This is also typically seen when an adversary is injected into another process performing different discovery techniques. This event stands out as a TTP since these tools are commonly executed with a shell application or Explorer parent, and not by another application. This TTP is a good indicator for an adversary gathering host information, but one possible false positive might be an automated tool used by a system administator.", user="Administrator" 1686748442, search_name="ESCU - Cmdline Tool Not Executed In CMD Shell - Rule", analyticstories="CISA AA22-277A", analyticstories="FIN7", analyticstories="Qakbot", annotations="{\"analytic_story\":[\"FIN7\",\"Qakbot\",\"CISA AA22-277A\",\"Qakbot\"],\"cis20\":[\"CIS 10\"],\"confidence\":80,\"impact\":70,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1059\",\"T1059.007\"],\"nist\":[\"DE.CM\"]}", annotations._all="Installation", annotations._all="CISA AA22-277A", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="FIN7", annotations._all="Qakbot", annotations._all="T1059.007", annotations._all="T1059", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="FIN7", annotations.analytic_story="Qakbot", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Qakbot", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1059", annotations.mitre_attack="T1059.007", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:09", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748438.701389000", lastTime="2023-06-14T13:04:09", original_file_name="net1.exe", parent_process="net localgroup Administradores", parent_process_name="net.exe", process="C:\\Windows\\system32\\net1 localgroup Administradores", process_id="6844", process_name="net1.exe", risk_message="A non-standard parent process net.exe spawned child process net1.exe to execute command-line tool on ar-win-dc.attackrange.local.", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="56.0", savedsearch_description="The following analytic identifies a non-standard parent process (not matching CMD, PowerShell, or Explorer) spawning `ipconfig.exe` or `systeminfo.exe`. This particular behavior was seen in FIN7's JSSLoader .NET payload. This is also typically seen when an adversary is injected into another process performing different discovery techniques. This event stands out as a TTP since these tools are commonly executed with a shell application or Explorer parent, and not by another application. This TTP is a good indicator for an adversary gathering host information, but one possible false positive might be an automated tool used by a system administator.", user="Administrator" 1686748442, search_name="ESCU - Cmdline Tool Not Executed In CMD Shell - Rule", analyticstories="CISA AA22-277A", analyticstories="FIN7", analyticstories="Qakbot", annotations="{\"analytic_story\":[\"FIN7\",\"Qakbot\",\"CISA AA22-277A\",\"Qakbot\"],\"cis20\":[\"CIS 10\"],\"confidence\":80,\"impact\":70,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1059\",\"T1059.007\"],\"nist\":[\"DE.CM\"]}", annotations._all="Installation", annotations._all="CISA AA22-277A", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="FIN7", annotations._all="Qakbot", annotations._all="T1059.007", annotations._all="T1059", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="FIN7", annotations.analytic_story="Qakbot", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Qakbot", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1059", annotations.mitre_attack="T1059.007", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:09", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748438.701389000", lastTime="2023-06-14T13:04:09", original_file_name="net1.exe", parent_process="net localgroup", parent_process_name="net.exe", process="C:\\Windows\\system32\\net1 localgroup", process_id="6984", process_name="net1.exe", risk_message="A non-standard parent process net.exe spawned child process net1.exe to execute command-line tool on ar-win-dc.attackrange.local.", risk_object="net1.exe", risk_object_type="other", risk_score="56.0", savedsearch_description="The following analytic identifies a non-standard parent process (not matching CMD, PowerShell, or Explorer) spawning `ipconfig.exe` or `systeminfo.exe`. This particular behavior was seen in FIN7's JSSLoader .NET payload. This is also typically seen when an adversary is injected into another process performing different discovery techniques. This event stands out as a TTP since these tools are commonly executed with a shell application or Explorer parent, and not by another application. This TTP is a good indicator for an adversary gathering host information, but one possible false positive might be an automated tool used by a system administator.", user="Administrator" 1686748442, search_name="ESCU - Cmdline Tool Not Executed In CMD Shell - Rule", analyticstories="CISA AA22-277A", analyticstories="FIN7", analyticstories="Qakbot", annotations="{\"analytic_story\":[\"FIN7\",\"Qakbot\",\"CISA AA22-277A\",\"Qakbot\"],\"cis20\":[\"CIS 10\"],\"confidence\":80,\"impact\":70,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1059\",\"T1059.007\"],\"nist\":[\"DE.CM\"]}", annotations._all="Installation", annotations._all="CISA AA22-277A", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="FIN7", annotations._all="Qakbot", annotations._all="T1059.007", annotations._all="T1059", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="FIN7", annotations.analytic_story="Qakbot", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Qakbot", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1059", annotations.mitre_attack="T1059.007", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:09", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748438.701389000", lastTime="2023-06-14T13:04:09", original_file_name="net1.exe", parent_process="net localgroup", parent_process_name="net.exe", process="C:\\Windows\\system32\\net1 localgroup", process_id="6984", process_name="net1.exe", risk_message="A non-standard parent process net.exe spawned child process net1.exe to execute command-line tool on ar-win-dc.attackrange.local.", risk_object="net.exe", risk_object_type="other", risk_score="56.0", savedsearch_description="The following analytic identifies a non-standard parent process (not matching CMD, PowerShell, or Explorer) spawning `ipconfig.exe` or `systeminfo.exe`. This particular behavior was seen in FIN7's JSSLoader .NET payload. This is also typically seen when an adversary is injected into another process performing different discovery techniques. This event stands out as a TTP since these tools are commonly executed with a shell application or Explorer parent, and not by another application. This TTP is a good indicator for an adversary gathering host information, but one possible false positive might be an automated tool used by a system administator.", user="Administrator" 1686748442, search_name="ESCU - Cmdline Tool Not Executed In CMD Shell - Rule", analyticstories="CISA AA22-277A", analyticstories="FIN7", analyticstories="Qakbot", annotations="{\"analytic_story\":[\"FIN7\",\"Qakbot\",\"CISA AA22-277A\",\"Qakbot\"],\"cis20\":[\"CIS 10\"],\"confidence\":80,\"impact\":70,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1059\",\"T1059.007\"],\"nist\":[\"DE.CM\"]}", annotations._all="Installation", annotations._all="CISA AA22-277A", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="FIN7", annotations._all="Qakbot", annotations._all="T1059.007", annotations._all="T1059", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="FIN7", annotations.analytic_story="Qakbot", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Qakbot", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1059", annotations.mitre_attack="T1059.007", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:09", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748438.701389000", lastTime="2023-06-14T13:04:09", original_file_name="net1.exe", parent_process="net localgroup", parent_process_name="net.exe", process="C:\\Windows\\system32\\net1 localgroup", process_id="6984", process_name="net1.exe", risk_message="A non-standard parent process net.exe spawned child process net1.exe to execute command-line tool on ar-win-dc.attackrange.local.", risk_object="Administrator", risk_object_type="user", risk_score="56.0", savedsearch_description="The following analytic identifies a non-standard parent process (not matching CMD, PowerShell, or Explorer) spawning `ipconfig.exe` or `systeminfo.exe`. This particular behavior was seen in FIN7's JSSLoader .NET payload. This is also typically seen when an adversary is injected into another process performing different discovery techniques. This event stands out as a TTP since these tools are commonly executed with a shell application or Explorer parent, and not by another application. This TTP is a good indicator for an adversary gathering host information, but one possible false positive might be an automated tool used by a system administator.", user="Administrator" 1686748442, search_name="ESCU - Cmdline Tool Not Executed In CMD Shell - Rule", analyticstories="CISA AA22-277A", analyticstories="FIN7", analyticstories="Qakbot", annotations="{\"analytic_story\":[\"FIN7\",\"Qakbot\",\"CISA AA22-277A\",\"Qakbot\"],\"cis20\":[\"CIS 10\"],\"confidence\":80,\"impact\":70,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1059\",\"T1059.007\"],\"nist\":[\"DE.CM\"]}", annotations._all="Installation", annotations._all="CISA AA22-277A", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="FIN7", annotations._all="Qakbot", annotations._all="T1059.007", annotations._all="T1059", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="FIN7", annotations.analytic_story="Qakbot", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Qakbot", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1059", annotations.mitre_attack="T1059.007", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:09", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748438.701389000", lastTime="2023-06-14T13:04:09", original_file_name="net1.exe", parent_process="net localgroup", parent_process_name="net.exe", process="C:\\Windows\\system32\\net1 localgroup", process_id="6984", process_name="net1.exe", risk_message="A non-standard parent process net.exe spawned child process net1.exe to execute command-line tool on ar-win-dc.attackrange.local.", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="56.0", savedsearch_description="The following analytic identifies a non-standard parent process (not matching CMD, PowerShell, or Explorer) spawning `ipconfig.exe` or `systeminfo.exe`. This particular behavior was seen in FIN7's JSSLoader .NET payload. This is also typically seen when an adversary is injected into another process performing different discovery techniques. This event stands out as a TTP since these tools are commonly executed with a shell application or Explorer parent, and not by another application. This TTP is a good indicator for an adversary gathering host information, but one possible false positive might be an automated tool used by a system administator.", user="Administrator" 1686748442, search_name="ESCU - Cmdline Tool Not Executed In CMD Shell - Rule", analyticstories="CISA AA22-277A", analyticstories="FIN7", analyticstories="Qakbot", annotations="{\"analytic_story\":[\"FIN7\",\"Qakbot\",\"CISA AA22-277A\",\"Qakbot\"],\"cis20\":[\"CIS 10\"],\"confidence\":80,\"impact\":70,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1059\",\"T1059.007\"],\"nist\":[\"DE.CM\"]}", annotations._all="Installation", annotations._all="CISA AA22-277A", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="FIN7", annotations._all="Qakbot", annotations._all="T1059.007", annotations._all="T1059", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="FIN7", annotations.analytic_story="Qakbot", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Qakbot", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1059", annotations.mitre_attack="T1059.007", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:08", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748438.701389000", lastTime="2023-06-14T13:04:08", original_file_name="unknown", parent_process="C:\\Windows\\System32\\net.exe", parent_process_name="net.exe", process="C:\\Windows\\system32\\net1 user", process_id="0xa38", process_name="net1.exe", risk_message="A non-standard parent process net.exe spawned child process net1.exe to execute command-line tool on ar-win-dc.attackrange.local.", risk_object="net1.exe", risk_object_type="other", risk_score="56.0", savedsearch_description="The following analytic identifies a non-standard parent process (not matching CMD, PowerShell, or Explorer) spawning `ipconfig.exe` or `systeminfo.exe`. This particular behavior was seen in FIN7's JSSLoader .NET payload. This is also typically seen when an adversary is injected into another process performing different discovery techniques. This event stands out as a TTP since these tools are commonly executed with a shell application or Explorer parent, and not by another application. This TTP is a good indicator for an adversary gathering host information, but one possible false positive might be an automated tool used by a system administator.", user="Administrator" 1686748442, search_name="ESCU - Cmdline Tool Not Executed In CMD Shell - Rule", analyticstories="CISA AA22-277A", analyticstories="FIN7", analyticstories="Qakbot", annotations="{\"analytic_story\":[\"FIN7\",\"Qakbot\",\"CISA AA22-277A\",\"Qakbot\"],\"cis20\":[\"CIS 10\"],\"confidence\":80,\"impact\":70,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1059\",\"T1059.007\"],\"nist\":[\"DE.CM\"]}", annotations._all="Installation", annotations._all="CISA AA22-277A", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="FIN7", annotations._all="Qakbot", annotations._all="T1059.007", annotations._all="T1059", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="FIN7", annotations.analytic_story="Qakbot", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Qakbot", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1059", annotations.mitre_attack="T1059.007", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:08", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748438.701389000", lastTime="2023-06-14T13:04:08", original_file_name="unknown", parent_process="C:\\Windows\\System32\\net.exe", parent_process_name="net.exe", process="C:\\Windows\\system32\\net1 user", process_id="0xa38", process_name="net1.exe", risk_message="A non-standard parent process net.exe spawned child process net1.exe to execute command-line tool on ar-win-dc.attackrange.local.", risk_object="net.exe", risk_object_type="other", risk_score="56.0", savedsearch_description="The following analytic identifies a non-standard parent process (not matching CMD, PowerShell, or Explorer) spawning `ipconfig.exe` or `systeminfo.exe`. This particular behavior was seen in FIN7's JSSLoader .NET payload. This is also typically seen when an adversary is injected into another process performing different discovery techniques. This event stands out as a TTP since these tools are commonly executed with a shell application or Explorer parent, and not by another application. This TTP is a good indicator for an adversary gathering host information, but one possible false positive might be an automated tool used by a system administator.", user="Administrator" 1686748442, search_name="ESCU - Cmdline Tool Not Executed In CMD Shell - Rule", analyticstories="CISA AA22-277A", analyticstories="FIN7", analyticstories="Qakbot", annotations="{\"analytic_story\":[\"FIN7\",\"Qakbot\",\"CISA AA22-277A\",\"Qakbot\"],\"cis20\":[\"CIS 10\"],\"confidence\":80,\"impact\":70,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1059\",\"T1059.007\"],\"nist\":[\"DE.CM\"]}", annotations._all="Installation", annotations._all="CISA AA22-277A", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="FIN7", annotations._all="Qakbot", annotations._all="T1059.007", annotations._all="T1059", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="FIN7", annotations.analytic_story="Qakbot", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Qakbot", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1059", annotations.mitre_attack="T1059.007", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:08", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748438.701389000", lastTime="2023-06-14T13:04:08", original_file_name="unknown", parent_process="C:\\Windows\\System32\\net.exe", parent_process_name="net.exe", process="C:\\Windows\\system32\\net1 user", process_id="0xa38", process_name="net1.exe", risk_message="A non-standard parent process net.exe spawned child process net1.exe to execute command-line tool on ar-win-dc.attackrange.local.", risk_object="Administrator", risk_object_type="user", risk_score="56.0", savedsearch_description="The following analytic identifies a non-standard parent process (not matching CMD, PowerShell, or Explorer) spawning `ipconfig.exe` or `systeminfo.exe`. This particular behavior was seen in FIN7's JSSLoader .NET payload. This is also typically seen when an adversary is injected into another process performing different discovery techniques. This event stands out as a TTP since these tools are commonly executed with a shell application or Explorer parent, and not by another application. This TTP is a good indicator for an adversary gathering host information, but one possible false positive might be an automated tool used by a system administator.", user="Administrator" 1686748442, search_name="ESCU - Cmdline Tool Not Executed In CMD Shell - Rule", analyticstories="CISA AA22-277A", analyticstories="FIN7", analyticstories="Qakbot", annotations="{\"analytic_story\":[\"FIN7\",\"Qakbot\",\"CISA AA22-277A\",\"Qakbot\"],\"cis20\":[\"CIS 10\"],\"confidence\":80,\"impact\":70,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1059\",\"T1059.007\"],\"nist\":[\"DE.CM\"]}", annotations._all="Installation", annotations._all="CISA AA22-277A", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="FIN7", annotations._all="Qakbot", annotations._all="T1059.007", annotations._all="T1059", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="FIN7", annotations.analytic_story="Qakbot", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Qakbot", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1059", annotations.mitre_attack="T1059.007", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:08", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748438.701389000", lastTime="2023-06-14T13:04:08", original_file_name="unknown", parent_process="C:\\Windows\\System32\\net.exe", parent_process_name="net.exe", process="C:\\Windows\\system32\\net1 user", process_id="0xa38", process_name="net1.exe", risk_message="A non-standard parent process net.exe spawned child process net1.exe to execute command-line tool on ar-win-dc.attackrange.local.", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="56.0", savedsearch_description="The following analytic identifies a non-standard parent process (not matching CMD, PowerShell, or Explorer) spawning `ipconfig.exe` or `systeminfo.exe`. This particular behavior was seen in FIN7's JSSLoader .NET payload. This is also typically seen when an adversary is injected into another process performing different discovery techniques. This event stands out as a TTP since these tools are commonly executed with a shell application or Explorer parent, and not by another application. This TTP is a good indicator for an adversary gathering host information, but one possible false positive might be an automated tool used by a system administator.", user="Administrator" 1686748442, search_name="ESCU - Cmdline Tool Not Executed In CMD Shell - Rule", analyticstories="CISA AA22-277A", analyticstories="FIN7", analyticstories="Qakbot", annotations="{\"analytic_story\":[\"FIN7\",\"Qakbot\",\"CISA AA22-277A\",\"Qakbot\"],\"cis20\":[\"CIS 10\"],\"confidence\":80,\"impact\":70,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1059\",\"T1059.007\"],\"nist\":[\"DE.CM\"]}", annotations._all="Installation", annotations._all="CISA AA22-277A", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="FIN7", annotations._all="Qakbot", annotations._all="T1059.007", annotations._all="T1059", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="FIN7", annotations.analytic_story="Qakbot", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Qakbot", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1059", annotations.mitre_attack="T1059.007", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:09", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748438.701389000", lastTime="2023-06-14T13:04:09", original_file_name="unknown", parent_process="C:\\Windows\\System32\\net.exe", parent_process_name="net.exe", process="C:\\Windows\\system32\\net1 localgroup Administrators", process_id="0x1bc0", process_name="net1.exe", risk_message="A non-standard parent process net.exe spawned child process net1.exe to execute command-line tool on ar-win-dc.attackrange.local.", risk_object="net1.exe", risk_object_type="other", risk_score="56.0", savedsearch_description="The following analytic identifies a non-standard parent process (not matching CMD, PowerShell, or Explorer) spawning `ipconfig.exe` or `systeminfo.exe`. This particular behavior was seen in FIN7's JSSLoader .NET payload. This is also typically seen when an adversary is injected into another process performing different discovery techniques. This event stands out as a TTP since these tools are commonly executed with a shell application or Explorer parent, and not by another application. This TTP is a good indicator for an adversary gathering host information, but one possible false positive might be an automated tool used by a system administator.", user="Administrator" 1686748442, search_name="ESCU - Cmdline Tool Not Executed In CMD Shell - Rule", analyticstories="CISA AA22-277A", analyticstories="FIN7", analyticstories="Qakbot", annotations="{\"analytic_story\":[\"FIN7\",\"Qakbot\",\"CISA AA22-277A\",\"Qakbot\"],\"cis20\":[\"CIS 10\"],\"confidence\":80,\"impact\":70,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1059\",\"T1059.007\"],\"nist\":[\"DE.CM\"]}", annotations._all="Installation", annotations._all="CISA AA22-277A", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="FIN7", annotations._all="Qakbot", annotations._all="T1059.007", annotations._all="T1059", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="FIN7", annotations.analytic_story="Qakbot", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Qakbot", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1059", annotations.mitre_attack="T1059.007", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:09", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748438.701389000", lastTime="2023-06-14T13:04:09", original_file_name="unknown", parent_process="C:\\Windows\\System32\\net.exe", parent_process_name="net.exe", process="C:\\Windows\\system32\\net1 localgroup Administrators", process_id="0x1bc0", process_name="net1.exe", risk_message="A non-standard parent process net.exe spawned child process net1.exe to execute command-line tool on ar-win-dc.attackrange.local.", risk_object="net.exe", risk_object_type="other", risk_score="56.0", savedsearch_description="The following analytic identifies a non-standard parent process (not matching CMD, PowerShell, or Explorer) spawning `ipconfig.exe` or `systeminfo.exe`. This particular behavior was seen in FIN7's JSSLoader .NET payload. This is also typically seen when an adversary is injected into another process performing different discovery techniques. This event stands out as a TTP since these tools are commonly executed with a shell application or Explorer parent, and not by another application. This TTP is a good indicator for an adversary gathering host information, but one possible false positive might be an automated tool used by a system administator.", user="Administrator" 1686748442, search_name="ESCU - Cmdline Tool Not Executed In CMD Shell - Rule", analyticstories="CISA AA22-277A", analyticstories="FIN7", analyticstories="Qakbot", annotations="{\"analytic_story\":[\"FIN7\",\"Qakbot\",\"CISA AA22-277A\",\"Qakbot\"],\"cis20\":[\"CIS 10\"],\"confidence\":80,\"impact\":70,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1059\",\"T1059.007\"],\"nist\":[\"DE.CM\"]}", annotations._all="Installation", annotations._all="CISA AA22-277A", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="FIN7", annotations._all="Qakbot", annotations._all="T1059.007", annotations._all="T1059", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="FIN7", annotations.analytic_story="Qakbot", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Qakbot", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1059", annotations.mitre_attack="T1059.007", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:09", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748438.701389000", lastTime="2023-06-14T13:04:09", original_file_name="unknown", parent_process="C:\\Windows\\System32\\net.exe", parent_process_name="net.exe", process="C:\\Windows\\system32\\net1 localgroup Administrators", process_id="0x1bc0", process_name="net1.exe", risk_message="A non-standard parent process net.exe spawned child process net1.exe to execute command-line tool on ar-win-dc.attackrange.local.", risk_object="Administrator", risk_object_type="user", risk_score="56.0", savedsearch_description="The following analytic identifies a non-standard parent process (not matching CMD, PowerShell, or Explorer) spawning `ipconfig.exe` or `systeminfo.exe`. This particular behavior was seen in FIN7's JSSLoader .NET payload. This is also typically seen when an adversary is injected into another process performing different discovery techniques. This event stands out as a TTP since these tools are commonly executed with a shell application or Explorer parent, and not by another application. This TTP is a good indicator for an adversary gathering host information, but one possible false positive might be an automated tool used by a system administator.", user="Administrator" 1686748442, search_name="ESCU - Cmdline Tool Not Executed In CMD Shell - Rule", analyticstories="CISA AA22-277A", analyticstories="FIN7", analyticstories="Qakbot", annotations="{\"analytic_story\":[\"FIN7\",\"Qakbot\",\"CISA AA22-277A\",\"Qakbot\"],\"cis20\":[\"CIS 10\"],\"confidence\":80,\"impact\":70,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1059\",\"T1059.007\"],\"nist\":[\"DE.CM\"]}", annotations._all="Installation", annotations._all="CISA AA22-277A", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="FIN7", annotations._all="Qakbot", annotations._all="T1059.007", annotations._all="T1059", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="FIN7", annotations.analytic_story="Qakbot", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Qakbot", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1059", annotations.mitre_attack="T1059.007", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:09", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748438.701389000", lastTime="2023-06-14T13:04:09", original_file_name="unknown", parent_process="C:\\Windows\\System32\\net.exe", parent_process_name="net.exe", process="C:\\Windows\\system32\\net1 localgroup Administrators", process_id="0x1bc0", process_name="net1.exe", risk_message="A non-standard parent process net.exe spawned child process net1.exe to execute command-line tool on ar-win-dc.attackrange.local.", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="56.0", savedsearch_description="The following analytic identifies a non-standard parent process (not matching CMD, PowerShell, or Explorer) spawning `ipconfig.exe` or `systeminfo.exe`. This particular behavior was seen in FIN7's JSSLoader .NET payload. This is also typically seen when an adversary is injected into another process performing different discovery techniques. This event stands out as a TTP since these tools are commonly executed with a shell application or Explorer parent, and not by another application. This TTP is a good indicator for an adversary gathering host information, but one possible false positive might be an automated tool used by a system administator.", user="Administrator" 1686748442, search_name="ESCU - Cmdline Tool Not Executed In CMD Shell - Rule", analyticstories="CISA AA22-277A", analyticstories="FIN7", analyticstories="Qakbot", annotations="{\"analytic_story\":[\"FIN7\",\"Qakbot\",\"CISA AA22-277A\",\"Qakbot\"],\"cis20\":[\"CIS 10\"],\"confidence\":80,\"impact\":70,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1059\",\"T1059.007\"],\"nist\":[\"DE.CM\"]}", annotations._all="Installation", annotations._all="CISA AA22-277A", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="FIN7", annotations._all="Qakbot", annotations._all="T1059.007", annotations._all="T1059", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="FIN7", annotations.analytic_story="Qakbot", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Qakbot", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1059", annotations.mitre_attack="T1059.007", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:09", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748438.701389000", lastTime="2023-06-14T13:04:09", original_file_name="unknown", parent_process="C:\\Windows\\System32\\net.exe", parent_process_name="net.exe", process="C:\\Windows\\system32\\net1 localgroup", process_id="0x1b48", process_name="net1.exe", risk_message="A non-standard parent process net.exe spawned child process net1.exe to execute command-line tool on ar-win-dc.attackrange.local.", risk_object="net1.exe", risk_object_type="other", risk_score="56.0", savedsearch_description="The following analytic identifies a non-standard parent process (not matching CMD, PowerShell, or Explorer) spawning `ipconfig.exe` or `systeminfo.exe`. This particular behavior was seen in FIN7's JSSLoader .NET payload. This is also typically seen when an adversary is injected into another process performing different discovery techniques. This event stands out as a TTP since these tools are commonly executed with a shell application or Explorer parent, and not by another application. This TTP is a good indicator for an adversary gathering host information, but one possible false positive might be an automated tool used by a system administator.", user="Administrator" 1686748442, search_name="ESCU - Cmdline Tool Not Executed In CMD Shell - Rule", analyticstories="CISA AA22-277A", analyticstories="FIN7", analyticstories="Qakbot", annotations="{\"analytic_story\":[\"FIN7\",\"Qakbot\",\"CISA AA22-277A\",\"Qakbot\"],\"cis20\":[\"CIS 10\"],\"confidence\":80,\"impact\":70,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1059\",\"T1059.007\"],\"nist\":[\"DE.CM\"]}", annotations._all="Installation", annotations._all="CISA AA22-277A", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="FIN7", annotations._all="Qakbot", annotations._all="T1059.007", annotations._all="T1059", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="FIN7", annotations.analytic_story="Qakbot", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Qakbot", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1059", annotations.mitre_attack="T1059.007", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:09", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748438.701389000", lastTime="2023-06-14T13:04:09", original_file_name="unknown", parent_process="C:\\Windows\\System32\\net.exe", parent_process_name="net.exe", process="C:\\Windows\\system32\\net1 localgroup", process_id="0x1b48", process_name="net1.exe", risk_message="A non-standard parent process net.exe spawned child process net1.exe to execute command-line tool on ar-win-dc.attackrange.local.", risk_object="net.exe", risk_object_type="other", risk_score="56.0", savedsearch_description="The following analytic identifies a non-standard parent process (not matching CMD, PowerShell, or Explorer) spawning `ipconfig.exe` or `systeminfo.exe`. This particular behavior was seen in FIN7's JSSLoader .NET payload. This is also typically seen when an adversary is injected into another process performing different discovery techniques. This event stands out as a TTP since these tools are commonly executed with a shell application or Explorer parent, and not by another application. This TTP is a good indicator for an adversary gathering host information, but one possible false positive might be an automated tool used by a system administator.", user="Administrator" 1686748442, search_name="ESCU - Cmdline Tool Not Executed In CMD Shell - Rule", analyticstories="CISA AA22-277A", analyticstories="FIN7", analyticstories="Qakbot", annotations="{\"analytic_story\":[\"FIN7\",\"Qakbot\",\"CISA AA22-277A\",\"Qakbot\"],\"cis20\":[\"CIS 10\"],\"confidence\":80,\"impact\":70,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1059\",\"T1059.007\"],\"nist\":[\"DE.CM\"]}", annotations._all="Installation", annotations._all="CISA AA22-277A", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="FIN7", annotations._all="Qakbot", annotations._all="T1059.007", annotations._all="T1059", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="FIN7", annotations.analytic_story="Qakbot", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Qakbot", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1059", annotations.mitre_attack="T1059.007", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:09", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748438.701389000", lastTime="2023-06-14T13:04:09", original_file_name="unknown", parent_process="C:\\Windows\\System32\\net.exe", parent_process_name="net.exe", process="C:\\Windows\\system32\\net1 localgroup", process_id="0x1b48", process_name="net1.exe", risk_message="A non-standard parent process net.exe spawned child process net1.exe to execute command-line tool on ar-win-dc.attackrange.local.", risk_object="Administrator", risk_object_type="user", risk_score="56.0", savedsearch_description="The following analytic identifies a non-standard parent process (not matching CMD, PowerShell, or Explorer) spawning `ipconfig.exe` or `systeminfo.exe`. This particular behavior was seen in FIN7's JSSLoader .NET payload. This is also typically seen when an adversary is injected into another process performing different discovery techniques. This event stands out as a TTP since these tools are commonly executed with a shell application or Explorer parent, and not by another application. This TTP is a good indicator for an adversary gathering host information, but one possible false positive might be an automated tool used by a system administator.", user="Administrator" 1686748442, search_name="ESCU - Cmdline Tool Not Executed In CMD Shell - Rule", analyticstories="CISA AA22-277A", analyticstories="FIN7", analyticstories="Qakbot", annotations="{\"analytic_story\":[\"FIN7\",\"Qakbot\",\"CISA AA22-277A\",\"Qakbot\"],\"cis20\":[\"CIS 10\"],\"confidence\":80,\"impact\":70,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1059\",\"T1059.007\"],\"nist\":[\"DE.CM\"]}", annotations._all="Installation", annotations._all="CISA AA22-277A", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="FIN7", annotations._all="Qakbot", annotations._all="T1059.007", annotations._all="T1059", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="FIN7", annotations.analytic_story="Qakbot", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Qakbot", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1059", annotations.mitre_attack="T1059.007", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:09", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748438.701389000", lastTime="2023-06-14T13:04:09", original_file_name="unknown", parent_process="C:\\Windows\\System32\\net.exe", parent_process_name="net.exe", process="C:\\Windows\\system32\\net1 localgroup", process_id="0x1b48", process_name="net1.exe", risk_message="A non-standard parent process net.exe spawned child process net1.exe to execute command-line tool on ar-win-dc.attackrange.local.", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="56.0", savedsearch_description="The following analytic identifies a non-standard parent process (not matching CMD, PowerShell, or Explorer) spawning `ipconfig.exe` or `systeminfo.exe`. This particular behavior was seen in FIN7's JSSLoader .NET payload. This is also typically seen when an adversary is injected into another process performing different discovery techniques. This event stands out as a TTP since these tools are commonly executed with a shell application or Explorer parent, and not by another application. This TTP is a good indicator for an adversary gathering host information, but one possible false positive might be an automated tool used by a system administator.", user="Administrator" 1686748442, search_name="ESCU - Cmdline Tool Not Executed In CMD Shell - Rule", analyticstories="CISA AA22-277A", analyticstories="FIN7", analyticstories="Qakbot", annotations="{\"analytic_story\":[\"FIN7\",\"Qakbot\",\"CISA AA22-277A\",\"Qakbot\"],\"cis20\":[\"CIS 10\"],\"confidence\":80,\"impact\":70,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1059\",\"T1059.007\"],\"nist\":[\"DE.CM\"]}", annotations._all="Installation", annotations._all="CISA AA22-277A", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="FIN7", annotations._all="Qakbot", annotations._all="T1059.007", annotations._all="T1059", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="FIN7", annotations.analytic_story="Qakbot", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Qakbot", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1059", annotations.mitre_attack="T1059.007", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:09", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748438.701389000", lastTime="2023-06-14T13:04:09", original_file_name="unknown", parent_process="C:\\Windows\\System32\\net.exe", parent_process_name="net.exe", process="C:\\Windows\\system32\\net1 localgroup Administradores", process_id="0x1abc", process_name="net1.exe", risk_message="A non-standard parent process net.exe spawned child process net1.exe to execute command-line tool on ar-win-dc.attackrange.local.", risk_object="net1.exe", risk_object_type="other", risk_score="56.0", savedsearch_description="The following analytic identifies a non-standard parent process (not matching CMD, PowerShell, or Explorer) spawning `ipconfig.exe` or `systeminfo.exe`. This particular behavior was seen in FIN7's JSSLoader .NET payload. This is also typically seen when an adversary is injected into another process performing different discovery techniques. This event stands out as a TTP since these tools are commonly executed with a shell application or Explorer parent, and not by another application. This TTP is a good indicator for an adversary gathering host information, but one possible false positive might be an automated tool used by a system administator.", user="Administrator" 1686748442, search_name="ESCU - Cmdline Tool Not Executed In CMD Shell - Rule", analyticstories="CISA AA22-277A", analyticstories="FIN7", analyticstories="Qakbot", annotations="{\"analytic_story\":[\"FIN7\",\"Qakbot\",\"CISA AA22-277A\",\"Qakbot\"],\"cis20\":[\"CIS 10\"],\"confidence\":80,\"impact\":70,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1059\",\"T1059.007\"],\"nist\":[\"DE.CM\"]}", annotations._all="Installation", annotations._all="CISA AA22-277A", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="FIN7", annotations._all="Qakbot", annotations._all="T1059.007", annotations._all="T1059", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="FIN7", annotations.analytic_story="Qakbot", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Qakbot", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1059", annotations.mitre_attack="T1059.007", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:09", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748438.701389000", lastTime="2023-06-14T13:04:09", original_file_name="unknown", parent_process="C:\\Windows\\System32\\net.exe", parent_process_name="net.exe", process="C:\\Windows\\system32\\net1 localgroup Administradores", process_id="0x1abc", process_name="net1.exe", risk_message="A non-standard parent process net.exe spawned child process net1.exe to execute command-line tool on ar-win-dc.attackrange.local.", risk_object="net.exe", risk_object_type="other", risk_score="56.0", savedsearch_description="The following analytic identifies a non-standard parent process (not matching CMD, PowerShell, or Explorer) spawning `ipconfig.exe` or `systeminfo.exe`. This particular behavior was seen in FIN7's JSSLoader .NET payload. This is also typically seen when an adversary is injected into another process performing different discovery techniques. This event stands out as a TTP since these tools are commonly executed with a shell application or Explorer parent, and not by another application. This TTP is a good indicator for an adversary gathering host information, but one possible false positive might be an automated tool used by a system administator.", user="Administrator" 1686748442, search_name="ESCU - Cmdline Tool Not Executed In CMD Shell - Rule", analyticstories="CISA AA22-277A", analyticstories="FIN7", analyticstories="Qakbot", annotations="{\"analytic_story\":[\"FIN7\",\"Qakbot\",\"CISA AA22-277A\",\"Qakbot\"],\"cis20\":[\"CIS 10\"],\"confidence\":80,\"impact\":70,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1059\",\"T1059.007\"],\"nist\":[\"DE.CM\"]}", annotations._all="Installation", annotations._all="CISA AA22-277A", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="FIN7", annotations._all="Qakbot", annotations._all="T1059.007", annotations._all="T1059", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="FIN7", annotations.analytic_story="Qakbot", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Qakbot", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1059", annotations.mitre_attack="T1059.007", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:09", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748438.701389000", lastTime="2023-06-14T13:04:09", original_file_name="unknown", parent_process="C:\\Windows\\System32\\net.exe", parent_process_name="net.exe", process="C:\\Windows\\system32\\net1 localgroup Administradores", process_id="0x1abc", process_name="net1.exe", risk_message="A non-standard parent process net.exe spawned child process net1.exe to execute command-line tool on ar-win-dc.attackrange.local.", risk_object="Administrator", risk_object_type="user", risk_score="56.0", savedsearch_description="The following analytic identifies a non-standard parent process (not matching CMD, PowerShell, or Explorer) spawning `ipconfig.exe` or `systeminfo.exe`. This particular behavior was seen in FIN7's JSSLoader .NET payload. This is also typically seen when an adversary is injected into another process performing different discovery techniques. This event stands out as a TTP since these tools are commonly executed with a shell application or Explorer parent, and not by another application. This TTP is a good indicator for an adversary gathering host information, but one possible false positive might be an automated tool used by a system administator.", user="Administrator" 1686748442, search_name="ESCU - Cmdline Tool Not Executed In CMD Shell - Rule", analyticstories="CISA AA22-277A", analyticstories="FIN7", analyticstories="Qakbot", annotations="{\"analytic_story\":[\"FIN7\",\"Qakbot\",\"CISA AA22-277A\",\"Qakbot\"],\"cis20\":[\"CIS 10\"],\"confidence\":80,\"impact\":70,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1059\",\"T1059.007\"],\"nist\":[\"DE.CM\"]}", annotations._all="Installation", annotations._all="CISA AA22-277A", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="FIN7", annotations._all="Qakbot", annotations._all="T1059.007", annotations._all="T1059", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="FIN7", annotations.analytic_story="Qakbot", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Qakbot", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1059", annotations.mitre_attack="T1059.007", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:09", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748438.701389000", lastTime="2023-06-14T13:04:09", original_file_name="unknown", parent_process="C:\\Windows\\System32\\net.exe", parent_process_name="net.exe", process="C:\\Windows\\system32\\net1 localgroup Administradores", process_id="0x1abc", process_name="net1.exe", risk_message="A non-standard parent process net.exe spawned child process net1.exe to execute command-line tool on ar-win-dc.attackrange.local.", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="56.0", savedsearch_description="The following analytic identifies a non-standard parent process (not matching CMD, PowerShell, or Explorer) spawning `ipconfig.exe` or `systeminfo.exe`. This particular behavior was seen in FIN7's JSSLoader .NET payload. This is also typically seen when an adversary is injected into another process performing different discovery techniques. This event stands out as a TTP since these tools are commonly executed with a shell application or Explorer parent, and not by another application. This TTP is a good indicator for an adversary gathering host information, but one possible false positive might be an automated tool used by a system administator.", user="Administrator" 1686748442, search_name="ESCU - Cmdline Tool Not Executed In CMD Shell - Rule", analyticstories="CISA AA22-277A", analyticstories="FIN7", analyticstories="Qakbot", annotations="{\"analytic_story\":[\"FIN7\",\"Qakbot\",\"CISA AA22-277A\",\"Qakbot\"],\"cis20\":[\"CIS 10\"],\"confidence\":80,\"impact\":70,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1059\",\"T1059.007\"],\"nist\":[\"DE.CM\"]}", annotations._all="Installation", annotations._all="CISA AA22-277A", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="FIN7", annotations._all="Qakbot", annotations._all="T1059.007", annotations._all="T1059", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="FIN7", annotations.analytic_story="Qakbot", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Qakbot", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1059", annotations.mitre_attack="T1059.007", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:06", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748438.701389000", lastTime="2023-06-14T13:04:06", original_file_name="unknown", parent_process="C:\\Windows\\System32\\net.exe", parent_process_name="net.exe", process="C:\\Windows\\system32\\net1 share", process_id="0x1a20", process_name="net1.exe", risk_message="A non-standard parent process net.exe spawned child process net1.exe to execute command-line tool on ar-win-dc.attackrange.local.", risk_object="net1.exe", risk_object_type="other", risk_score="56.0", savedsearch_description="The following analytic identifies a non-standard parent process (not matching CMD, PowerShell, or Explorer) spawning `ipconfig.exe` or `systeminfo.exe`. This particular behavior was seen in FIN7's JSSLoader .NET payload. This is also typically seen when an adversary is injected into another process performing different discovery techniques. This event stands out as a TTP since these tools are commonly executed with a shell application or Explorer parent, and not by another application. This TTP is a good indicator for an adversary gathering host information, but one possible false positive might be an automated tool used by a system administator.", user="Administrator" 1686748442, search_name="ESCU - Cmdline Tool Not Executed In CMD Shell - Rule", analyticstories="CISA AA22-277A", analyticstories="FIN7", analyticstories="Qakbot", annotations="{\"analytic_story\":[\"FIN7\",\"Qakbot\",\"CISA AA22-277A\",\"Qakbot\"],\"cis20\":[\"CIS 10\"],\"confidence\":80,\"impact\":70,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1059\",\"T1059.007\"],\"nist\":[\"DE.CM\"]}", annotations._all="Installation", annotations._all="CISA AA22-277A", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="FIN7", annotations._all="Qakbot", annotations._all="T1059.007", annotations._all="T1059", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="FIN7", annotations.analytic_story="Qakbot", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Qakbot", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1059", annotations.mitre_attack="T1059.007", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:06", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748438.701389000", lastTime="2023-06-14T13:04:06", original_file_name="unknown", parent_process="C:\\Windows\\System32\\net.exe", parent_process_name="net.exe", process="C:\\Windows\\system32\\net1 share", process_id="0x1a20", process_name="net1.exe", risk_message="A non-standard parent process net.exe spawned child process net1.exe to execute command-line tool on ar-win-dc.attackrange.local.", risk_object="net.exe", risk_object_type="other", risk_score="56.0", savedsearch_description="The following analytic identifies a non-standard parent process (not matching CMD, PowerShell, or Explorer) spawning `ipconfig.exe` or `systeminfo.exe`. This particular behavior was seen in FIN7's JSSLoader .NET payload. This is also typically seen when an adversary is injected into another process performing different discovery techniques. This event stands out as a TTP since these tools are commonly executed with a shell application or Explorer parent, and not by another application. This TTP is a good indicator for an adversary gathering host information, but one possible false positive might be an automated tool used by a system administator.", user="Administrator" 1686748442, search_name="ESCU - Cmdline Tool Not Executed In CMD Shell - Rule", analyticstories="CISA AA22-277A", analyticstories="FIN7", analyticstories="Qakbot", annotations="{\"analytic_story\":[\"FIN7\",\"Qakbot\",\"CISA AA22-277A\",\"Qakbot\"],\"cis20\":[\"CIS 10\"],\"confidence\":80,\"impact\":70,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1059\",\"T1059.007\"],\"nist\":[\"DE.CM\"]}", annotations._all="Installation", annotations._all="CISA AA22-277A", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="FIN7", annotations._all="Qakbot", annotations._all="T1059.007", annotations._all="T1059", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="FIN7", annotations.analytic_story="Qakbot", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Qakbot", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1059", annotations.mitre_attack="T1059.007", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:06", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748438.701389000", lastTime="2023-06-14T13:04:06", original_file_name="unknown", parent_process="C:\\Windows\\System32\\net.exe", parent_process_name="net.exe", process="C:\\Windows\\system32\\net1 share", process_id="0x1a20", process_name="net1.exe", risk_message="A non-standard parent process net.exe spawned child process net1.exe to execute command-line tool on ar-win-dc.attackrange.local.", risk_object="Administrator", risk_object_type="user", risk_score="56.0", savedsearch_description="The following analytic identifies a non-standard parent process (not matching CMD, PowerShell, or Explorer) spawning `ipconfig.exe` or `systeminfo.exe`. This particular behavior was seen in FIN7's JSSLoader .NET payload. This is also typically seen when an adversary is injected into another process performing different discovery techniques. This event stands out as a TTP since these tools are commonly executed with a shell application or Explorer parent, and not by another application. This TTP is a good indicator for an adversary gathering host information, but one possible false positive might be an automated tool used by a system administator.", user="Administrator" 1686748442, search_name="ESCU - Cmdline Tool Not Executed In CMD Shell - Rule", analyticstories="CISA AA22-277A", analyticstories="FIN7", analyticstories="Qakbot", annotations="{\"analytic_story\":[\"FIN7\",\"Qakbot\",\"CISA AA22-277A\",\"Qakbot\"],\"cis20\":[\"CIS 10\"],\"confidence\":80,\"impact\":70,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1059\",\"T1059.007\"],\"nist\":[\"DE.CM\"]}", annotations._all="Installation", annotations._all="CISA AA22-277A", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="FIN7", annotations._all="Qakbot", annotations._all="T1059.007", annotations._all="T1059", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="FIN7", annotations.analytic_story="Qakbot", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Qakbot", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1059", annotations.mitre_attack="T1059.007", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:06", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748438.701389000", lastTime="2023-06-14T13:04:06", original_file_name="unknown", parent_process="C:\\Windows\\System32\\net.exe", parent_process_name="net.exe", process="C:\\Windows\\system32\\net1 share", process_id="0x1a20", process_name="net1.exe", risk_message="A non-standard parent process net.exe spawned child process net1.exe to execute command-line tool on ar-win-dc.attackrange.local.", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="56.0", savedsearch_description="The following analytic identifies a non-standard parent process (not matching CMD, PowerShell, or Explorer) spawning `ipconfig.exe` or `systeminfo.exe`. This particular behavior was seen in FIN7's JSSLoader .NET payload. This is also typically seen when an adversary is injected into another process performing different discovery techniques. This event stands out as a TTP since these tools are commonly executed with a shell application or Explorer parent, and not by another application. This TTP is a good indicator for an adversary gathering host information, but one possible false positive might be an automated tool used by a system administator.", user="Administrator" 1686748442, search_name="ESCU - Cmdline Tool Not Executed In CMD Shell - Rule", analyticstories="CISA AA22-277A", analyticstories="FIN7", analyticstories="Qakbot", annotations="{\"analytic_story\":[\"FIN7\",\"Qakbot\",\"CISA AA22-277A\",\"Qakbot\"],\"cis20\":[\"CIS 10\"],\"confidence\":80,\"impact\":70,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1059\",\"T1059.007\"],\"nist\":[\"DE.CM\"]}", annotations._all="Installation", annotations._all="CISA AA22-277A", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="FIN7", annotations._all="Qakbot", annotations._all="T1059.007", annotations._all="T1059", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="FIN7", annotations.analytic_story="Qakbot", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Qakbot", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1059", annotations.mitre_attack="T1059.007", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:08", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748438.701389000", lastTime="2023-06-14T13:04:08", original_file_name="unknown", parent_process="C:\\Windows\\System32\\net.exe", parent_process_name="net.exe", process="C:\\Windows\\system32\\net1 user Administrator", process_id="0x17c8", process_name="net1.exe", risk_message="A non-standard parent process net.exe spawned child process net1.exe to execute command-line tool on ar-win-dc.attackrange.local.", risk_object="net1.exe", risk_object_type="other", risk_score="56.0", savedsearch_description="The following analytic identifies a non-standard parent process (not matching CMD, PowerShell, or Explorer) spawning `ipconfig.exe` or `systeminfo.exe`. This particular behavior was seen in FIN7's JSSLoader .NET payload. This is also typically seen when an adversary is injected into another process performing different discovery techniques. This event stands out as a TTP since these tools are commonly executed with a shell application or Explorer parent, and not by another application. This TTP is a good indicator for an adversary gathering host information, but one possible false positive might be an automated tool used by a system administator.", user="Administrator" 1686748442, search_name="ESCU - Cmdline Tool Not Executed In CMD Shell - Rule", analyticstories="CISA AA22-277A", analyticstories="FIN7", analyticstories="Qakbot", annotations="{\"analytic_story\":[\"FIN7\",\"Qakbot\",\"CISA AA22-277A\",\"Qakbot\"],\"cis20\":[\"CIS 10\"],\"confidence\":80,\"impact\":70,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1059\",\"T1059.007\"],\"nist\":[\"DE.CM\"]}", annotations._all="Installation", annotations._all="CISA AA22-277A", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="FIN7", annotations._all="Qakbot", annotations._all="T1059.007", annotations._all="T1059", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="FIN7", annotations.analytic_story="Qakbot", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Qakbot", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1059", annotations.mitre_attack="T1059.007", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:08", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748438.701389000", lastTime="2023-06-14T13:04:08", original_file_name="unknown", parent_process="C:\\Windows\\System32\\net.exe", parent_process_name="net.exe", process="C:\\Windows\\system32\\net1 user Administrator", process_id="0x17c8", process_name="net1.exe", risk_message="A non-standard parent process net.exe spawned child process net1.exe to execute command-line tool on ar-win-dc.attackrange.local.", risk_object="net.exe", risk_object_type="other", risk_score="56.0", savedsearch_description="The following analytic identifies a non-standard parent process (not matching CMD, PowerShell, or Explorer) spawning `ipconfig.exe` or `systeminfo.exe`. This particular behavior was seen in FIN7's JSSLoader .NET payload. This is also typically seen when an adversary is injected into another process performing different discovery techniques. This event stands out as a TTP since these tools are commonly executed with a shell application or Explorer parent, and not by another application. This TTP is a good indicator for an adversary gathering host information, but one possible false positive might be an automated tool used by a system administator.", user="Administrator" 1686748442, search_name="ESCU - Cmdline Tool Not Executed In CMD Shell - Rule", analyticstories="CISA AA22-277A", analyticstories="FIN7", analyticstories="Qakbot", annotations="{\"analytic_story\":[\"FIN7\",\"Qakbot\",\"CISA AA22-277A\",\"Qakbot\"],\"cis20\":[\"CIS 10\"],\"confidence\":80,\"impact\":70,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1059\",\"T1059.007\"],\"nist\":[\"DE.CM\"]}", annotations._all="Installation", annotations._all="CISA AA22-277A", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="FIN7", annotations._all="Qakbot", annotations._all="T1059.007", annotations._all="T1059", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="FIN7", annotations.analytic_story="Qakbot", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Qakbot", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1059", annotations.mitre_attack="T1059.007", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:08", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748438.701389000", lastTime="2023-06-14T13:04:08", original_file_name="unknown", parent_process="C:\\Windows\\System32\\net.exe", parent_process_name="net.exe", process="C:\\Windows\\system32\\net1 user Administrator", process_id="0x17c8", process_name="net1.exe", risk_message="A non-standard parent process net.exe spawned child process net1.exe to execute command-line tool on ar-win-dc.attackrange.local.", risk_object="Administrator", risk_object_type="user", risk_score="56.0", savedsearch_description="The following analytic identifies a non-standard parent process (not matching CMD, PowerShell, or Explorer) spawning `ipconfig.exe` or `systeminfo.exe`. This particular behavior was seen in FIN7's JSSLoader .NET payload. This is also typically seen when an adversary is injected into another process performing different discovery techniques. This event stands out as a TTP since these tools are commonly executed with a shell application or Explorer parent, and not by another application. This TTP is a good indicator for an adversary gathering host information, but one possible false positive might be an automated tool used by a system administator.", user="Administrator" 1686748442, search_name="ESCU - Cmdline Tool Not Executed In CMD Shell - Rule", analyticstories="CISA AA22-277A", analyticstories="FIN7", analyticstories="Qakbot", annotations="{\"analytic_story\":[\"FIN7\",\"Qakbot\",\"CISA AA22-277A\",\"Qakbot\"],\"cis20\":[\"CIS 10\"],\"confidence\":80,\"impact\":70,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1059\",\"T1059.007\"],\"nist\":[\"DE.CM\"]}", annotations._all="Installation", annotations._all="CISA AA22-277A", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="FIN7", annotations._all="Qakbot", annotations._all="T1059.007", annotations._all="T1059", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="FIN7", annotations.analytic_story="Qakbot", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Qakbot", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1059", annotations.mitre_attack="T1059.007", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:08", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748438.701389000", lastTime="2023-06-14T13:04:08", original_file_name="unknown", parent_process="C:\\Windows\\System32\\net.exe", parent_process_name="net.exe", process="C:\\Windows\\system32\\net1 user Administrator", process_id="0x17c8", process_name="net1.exe", risk_message="A non-standard parent process net.exe spawned child process net1.exe to execute command-line tool on ar-win-dc.attackrange.local.", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="56.0", savedsearch_description="The following analytic identifies a non-standard parent process (not matching CMD, PowerShell, or Explorer) spawning `ipconfig.exe` or `systeminfo.exe`. This particular behavior was seen in FIN7's JSSLoader .NET payload. This is also typically seen when an adversary is injected into another process performing different discovery techniques. This event stands out as a TTP since these tools are commonly executed with a shell application or Explorer parent, and not by another application. This TTP is a good indicator for an adversary gathering host information, but one possible false positive might be an automated tool used by a system administator.", user="Administrator" 1686748442, search_name="ESCU - Cmdline Tool Not Executed In CMD Shell - Rule", analyticstories="CISA AA22-277A", analyticstories="FIN7", analyticstories="Qakbot", annotations="{\"analytic_story\":[\"FIN7\",\"Qakbot\",\"CISA AA22-277A\",\"Qakbot\"],\"cis20\":[\"CIS 10\"],\"confidence\":80,\"impact\":70,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1059\",\"T1059.007\"],\"nist\":[\"DE.CM\"]}", annotations._all="Installation", annotations._all="CISA AA22-277A", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="FIN7", annotations._all="Qakbot", annotations._all="T1059.007", annotations._all="T1059", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="FIN7", annotations.analytic_story="Qakbot", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Qakbot", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1059", annotations.mitre_attack="T1059.007", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:08", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748438.701389000", lastTime="2023-06-14T13:04:08", original_file_name="unknown", parent_process="C:\\Windows\\System32\\net.exe", parent_process_name="net.exe", process="C:\\Windows\\system32\\net1 user Administrator /domain", process_id="0x162c", process_name="net1.exe", risk_message="A non-standard parent process net.exe spawned child process net1.exe to execute command-line tool on ar-win-dc.attackrange.local.", risk_object="net1.exe", risk_object_type="other", risk_score="56.0", savedsearch_description="The following analytic identifies a non-standard parent process (not matching CMD, PowerShell, or Explorer) spawning `ipconfig.exe` or `systeminfo.exe`. This particular behavior was seen in FIN7's JSSLoader .NET payload. This is also typically seen when an adversary is injected into another process performing different discovery techniques. This event stands out as a TTP since these tools are commonly executed with a shell application or Explorer parent, and not by another application. This TTP is a good indicator for an adversary gathering host information, but one possible false positive might be an automated tool used by a system administator.", user="Administrator" 1686748442, search_name="ESCU - Cmdline Tool Not Executed In CMD Shell - Rule", analyticstories="CISA AA22-277A", analyticstories="FIN7", analyticstories="Qakbot", annotations="{\"analytic_story\":[\"FIN7\",\"Qakbot\",\"CISA AA22-277A\",\"Qakbot\"],\"cis20\":[\"CIS 10\"],\"confidence\":80,\"impact\":70,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1059\",\"T1059.007\"],\"nist\":[\"DE.CM\"]}", annotations._all="Installation", annotations._all="CISA AA22-277A", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="FIN7", annotations._all="Qakbot", annotations._all="T1059.007", annotations._all="T1059", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="FIN7", annotations.analytic_story="Qakbot", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Qakbot", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1059", annotations.mitre_attack="T1059.007", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:08", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748438.701389000", lastTime="2023-06-14T13:04:08", original_file_name="unknown", parent_process="C:\\Windows\\System32\\net.exe", parent_process_name="net.exe", process="C:\\Windows\\system32\\net1 user Administrator /domain", process_id="0x162c", process_name="net1.exe", risk_message="A non-standard parent process net.exe spawned child process net1.exe to execute command-line tool on ar-win-dc.attackrange.local.", risk_object="net.exe", risk_object_type="other", risk_score="56.0", savedsearch_description="The following analytic identifies a non-standard parent process (not matching CMD, PowerShell, or Explorer) spawning `ipconfig.exe` or `systeminfo.exe`. This particular behavior was seen in FIN7's JSSLoader .NET payload. This is also typically seen when an adversary is injected into another process performing different discovery techniques. This event stands out as a TTP since these tools are commonly executed with a shell application or Explorer parent, and not by another application. This TTP is a good indicator for an adversary gathering host information, but one possible false positive might be an automated tool used by a system administator.", user="Administrator" 1686748442, search_name="ESCU - Cmdline Tool Not Executed In CMD Shell - Rule", analyticstories="CISA AA22-277A", analyticstories="FIN7", analyticstories="Qakbot", annotations="{\"analytic_story\":[\"FIN7\",\"Qakbot\",\"CISA AA22-277A\",\"Qakbot\"],\"cis20\":[\"CIS 10\"],\"confidence\":80,\"impact\":70,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1059\",\"T1059.007\"],\"nist\":[\"DE.CM\"]}", annotations._all="Installation", annotations._all="CISA AA22-277A", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="FIN7", annotations._all="Qakbot", annotations._all="T1059.007", annotations._all="T1059", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="FIN7", annotations.analytic_story="Qakbot", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Qakbot", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1059", annotations.mitre_attack="T1059.007", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:08", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748438.701389000", lastTime="2023-06-14T13:04:08", original_file_name="unknown", parent_process="C:\\Windows\\System32\\net.exe", parent_process_name="net.exe", process="C:\\Windows\\system32\\net1 user Administrator /domain", process_id="0x162c", process_name="net1.exe", risk_message="A non-standard parent process net.exe spawned child process net1.exe to execute command-line tool on ar-win-dc.attackrange.local.", risk_object="Administrator", risk_object_type="user", risk_score="56.0", savedsearch_description="The following analytic identifies a non-standard parent process (not matching CMD, PowerShell, or Explorer) spawning `ipconfig.exe` or `systeminfo.exe`. This particular behavior was seen in FIN7's JSSLoader .NET payload. This is also typically seen when an adversary is injected into another process performing different discovery techniques. This event stands out as a TTP since these tools are commonly executed with a shell application or Explorer parent, and not by another application. This TTP is a good indicator for an adversary gathering host information, but one possible false positive might be an automated tool used by a system administator.", user="Administrator" 1686748442, search_name="ESCU - Cmdline Tool Not Executed In CMD Shell - Rule", analyticstories="CISA AA22-277A", analyticstories="FIN7", analyticstories="Qakbot", annotations="{\"analytic_story\":[\"FIN7\",\"Qakbot\",\"CISA AA22-277A\",\"Qakbot\"],\"cis20\":[\"CIS 10\"],\"confidence\":80,\"impact\":70,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1059\",\"T1059.007\"],\"nist\":[\"DE.CM\"]}", annotations._all="Installation", annotations._all="CISA AA22-277A", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="FIN7", annotations._all="Qakbot", annotations._all="T1059.007", annotations._all="T1059", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="FIN7", annotations.analytic_story="Qakbot", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Qakbot", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1059", annotations.mitre_attack="T1059.007", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:08", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748438.701389000", lastTime="2023-06-14T13:04:08", original_file_name="unknown", parent_process="C:\\Windows\\System32\\net.exe", parent_process_name="net.exe", process="C:\\Windows\\system32\\net1 user Administrator /domain", process_id="0x162c", process_name="net1.exe", risk_message="A non-standard parent process net.exe spawned child process net1.exe to execute command-line tool on ar-win-dc.attackrange.local.", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="56.0", savedsearch_description="The following analytic identifies a non-standard parent process (not matching CMD, PowerShell, or Explorer) spawning `ipconfig.exe` or `systeminfo.exe`. This particular behavior was seen in FIN7's JSSLoader .NET payload. This is also typically seen when an adversary is injected into another process performing different discovery techniques. This event stands out as a TTP since these tools are commonly executed with a shell application or Explorer parent, and not by another application. This TTP is a good indicator for an adversary gathering host information, but one possible false positive might be an automated tool used by a system administator.", user="Administrator" 1686748433, search_name="ESCU - Windows ClipBoard Data via Get-ClipBoard - Rule", Computer="ar-win-dc.attackrange.local", EventCode="4104", ScriptBlockText="Get-Clipboard", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1115\"],\"nist\":[\"DE.AE\"]}", annotations._all="DE.AE", annotations._all="Prestige Ransomware", annotations._all="T1115", annotations._all="CIS 10", annotations._all="Exploitation", annotations._all="Windows Post-Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1115", annotations.nist="DE.AE", count="1", firstTime="2023-06-14T13:04:10", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748430.194970000", lastTime="2023-06-14T13:04:10", risk_message="powershell script Get-Clipboard execute Get-Clipboard commandlet in $dest$", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="25.0", savedsearch_description="The following analytic identifies a powershell script command to retrieve clipboard data. This technique was seen in several post exploitation tools like WINPEAS to steal sensitive information that was saved in clipboard. Using the Get-Clipboard powershell commandlet, adversaries can be able collect data stored in clipboard that might be a copied user name, password or other sensitive information.", user_id="'S-1-5-21-647039874-1738661239-2692048096-500'" 1686748427, search_name="ESCU - Windows Private Keys Discovery - Rule", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1552.004\",\"T1552\"],\"nist\":[\"DE.AE\"]}", annotations._all="T1552", annotations._all="DE.AE", annotations._all="Windows Post-Exploitation", annotations._all="Prestige Ransomware", annotations._all="T1552.004", annotations._all="CIS 10", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1552.004", annotations.mitre_attack="T1552", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:36", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748419.835360000", lastTime="2023-06-14T13:04:36", original_file_name="unknown", parent_process="C:\\Windows\\System32\\cmd.exe", parent_process_guid="null", parent_process_name="cmd.exe", process="C:\\Windows\\system32\\cmd.exe /S /D /c\" dir /s/b /A:-D RDCMan.settings == *.rdg == SCClient.exe == *_history == .sudo_as_admin_successful == .profile == *bashrc == httpd.conf == *.plan == .htpasswd == .git-credentials == *.rhosts == hosts.equiv == Dockerfile == docker-compose.yml == appcmd.exe == TypedURLs == TypedURLsTime == History == Bookmarks == Cookies == \"Login Data\" == places.sqlite == key3.db == key4.db == credentials == credentials.db == access_tokens.db == accessTokens.json == legacy_credentials == azureProfile.json == unattend.txt == access.log == error.log == *.gpg == *.pgp == *config*.php == elasticsearch.y*ml == kibana.y*ml == *.p12 == *.der == *.csr == *.cer == known_hosts == id_rsa == id_dsa == *.ovpn == anaconda-ks.cfg == hostapd.conf == rsyncd.conf == cesi.conf == supervisord.conf == tomcat-users.xml == *.kdbx == KeePass.config == Ntds.dit == SAM == SYSTEM == FreeSSHDservice.ini == sysprep.inf == sysprep.xml == unattend.xml == unattended.xml == *vnc*.ini == *vnc*.c*nf* == *vnc*.txt == *vnc*.xml == groups.xml == services.xml == scheduledtasks.xml == printers.xml == drives.xml == datasources.xml == php.ini == https.conf == https-xampp.conf == httpd.conf == my.ini == my.cnf == access.log == error.log == server.xml == SiteList.xml == ConsoleHost_history.txt == setupinfo == setupinfo.bak 2>nul\"", process_guid="null", process_id="0xfc0", process_name="cmd.exe", risk_message="a process with commandline C:\\Windows\\system32\\cmd.exe /S /D /c\" dir /s/b /A:-D RDCMan.settings == *.rdg == SCClient.exe == *_history == .sudo_as_admin_successful == .profile == *bashrc == httpd.conf == *.plan == .htpasswd == .git-credentials == *.rhosts == hosts.equiv == Dockerfile == docker-compose.yml == appcmd.exe == TypedURLs == TypedURLsTime == History == Bookmarks == Cookies == \"Login Data\" == places.sqlite == key3.db == key4.db == credentials == credentials.db == access_tokens.db == accessTokens.json == legacy_credentials == azureProfile.json == unattend.txt == access.log == error.log == *.gpg == *.pgp == *config*.php == elasticsearch.y*ml == kibana.y*ml == *.p12 == *.der == *.csr == *.cer == known_hosts == id_rsa == id_dsa == *.ovpn == anaconda-ks.cfg == hostapd.conf == rsyncd.conf == cesi.conf == supervisord.conf == tomcat-users.xml == *.kdbx == KeePass.config == Ntds.dit == SAM == SYSTEM == FreeSSHDservice.ini == sysprep.inf == sysprep.xml == unattend.xml == unattended.xml == *vnc*.ini == *vnc*.c*nf* == *vnc*.txt == *vnc*.xml == groups.xml == services.xml == scheduledtasks.xml == printers.xml == drives.xml == datasources.xml == php.ini == https.conf == https-xampp.conf == httpd.conf == my.ini == my.cnf == access.log == error.log == server.xml == SiteList.xml == ConsoleHost_history.txt == setupinfo == setupinfo.bak 2>nul\" that can retrieve information related to private keys in ar-win-dc.attackrange.local", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="25.0", savedsearch_description="The following analytic identifies a process command line that retrieves information related to private keys files. This technique was seen in several post exploitation tools like winpeas that are being used by Ransomware Prestige to search for private key certificates on the compromised host for insecurely stored credentials. This files can be used by adversaries to gain privileges, persistence or remote service authentication to collect more sensitive information. Some private keys required password for operation, so in this case adversaries may need to have that passphrase either via keylogging or brute force attack.", user="Administrator" 1686748427, search_name="ESCU - Windows Private Keys Discovery - Rule", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1552.004\",\"T1552\"],\"nist\":[\"DE.AE\"]}", annotations._all="T1552", annotations._all="DE.AE", annotations._all="Windows Post-Exploitation", annotations._all="Prestige Ransomware", annotations._all="T1552.004", annotations._all="CIS 10", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1552.004", annotations.mitre_attack="T1552", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:36", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748419.835360000", lastTime="2023-06-14T13:04:36", original_file_name="Cmd.Exe", parent_process="\"cmd.exe\" /s /k pushd \"C:\\Temp\"", parent_process_guid="{953948C6-BA8E-6489-C200-00000000F902}", parent_process_name="cmd.exe", process="C:\\Windows\\system32\\cmd.exe /S /D /c\" dir /s/b /A:-D RDCMan.settings == *.rdg == SCClient.exe == *_history == .sudo_as_admin_successful == .profile == *bashrc == httpd.conf == *.plan == .htpasswd == .git-credentials == *.rhosts == hosts.equiv == Dockerfile == docker-compose.yml == appcmd.exe == TypedURLs == TypedURLsTime == History == Bookmarks == Cookies == \"Login Data\" == places.sqlite == key3.db == key4.db == credentials == credentials.db == access_tokens.db == accessTokens.json == legacy_credentials == azureProfile.json == unattend.txt == access.log == error.log == *.gpg == *.pgp == *config*.php == elasticsearch.y*ml == kibana.y*ml == *.p12 == *.der == *.csr == *.cer == known_hosts == id_rsa == id_dsa == *.ovpn == anaconda-ks.cfg == hostapd.conf == rsyncd.conf == cesi.conf == supervisord.conf == tomcat-users.xml == *.kdbx == KeePass.config == Ntds.dit == SAM == SYSTEM == FreeSSHDservice.ini == sysprep.inf == sysprep.xml == unattend.xml == unattended.xml == *vnc*.ini == *vnc*.c*nf* == *vnc*.txt == *vnc*.xml == groups.xml == services.xml == scheduledtasks.xml == printers.xml == drives.xml == datasources.xml == php.ini == https.conf == https-xampp.conf == httpd.conf == my.ini == my.cnf == access.log == error.log == server.xml == SiteList.xml == ConsoleHost_history.txt == setupinfo == setupinfo.bak 2>nul\"", process_guid="{953948C6-BAE4-6489-7E0C-00000000F902}", process_id="4032", process_name="cmd.exe", risk_message="a process with commandline C:\\Windows\\system32\\cmd.exe /S /D /c\" dir /s/b /A:-D RDCMan.settings == *.rdg == SCClient.exe == *_history == .sudo_as_admin_successful == .profile == *bashrc == httpd.conf == *.plan == .htpasswd == .git-credentials == *.rhosts == hosts.equiv == Dockerfile == docker-compose.yml == appcmd.exe == TypedURLs == TypedURLsTime == History == Bookmarks == Cookies == \"Login Data\" == places.sqlite == key3.db == key4.db == credentials == credentials.db == access_tokens.db == accessTokens.json == legacy_credentials == azureProfile.json == unattend.txt == access.log == error.log == *.gpg == *.pgp == *config*.php == elasticsearch.y*ml == kibana.y*ml == *.p12 == *.der == *.csr == *.cer == known_hosts == id_rsa == id_dsa == *.ovpn == anaconda-ks.cfg == hostapd.conf == rsyncd.conf == cesi.conf == supervisord.conf == tomcat-users.xml == *.kdbx == KeePass.config == Ntds.dit == SAM == SYSTEM == FreeSSHDservice.ini == sysprep.inf == sysprep.xml == unattend.xml == unattended.xml == *vnc*.ini == *vnc*.c*nf* == *vnc*.txt == *vnc*.xml == groups.xml == services.xml == scheduledtasks.xml == printers.xml == drives.xml == datasources.xml == php.ini == https.conf == https-xampp.conf == httpd.conf == my.ini == my.cnf == access.log == error.log == server.xml == SiteList.xml == ConsoleHost_history.txt == setupinfo == setupinfo.bak 2>nul\" that can retrieve information related to private keys in ar-win-dc.attackrange.local", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="25.0", savedsearch_description="The following analytic identifies a process command line that retrieves information related to private keys files. This technique was seen in several post exploitation tools like winpeas that are being used by Ransomware Prestige to search for private key certificates on the compromised host for insecurely stored credentials. This files can be used by adversaries to gain privileges, persistence or remote service authentication to collect more sensitive information. Some private keys required password for operation, so in this case adversaries may need to have that passphrase either via keylogging or brute force attack.", user="Administrator" 1686748406, search_name="ESCU - Windows Security Support Provider Reg Query - Rule", analyticstories="Prestige Ransomware", analyticstories="Sneaky Active Directory Persistence Tricks", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\",\"Sneaky Active Directory Persistence Tricks\"],\"cis20\":[\"CIS 10\"],\"confidence\":30,\"impact\":30,\"kill_chain_phases\":[\"Installation\",\"Exploitation\"],\"mitre_attack\":[\"T1547.005\",\"T1547\"],\"nist\":[\"DE.AE\"]}", annotations._all="DE.AE", annotations._all="T1547", annotations._all="Prestige Ransomware", annotations._all="Windows Post-Exploitation", annotations._all="Installation", annotations._all="CIS 10", annotations._all="T1547.005", annotations._all="Exploitation", annotations._all="Sneaky Active Directory Persistence Tricks", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.analytic_story="Sneaky Active Directory Persistence Tricks", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1547.005", annotations.mitre_attack="T1547", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:01", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748400.226778000", lastTime="2023-06-14T13:04:01", original_file_name="unknown", parent_process="C:\\Windows\\System32\\cmd.exe", parent_process_guid="null", parent_process_name="cmd.exe", process="C:\\Windows\\System32\\reg.exe QUERY \"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\LSA\" /v RunAsPPL", process_guid="null", process_id="0x146c", process_name="reg.exe", risk_message="process with reg query command line C:\\Windows\\System32\\reg.exe QUERY \"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\LSA\" /v RunAsPPL in ar-win-dc.attackrange.local", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="9.0", savedsearch_description="The following analytic identifies a process command line related to the discovery of possible Security Support Providers in the registry. This technique is being abused by adversaries or post exploitation tools like winpeas to gather LSA protection and configuration in the registry in the targeted host. This registry entry can contain several information related to LSA that validates users for local and remote sign-ins and enforces local security policies. Understanding LSA protection may give a good information in accessing LSA content in memory which is commonly attack by adversaries and tool like mimikatz to scrape password hashes or clear plain text passwords.", user="Administrator" 1686748406, search_name="ESCU - Windows Security Support Provider Reg Query - Rule", analyticstories="Prestige Ransomware", analyticstories="Sneaky Active Directory Persistence Tricks", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\",\"Sneaky Active Directory Persistence Tricks\"],\"cis20\":[\"CIS 10\"],\"confidence\":30,\"impact\":30,\"kill_chain_phases\":[\"Installation\",\"Exploitation\"],\"mitre_attack\":[\"T1547.005\",\"T1547\"],\"nist\":[\"DE.AE\"]}", annotations._all="DE.AE", annotations._all="T1547", annotations._all="Prestige Ransomware", annotations._all="Windows Post-Exploitation", annotations._all="Installation", annotations._all="CIS 10", annotations._all="T1547.005", annotations._all="Exploitation", annotations._all="Sneaky Active Directory Persistence Tricks", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.analytic_story="Sneaky Active Directory Persistence Tricks", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1547.005", annotations.mitre_attack="T1547", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:01", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748400.226778000", lastTime="2023-06-14T13:04:01", original_file_name="unknown", parent_process="C:\\Windows\\System32\\cmd.exe", parent_process_guid="null", parent_process_name="cmd.exe", process="C:\\Windows\\System32\\reg.exe QUERY \"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\LSA\" /v LsaCfgFlags", process_guid="null", process_id="0x854", process_name="reg.exe", risk_message="process with reg query command line C:\\Windows\\System32\\reg.exe QUERY \"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\LSA\" /v LsaCfgFlags in ar-win-dc.attackrange.local", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="9.0", savedsearch_description="The following analytic identifies a process command line related to the discovery of possible Security Support Providers in the registry. This technique is being abused by adversaries or post exploitation tools like winpeas to gather LSA protection and configuration in the registry in the targeted host. This registry entry can contain several information related to LSA that validates users for local and remote sign-ins and enforces local security policies. Understanding LSA protection may give a good information in accessing LSA content in memory which is commonly attack by adversaries and tool like mimikatz to scrape password hashes or clear plain text passwords.", user="Administrator" 1686748406, search_name="ESCU - Windows Security Support Provider Reg Query - Rule", analyticstories="Prestige Ransomware", analyticstories="Sneaky Active Directory Persistence Tricks", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\",\"Sneaky Active Directory Persistence Tricks\"],\"cis20\":[\"CIS 10\"],\"confidence\":30,\"impact\":30,\"kill_chain_phases\":[\"Installation\",\"Exploitation\"],\"mitre_attack\":[\"T1547.005\",\"T1547\"],\"nist\":[\"DE.AE\"]}", annotations._all="DE.AE", annotations._all="T1547", annotations._all="Prestige Ransomware", annotations._all="Windows Post-Exploitation", annotations._all="Installation", annotations._all="CIS 10", annotations._all="T1547.005", annotations._all="Exploitation", annotations._all="Sneaky Active Directory Persistence Tricks", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.analytic_story="Sneaky Active Directory Persistence Tricks", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1547.005", annotations.mitre_attack="T1547", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:01", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748400.226778000", lastTime="2023-06-14T13:04:01", original_file_name="reg.exe", parent_process="\"cmd.exe\" /s /k pushd \"C:\\Temp\"", parent_process_guid="{953948C6-BA8E-6489-C200-00000000F902}", parent_process_name="cmd.exe", process="REG QUERY \"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\LSA\" /v RunAsPPL", process_guid="{953948C6-BAC1-6489-DA01-00000000F902}", process_id="5228", process_name="reg.exe", risk_message="process with reg query command line REG QUERY \"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\LSA\" /v RunAsPPL in ar-win-dc.attackrange.local", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="9.0", savedsearch_description="The following analytic identifies a process command line related to the discovery of possible Security Support Providers in the registry. This technique is being abused by adversaries or post exploitation tools like winpeas to gather LSA protection and configuration in the registry in the targeted host. This registry entry can contain several information related to LSA that validates users for local and remote sign-ins and enforces local security policies. Understanding LSA protection may give a good information in accessing LSA content in memory which is commonly attack by adversaries and tool like mimikatz to scrape password hashes or clear plain text passwords.", user="Administrator" 1686748406, search_name="ESCU - Windows Security Support Provider Reg Query - Rule", analyticstories="Prestige Ransomware", analyticstories="Sneaky Active Directory Persistence Tricks", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\",\"Sneaky Active Directory Persistence Tricks\"],\"cis20\":[\"CIS 10\"],\"confidence\":30,\"impact\":30,\"kill_chain_phases\":[\"Installation\",\"Exploitation\"],\"mitre_attack\":[\"T1547.005\",\"T1547\"],\"nist\":[\"DE.AE\"]}", annotations._all="DE.AE", annotations._all="T1547", annotations._all="Prestige Ransomware", annotations._all="Windows Post-Exploitation", annotations._all="Installation", annotations._all="CIS 10", annotations._all="T1547.005", annotations._all="Exploitation", annotations._all="Sneaky Active Directory Persistence Tricks", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.analytic_story="Sneaky Active Directory Persistence Tricks", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1547.005", annotations.mitre_attack="T1547", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:01", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748400.226778000", lastTime="2023-06-14T13:04:01", original_file_name="reg.exe", parent_process="\"cmd.exe\" /s /k pushd \"C:\\Temp\"", parent_process_guid="{953948C6-BA8E-6489-C200-00000000F902}", parent_process_name="cmd.exe", process="REG QUERY \"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\LSA\" /v LsaCfgFlags", process_guid="{953948C6-BAC1-6489-DE01-00000000F902}", process_id="2132", process_name="reg.exe", risk_message="process with reg query command line REG QUERY \"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\LSA\" /v LsaCfgFlags in ar-win-dc.attackrange.local", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="9.0", savedsearch_description="The following analytic identifies a process command line related to the discovery of possible Security Support Providers in the registry. This technique is being abused by adversaries or post exploitation tools like winpeas to gather LSA protection and configuration in the registry in the targeted host. This registry entry can contain several information related to LSA that validates users for local and remote sign-ins and enforces local security policies. Understanding LSA protection may give a good information in accessing LSA content in memory which is commonly attack by adversaries and tool like mimikatz to scrape password hashes or clear plain text passwords.", user="Administrator" 1686748370, search_name="ESCU - Create or delete windows shares using net exe - Rule", analyticstories="CISA AA22-277A", analyticstories="Hidden Cobra Malware", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Hidden Cobra Malware\",\"CISA AA22-277A\",\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1070\",\"T1070.005\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Hidden Cobra Malware", annotations._all="Prestige Ransomware", annotations._all="Windows Post-Exploitation", annotations._all="Exploitation", annotations._all="CISA AA22-277A", annotations._all="T1070.005", annotations._all="T1070", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Hidden Cobra Malware", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1070", annotations.mitre_attack="T1070.005", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:06", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748364.773221000", lastTime="2023-06-14T13:04:06", original_file_name="net.exe", parent_process="\"cmd.exe\" /s /k pushd \"C:\\Temp\"", process="net share", process_name="net.exe", risk_message="An instance of $parent_process_name$ spawning net.exe was identified on endpoint ar-win-dc.attackrange.local by user Administrator enumerating Windows file shares.", risk_object="net.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="This search looks for the creation or deletion of hidden shares using net.exe.", user="Administrator" 1686748370, search_name="ESCU - Create or delete windows shares using net exe - Rule", analyticstories="CISA AA22-277A", analyticstories="Hidden Cobra Malware", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Hidden Cobra Malware\",\"CISA AA22-277A\",\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1070\",\"T1070.005\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Hidden Cobra Malware", annotations._all="Prestige Ransomware", annotations._all="Windows Post-Exploitation", annotations._all="Exploitation", annotations._all="CISA AA22-277A", annotations._all="T1070.005", annotations._all="T1070", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Hidden Cobra Malware", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1070", annotations.mitre_attack="T1070.005", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:06", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748364.773221000", lastTime="2023-06-14T13:04:06", original_file_name="net.exe", parent_process="\"cmd.exe\" /s /k pushd \"C:\\Temp\"", process="net share", process_name="net.exe", risk_message="An instance of $parent_process_name$ spawning net.exe was identified on endpoint ar-win-dc.attackrange.local by user Administrator enumerating Windows file shares.", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="25.0", savedsearch_description="This search looks for the creation or deletion of hidden shares using net.exe.", user="Administrator" 1686748370, search_name="ESCU - Create or delete windows shares using net exe - Rule", analyticstories="CISA AA22-277A", analyticstories="Hidden Cobra Malware", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Hidden Cobra Malware\",\"CISA AA22-277A\",\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1070\",\"T1070.005\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Hidden Cobra Malware", annotations._all="Prestige Ransomware", annotations._all="Windows Post-Exploitation", annotations._all="Exploitation", annotations._all="CISA AA22-277A", annotations._all="T1070.005", annotations._all="T1070", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Hidden Cobra Malware", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1070", annotations.mitre_attack="T1070.005", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:06", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748364.773221000", lastTime="2023-06-14T13:04:06", original_file_name="net.exe", parent_process="\"cmd.exe\" /s /k pushd \"C:\\Temp\"", process="net share", process_name="net.exe", risk_message="An instance of $parent_process_name$ spawning net.exe was identified on endpoint ar-win-dc.attackrange.local by user Administrator enumerating Windows file shares.", risk_object="Administrator", risk_object_type="user", risk_score="25.0", savedsearch_description="This search looks for the creation or deletion of hidden shares using net.exe.", user="Administrator" 1686748370, search_name="ESCU - Create or delete windows shares using net exe - Rule", analyticstories="CISA AA22-277A", analyticstories="Hidden Cobra Malware", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Hidden Cobra Malware\",\"CISA AA22-277A\",\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1070\",\"T1070.005\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Hidden Cobra Malware", annotations._all="Prestige Ransomware", annotations._all="Windows Post-Exploitation", annotations._all="Exploitation", annotations._all="CISA AA22-277A", annotations._all="T1070.005", annotations._all="T1070", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Hidden Cobra Malware", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1070", annotations.mitre_attack="T1070.005", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:06", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748364.773221000", lastTime="2023-06-14T13:04:06", original_file_name="unknown", parent_process="C:\\Windows\\System32\\net.exe", process="C:\\Windows\\system32\\net1 share", process_name="net1.exe", risk_message="An instance of $parent_process_name$ spawning net1.exe was identified on endpoint ar-win-dc.attackrange.local by user Administrator enumerating Windows file shares.", risk_object="net1.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="This search looks for the creation or deletion of hidden shares using net.exe.", user="Administrator" 1686748370, search_name="ESCU - Create or delete windows shares using net exe - Rule", analyticstories="CISA AA22-277A", analyticstories="Hidden Cobra Malware", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Hidden Cobra Malware\",\"CISA AA22-277A\",\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1070\",\"T1070.005\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Hidden Cobra Malware", annotations._all="Prestige Ransomware", annotations._all="Windows Post-Exploitation", annotations._all="Exploitation", annotations._all="CISA AA22-277A", annotations._all="T1070.005", annotations._all="T1070", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Hidden Cobra Malware", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1070", annotations.mitre_attack="T1070.005", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:06", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748364.773221000", lastTime="2023-06-14T13:04:06", original_file_name="unknown", parent_process="C:\\Windows\\System32\\net.exe", process="C:\\Windows\\system32\\net1 share", process_name="net1.exe", risk_message="An instance of $parent_process_name$ spawning net1.exe was identified on endpoint ar-win-dc.attackrange.local by user Administrator enumerating Windows file shares.", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="25.0", savedsearch_description="This search looks for the creation or deletion of hidden shares using net.exe.", user="Administrator" 1686748370, search_name="ESCU - Create or delete windows shares using net exe - Rule", analyticstories="CISA AA22-277A", analyticstories="Hidden Cobra Malware", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Hidden Cobra Malware\",\"CISA AA22-277A\",\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1070\",\"T1070.005\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Hidden Cobra Malware", annotations._all="Prestige Ransomware", annotations._all="Windows Post-Exploitation", annotations._all="Exploitation", annotations._all="CISA AA22-277A", annotations._all="T1070.005", annotations._all="T1070", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Hidden Cobra Malware", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1070", annotations.mitre_attack="T1070.005", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:06", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748364.773221000", lastTime="2023-06-14T13:04:06", original_file_name="unknown", parent_process="C:\\Windows\\System32\\net.exe", process="C:\\Windows\\system32\\net1 share", process_name="net1.exe", risk_message="An instance of $parent_process_name$ spawning net1.exe was identified on endpoint ar-win-dc.attackrange.local by user Administrator enumerating Windows file shares.", risk_object="Administrator", risk_object_type="user", risk_score="25.0", savedsearch_description="This search looks for the creation or deletion of hidden shares using net.exe.", user="Administrator" 1686748370, search_name="ESCU - Create or delete windows shares using net exe - Rule", analyticstories="CISA AA22-277A", analyticstories="Hidden Cobra Malware", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Hidden Cobra Malware\",\"CISA AA22-277A\",\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1070\",\"T1070.005\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Hidden Cobra Malware", annotations._all="Prestige Ransomware", annotations._all="Windows Post-Exploitation", annotations._all="Exploitation", annotations._all="CISA AA22-277A", annotations._all="T1070.005", annotations._all="T1070", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Hidden Cobra Malware", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1070", annotations.mitre_attack="T1070.005", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:06", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748364.773221000", lastTime="2023-06-14T13:04:06", original_file_name="net1.exe", parent_process="net share", process="C:\\Windows\\system32\\net1 share", process_name="net1.exe", risk_message="An instance of $parent_process_name$ spawning net1.exe was identified on endpoint ar-win-dc.attackrange.local by user Administrator enumerating Windows file shares.", risk_object="net1.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="This search looks for the creation or deletion of hidden shares using net.exe.", user="Administrator" 1686748370, search_name="ESCU - Create or delete windows shares using net exe - Rule", analyticstories="CISA AA22-277A", analyticstories="Hidden Cobra Malware", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Hidden Cobra Malware\",\"CISA AA22-277A\",\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1070\",\"T1070.005\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Hidden Cobra Malware", annotations._all="Prestige Ransomware", annotations._all="Windows Post-Exploitation", annotations._all="Exploitation", annotations._all="CISA AA22-277A", annotations._all="T1070.005", annotations._all="T1070", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Hidden Cobra Malware", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1070", annotations.mitre_attack="T1070.005", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:06", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748364.773221000", lastTime="2023-06-14T13:04:06", original_file_name="net1.exe", parent_process="net share", process="C:\\Windows\\system32\\net1 share", process_name="net1.exe", risk_message="An instance of $parent_process_name$ spawning net1.exe was identified on endpoint ar-win-dc.attackrange.local by user Administrator enumerating Windows file shares.", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="25.0", savedsearch_description="This search looks for the creation or deletion of hidden shares using net.exe.", user="Administrator" 1686748370, search_name="ESCU - Create or delete windows shares using net exe - Rule", analyticstories="CISA AA22-277A", analyticstories="Hidden Cobra Malware", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Hidden Cobra Malware\",\"CISA AA22-277A\",\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1070\",\"T1070.005\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Hidden Cobra Malware", annotations._all="Prestige Ransomware", annotations._all="Windows Post-Exploitation", annotations._all="Exploitation", annotations._all="CISA AA22-277A", annotations._all="T1070.005", annotations._all="T1070", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Hidden Cobra Malware", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1070", annotations.mitre_attack="T1070.005", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:06", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748364.773221000", lastTime="2023-06-14T13:04:06", original_file_name="net1.exe", parent_process="net share", process="C:\\Windows\\system32\\net1 share", process_name="net1.exe", risk_message="An instance of $parent_process_name$ spawning net1.exe was identified on endpoint ar-win-dc.attackrange.local by user Administrator enumerating Windows file shares.", risk_object="Administrator", risk_object_type="user", risk_score="25.0", savedsearch_description="This search looks for the creation or deletion of hidden shares using net.exe.", user="Administrator" 1686748370, search_name="ESCU - Create or delete windows shares using net exe - Rule", analyticstories="CISA AA22-277A", analyticstories="Hidden Cobra Malware", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Hidden Cobra Malware\",\"CISA AA22-277A\",\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1070\",\"T1070.005\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Hidden Cobra Malware", annotations._all="Prestige Ransomware", annotations._all="Windows Post-Exploitation", annotations._all="Exploitation", annotations._all="CISA AA22-277A", annotations._all="T1070.005", annotations._all="T1070", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Hidden Cobra Malware", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1070", annotations.mitre_attack="T1070.005", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:06", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748364.773221000", lastTime="2023-06-14T13:04:06", original_file_name="unknown", parent_process="C:\\Windows\\System32\\cmd.exe", process="C:\\Windows\\System32\\net.exe share", process_name="net.exe", risk_message="An instance of $parent_process_name$ spawning net.exe was identified on endpoint ar-win-dc.attackrange.local by user Administrator enumerating Windows file shares.", risk_object="net.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="This search looks for the creation or deletion of hidden shares using net.exe.", user="Administrator" 1686748370, search_name="ESCU - Create or delete windows shares using net exe - Rule", analyticstories="CISA AA22-277A", analyticstories="Hidden Cobra Malware", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Hidden Cobra Malware\",\"CISA AA22-277A\",\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1070\",\"T1070.005\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Hidden Cobra Malware", annotations._all="Prestige Ransomware", annotations._all="Windows Post-Exploitation", annotations._all="Exploitation", annotations._all="CISA AA22-277A", annotations._all="T1070.005", annotations._all="T1070", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Hidden Cobra Malware", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1070", annotations.mitre_attack="T1070.005", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:06", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748364.773221000", lastTime="2023-06-14T13:04:06", original_file_name="unknown", parent_process="C:\\Windows\\System32\\cmd.exe", process="C:\\Windows\\System32\\net.exe share", process_name="net.exe", risk_message="An instance of $parent_process_name$ spawning net.exe was identified on endpoint ar-win-dc.attackrange.local by user Administrator enumerating Windows file shares.", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="25.0", savedsearch_description="This search looks for the creation or deletion of hidden shares using net.exe.", user="Administrator" 1686748370, search_name="ESCU - Create or delete windows shares using net exe - Rule", analyticstories="CISA AA22-277A", analyticstories="Hidden Cobra Malware", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Hidden Cobra Malware\",\"CISA AA22-277A\",\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1070\",\"T1070.005\"],\"nist\":[\"DE.CM\"]}", annotations._all="DE.CM", annotations._all="CIS 10", annotations._all="Hidden Cobra Malware", annotations._all="Prestige Ransomware", annotations._all="Windows Post-Exploitation", annotations._all="Exploitation", annotations._all="CISA AA22-277A", annotations._all="T1070.005", annotations._all="T1070", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Hidden Cobra Malware", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1070", annotations.mitre_attack="T1070.005", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:06", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748364.773221000", lastTime="2023-06-14T13:04:06", original_file_name="unknown", parent_process="C:\\Windows\\System32\\cmd.exe", process="C:\\Windows\\System32\\net.exe share", process_name="net.exe", risk_message="An instance of $parent_process_name$ spawning net.exe was identified on endpoint ar-win-dc.attackrange.local by user Administrator enumerating Windows file shares.", risk_object="Administrator", risk_object_type="user", risk_score="25.0", savedsearch_description="This search looks for the creation or deletion of hidden shares using net.exe.", user="Administrator" 1686747840, search_name="ESCU - Excessive Usage Of Cacls App - Rule", orig_time="1686747840", analyticstories="Azorult", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", analyticstories="XMRig", annotations="{\"analytic_story\":[\"XMRig\",\"Azorult\",\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":100,\"impact\":80,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1222\"],\"nist\":[\"DE.AE\"]}", annotations._all="Prestige Ransomware", annotations._all="XMRig", annotations._all="Exploitation", annotations._all="CIS 10", annotations._all="Azorult", annotations._all="DE.AE", annotations._all="T1222", annotations._all="Windows Post-Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="XMRig", annotations.analytic_story="Azorult", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1222", annotations.nist="DE.AE", count="88", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:03", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748362.315827000", lastTime="2023-06-14T13:04:31", parent_process="C:\\Windows\\System32\\cmd.exe", parent_process_name="cmd.exe", process="C:\\Windows\\System32\\icacls.exe \"C:\\Documents and Settings\\Administrator\\Start Menu\\Programs\\Startup\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Documents and Settings\\Administrator\\Start Menu\\Programs\\Startup\\*\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\*\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files (x86)\\Mozilla Maintenance Service\\maintenanceservice.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Amazon\\SSM\\\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Amazon\\SSM\\amazon-ssm-agent.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Amazon\\SSM\\ssm-agent-worker.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Amazon\\XenTools\\LiteAgent.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Amazon\\cfn-bootstrap\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Amazon\\cfn-bootstrap\\winhup.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Aurora-Agent\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Aurora-Agent\\\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Aurora-Agent\\aurora-agent.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Aurora-Agent\\tools\\\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Aurora-Agent\\tools\\aurora-dashboard.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Git\\cmd\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Mozilla Firefox\\\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Mozilla Firefox\\firefox.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Notepad++\\\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Notepad++\\notepad++.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\*\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\ProgramData\\chocolatey\\bin\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Python311\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Python311\\Scripts\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Users\\Administrator\\AppData\\Local\\Microsoft\\WindowsApps\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Users\\Administrator\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Users\\Administrator\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\*\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\ADWS\\Microsoft.ActiveDirectory.WebServices.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\ADWS\\\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\Explorer.EXE\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\SMSvcHost.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\SysWow64\\perfhost.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\System32\\Wbem\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\SystemApps\\Microsoft.Windows.Cortana_cw5n1h2txyewy\\SearchUI.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\SystemApps\\Microsoft.Windows.Cortana_cw5n1h2txyewy\\\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\SystemApps\\ShellExperienceHost_cw5n1h2txyewy\\ShellExperienceHost.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\SystemApps\\ShellExperienceHost_cw5n1h2txyewy\\\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\WinSxS\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.5771_none_7ee250a22208ec93\\\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\servicing\\TrustedInstaller.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\servicing\\\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\sysmon64.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\system32\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\winsxs\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.5771_none_7ee250a22208ec93\\TiWorker.exe\"", process="C:\\Windows\\System32\\icacls.exe \"c:\\Program Files\\ansible\\sysmon\"", process="C:\\Windows\\System32\\icacls.exe C:\\Windows\\ADWS\\Microsoft.ActiveDirectory.WebServices.exe", process="C:\\Windows\\System32\\icacls.exe C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\SMSvcHost.exe", process="C:\\Windows\\System32\\icacls.exe C:\\Windows\\SysWow64\\perfhost.exe", process="C:\\Windows\\System32\\icacls.exe C:\\Windows\\servicing\\TrustedInstaller.exe", process="C:\\Windows\\System32\\icacls.exe C:\\Windows\\sysmon64.exe", process_id="0x105c", process_id="0x1060", process_id="0x10e8", process_id="0x1170", process_id="0x11bc", process_id="0x1220", process_id="0x1234", process_id="0x1238", process_id="0x1274", process_id="0x12bc", process_id="0x12c", process_id="0x131c", process_id="0x138c", process_id="0x13b8", process_id="0x13d8", process_id="0x1478", process_id="0x1510", process_id="0x1578", process_id="0x15d0", process_id="0x167c", process_id="0x1704", process_id="0x1760", process_id="0x177c", process_id="0x1840", process_id="0x18b8", process_id="0x18d0", process_id="0x18ec", process_id="0x18f8", process_id="0x1938", process_id="0x196c", process_id="0x198c", process_id="0x19c4", process_id="0x19c8", process_id="0x19f0", process_id="0x1a30", process_id="0x1a4c", process_id="0x1a74", process_id="0x1a8c", process_id="0x1a98", process_id="0x1a9c", process_id="0x1aa4", process_id="0x1aac", process_id="0x1ab0", process_id="0x1abc", process_id="0x1afc", process_id="0x1b00", process_id="0x1b08", process_id="0x1b10", process_id="0x1b34", process_id="0x1b58", process_id="0x1b5c", process_id="0x1b6c", process_id="0x1b7c", process_id="0x1b9c", process_id="0x1ba8", process_id="0x1bb4", process_id="0x1be0", process_id="0x1d8", process_id="0x338", process_id="0x4ec", process_id="0x4f0", process_id="0x4f4", process_id="0x71c", process_id="0x820", process_id="0x828", process_id="0x874", process_id="0x8cc", process_id="0xa14", process_id="0xad8", process_id="0xb48", process_id="0xb80", process_id="0xb90", process_id="0xc0c", process_id="0xe54", process_id="0xf20", process_id="0xfc0", process_name="icacls.exe", risk_message="An excessive amount of icacls.exe was executed on ar-win-dc.attackrange.local attempting to modify permissions.", risk_object="icacls.exe", risk_object_type="other", risk_score="80.0", savedsearch_description="The following analytic identifies excessive usage of `cacls.exe`, `xcacls.exe` or `icacls.exe` application to change file or folder permission. This behavior is commonly seen where the adversary attempts to impair some users from deleting or accessing its malware components or artifact from the compromised system.", user="Administrator" 1686747840, search_name="ESCU - Excessive Usage Of Cacls App - Rule", orig_time="1686747840", analyticstories="Azorult", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", analyticstories="XMRig", annotations="{\"analytic_story\":[\"XMRig\",\"Azorult\",\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":100,\"impact\":80,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1222\"],\"nist\":[\"DE.AE\"]}", annotations._all="Prestige Ransomware", annotations._all="XMRig", annotations._all="Exploitation", annotations._all="CIS 10", annotations._all="Azorult", annotations._all="DE.AE", annotations._all="T1222", annotations._all="Windows Post-Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="XMRig", annotations.analytic_story="Azorult", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1222", annotations.nist="DE.AE", count="88", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:03", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748362.315827000", lastTime="2023-06-14T13:04:31", parent_process="C:\\Windows\\System32\\cmd.exe", parent_process_name="cmd.exe", process="C:\\Windows\\System32\\icacls.exe \"C:\\Documents and Settings\\Administrator\\Start Menu\\Programs\\Startup\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Documents and Settings\\Administrator\\Start Menu\\Programs\\Startup\\*\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\*\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files (x86)\\Mozilla Maintenance Service\\maintenanceservice.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Amazon\\SSM\\\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Amazon\\SSM\\amazon-ssm-agent.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Amazon\\SSM\\ssm-agent-worker.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Amazon\\XenTools\\LiteAgent.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Amazon\\cfn-bootstrap\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Amazon\\cfn-bootstrap\\winhup.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Aurora-Agent\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Aurora-Agent\\\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Aurora-Agent\\aurora-agent.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Aurora-Agent\\tools\\\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Aurora-Agent\\tools\\aurora-dashboard.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Git\\cmd\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Mozilla Firefox\\\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Mozilla Firefox\\firefox.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Notepad++\\\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Notepad++\\notepad++.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\*\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\ProgramData\\chocolatey\\bin\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Python311\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Python311\\Scripts\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Users\\Administrator\\AppData\\Local\\Microsoft\\WindowsApps\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Users\\Administrator\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Users\\Administrator\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\*\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\ADWS\\Microsoft.ActiveDirectory.WebServices.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\ADWS\\\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\Explorer.EXE\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\SMSvcHost.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\SysWow64\\perfhost.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\System32\\Wbem\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\SystemApps\\Microsoft.Windows.Cortana_cw5n1h2txyewy\\SearchUI.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\SystemApps\\Microsoft.Windows.Cortana_cw5n1h2txyewy\\\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\SystemApps\\ShellExperienceHost_cw5n1h2txyewy\\ShellExperienceHost.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\SystemApps\\ShellExperienceHost_cw5n1h2txyewy\\\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\WinSxS\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.5771_none_7ee250a22208ec93\\\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\servicing\\TrustedInstaller.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\servicing\\\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\sysmon64.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\system32\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\winsxs\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.5771_none_7ee250a22208ec93\\TiWorker.exe\"", process="C:\\Windows\\System32\\icacls.exe \"c:\\Program Files\\ansible\\sysmon\"", process="C:\\Windows\\System32\\icacls.exe C:\\Windows\\ADWS\\Microsoft.ActiveDirectory.WebServices.exe", process="C:\\Windows\\System32\\icacls.exe C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\SMSvcHost.exe", process="C:\\Windows\\System32\\icacls.exe C:\\Windows\\SysWow64\\perfhost.exe", process="C:\\Windows\\System32\\icacls.exe C:\\Windows\\servicing\\TrustedInstaller.exe", process="C:\\Windows\\System32\\icacls.exe C:\\Windows\\sysmon64.exe", process_id="0x105c", process_id="0x1060", process_id="0x10e8", process_id="0x1170", process_id="0x11bc", process_id="0x1220", process_id="0x1234", process_id="0x1238", process_id="0x1274", process_id="0x12bc", process_id="0x12c", process_id="0x131c", process_id="0x138c", process_id="0x13b8", process_id="0x13d8", process_id="0x1478", process_id="0x1510", process_id="0x1578", process_id="0x15d0", process_id="0x167c", process_id="0x1704", process_id="0x1760", process_id="0x177c", process_id="0x1840", process_id="0x18b8", process_id="0x18d0", process_id="0x18ec", process_id="0x18f8", process_id="0x1938", process_id="0x196c", process_id="0x198c", process_id="0x19c4", process_id="0x19c8", process_id="0x19f0", process_id="0x1a30", process_id="0x1a4c", process_id="0x1a74", process_id="0x1a8c", process_id="0x1a98", process_id="0x1a9c", process_id="0x1aa4", process_id="0x1aac", process_id="0x1ab0", process_id="0x1abc", process_id="0x1afc", process_id="0x1b00", process_id="0x1b08", process_id="0x1b10", process_id="0x1b34", process_id="0x1b58", process_id="0x1b5c", process_id="0x1b6c", process_id="0x1b7c", process_id="0x1b9c", process_id="0x1ba8", process_id="0x1bb4", process_id="0x1be0", process_id="0x1d8", process_id="0x338", process_id="0x4ec", process_id="0x4f0", process_id="0x4f4", process_id="0x71c", process_id="0x820", process_id="0x828", process_id="0x874", process_id="0x8cc", process_id="0xa14", process_id="0xad8", process_id="0xb48", process_id="0xb80", process_id="0xb90", process_id="0xc0c", process_id="0xe54", process_id="0xf20", process_id="0xfc0", process_name="icacls.exe", risk_message="An excessive amount of icacls.exe was executed on ar-win-dc.attackrange.local attempting to modify permissions.", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="80.0", savedsearch_description="The following analytic identifies excessive usage of `cacls.exe`, `xcacls.exe` or `icacls.exe` application to change file or folder permission. This behavior is commonly seen where the adversary attempts to impair some users from deleting or accessing its malware components or artifact from the compromised system.", user="Administrator" 1686747840, search_name="ESCU - Excessive Usage Of Cacls App - Rule", orig_time="1686747840", analyticstories="Azorult", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", analyticstories="XMRig", annotations="{\"analytic_story\":[\"XMRig\",\"Azorult\",\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":100,\"impact\":80,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1222\"],\"nist\":[\"DE.AE\"]}", annotations._all="Prestige Ransomware", annotations._all="XMRig", annotations._all="Exploitation", annotations._all="CIS 10", annotations._all="Azorult", annotations._all="DE.AE", annotations._all="T1222", annotations._all="Windows Post-Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="XMRig", annotations.analytic_story="Azorult", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1222", annotations.nist="DE.AE", count="76", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:03", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748362.315827000", lastTime="2023-06-14T13:04:30", parent_process="\"cmd.exe\" /s /k pushd \"C:\\Temp\"", parent_process_name="cmd.exe", process="icacls C:\\Windows\\ADWS\\Microsoft.ActiveDirectory.WebServices.exe", process="icacls C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\SMSvcHost.exe", process="icacls C:\\Windows\\SysWow64\\perfhost.exe", process="icacls C:\\Windows\\servicing\\TrustedInstaller.exe", process="icacls C:\\Windows\\sysmon64.exe", process="icacls \"C:\\Documents and Settings\\Administrator\\Start Menu\\Programs\\Startup\"", process="icacls \"C:\\Documents and Settings\\Administrator\\Start Menu\\Programs\\Startup\\*\"", process="icacls \"C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\"", process="icacls \"C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\*\"", process="icacls \"C:\\Program Files (x86)\\Mozilla Maintenance Service\\maintenanceservice.exe\"", process="icacls \"C:\\Program Files\\Amazon\\SSM\\\\\"", process="icacls \"C:\\Program Files\\Amazon\\SSM\\amazon-ssm-agent.exe\"", process="icacls \"C:\\Program Files\\Amazon\\SSM\\ssm-agent-worker.exe\"", process="icacls \"C:\\Program Files\\Amazon\\XenTools\\LiteAgent.exe\"", process="icacls \"C:\\Program Files\\Amazon\\cfn-bootstrap\\winhup.exe\"", process="icacls \"C:\\Program Files\\Aurora-Agent\\\\\"", process="icacls \"C:\\Program Files\\Aurora-Agent\\aurora-agent.exe\"", process="icacls \"C:\\Program Files\\Aurora-Agent\\tools\\\\\"", process="icacls \"C:\\Program Files\\Aurora-Agent\\tools\\aurora-dashboard.exe\"", process="icacls \"C:\\Program Files\\Mozilla Firefox\\\\\"", process="icacls \"C:\\Program Files\\Mozilla Firefox\\firefox.exe\"", process="icacls \"C:\\Program Files\\Notepad++\\\\\"", process="icacls \"C:\\Program Files\\Notepad++\\notepad++.exe\"", process="icacls \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\\\\"", process="icacls \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\"", process="icacls \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe\"", process="icacls \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\"", process="icacls \"C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\"", process="icacls \"C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\*\"", process="icacls \"C:\\Users\\Administrator\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\"", process="icacls \"C:\\Users\\Administrator\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\*\"", process="icacls \"C:\\Windows\\ADWS\\Microsoft.ActiveDirectory.WebServices.exe\"", process="icacls \"C:\\Windows\\ADWS\\\\\"", process="icacls \"C:\\Windows\\Explorer.EXE\"", process="icacls \"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\SMSvcHost.exe\"", process="icacls \"C:\\Windows\\SysWow64\\perfhost.exe\"", process="icacls \"C:\\Windows\\SystemApps\\Microsoft.Windows.Cortana_cw5n1h2txyewy\\SearchUI.exe\"", process="icacls \"C:\\Windows\\SystemApps\\Microsoft.Windows.Cortana_cw5n1h2txyewy\\\\\"", process="icacls \"C:\\Windows\\SystemApps\\ShellExperienceHost_cw5n1h2txyewy\\ShellExperienceHost.exe\"", process="icacls \"C:\\Windows\\SystemApps\\ShellExperienceHost_cw5n1h2txyewy\\\\\"", process="icacls \"C:\\Windows\\WinSxS\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.5771_none_7ee250a22208ec93\\\\\"", process="icacls \"C:\\Windows\\\\\"", process="icacls \"C:\\Windows\\servicing\\TrustedInstaller.exe\"", process="icacls \"C:\\Windows\\servicing\\\\\"", process="icacls \"C:\\Windows\\sysmon64.exe\"", process="icacls \"C:\\Windows\\winsxs\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.5771_none_7ee250a22208ec93\\TiWorker.exe\"", process_id="1260", process_id="1264", process_id="1268", process_id="1820", process_id="2080", process_id="2088", process_id="2164", process_id="2252", process_id="2776", process_id="2888", process_id="2944", process_id="2960", process_id="300", process_id="3084", process_id="3668", process_id="3872", process_id="4032", process_id="4188", process_id="4192", process_id="4328", process_id="4464", process_id="4540", process_id="4640", process_id="4660", process_id="4664", process_id="472", process_id="4724", process_id="4796", process_id="4892", process_id="5048", process_id="5080", process_id="5240", process_id="5392", process_id="5496", process_id="5756", process_id="5892", process_id="6012", process_id="6208", process_id="6328", process_id="6380", process_id="6392", process_id="6456", process_id="6508", process_id="6540", process_id="6596", process_id="6600", process_id="6640", process_id="6704", process_id="6732", process_id="6772", process_id="6796", process_id="6808", process_id="6812", process_id="6820", process_id="6828", process_id="6832", process_id="6844", process_id="6920", process_id="6928", process_id="6964", process_id="7000", process_id="7004", process_id="7020", process_id="7036", process_id="7068", process_id="7080", process_id="7092", process_id="7136", process_id="824", process_name="icacls.exe", risk_message="An excessive amount of icacls.exe was executed on ar-win-dc.attackrange.local attempting to modify permissions.", risk_object="icacls.exe", risk_object_type="other", risk_score="80.0", savedsearch_description="The following analytic identifies excessive usage of `cacls.exe`, `xcacls.exe` or `icacls.exe` application to change file or folder permission. This behavior is commonly seen where the adversary attempts to impair some users from deleting or accessing its malware components or artifact from the compromised system.", user="Administrator" 1686747840, search_name="ESCU - Excessive Usage Of Cacls App - Rule", orig_time="1686747840", analyticstories="Azorult", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", analyticstories="XMRig", annotations="{\"analytic_story\":[\"XMRig\",\"Azorult\",\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":100,\"impact\":80,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1222\"],\"nist\":[\"DE.AE\"]}", annotations._all="Prestige Ransomware", annotations._all="XMRig", annotations._all="Exploitation", annotations._all="CIS 10", annotations._all="Azorult", annotations._all="DE.AE", annotations._all="T1222", annotations._all="Windows Post-Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="XMRig", annotations.analytic_story="Azorult", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1222", annotations.nist="DE.AE", count="76", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:03", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748362.315827000", lastTime="2023-06-14T13:04:30", parent_process="\"cmd.exe\" /s /k pushd \"C:\\Temp\"", parent_process_name="cmd.exe", process="icacls C:\\Windows\\ADWS\\Microsoft.ActiveDirectory.WebServices.exe", process="icacls C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\SMSvcHost.exe", process="icacls C:\\Windows\\SysWow64\\perfhost.exe", process="icacls C:\\Windows\\servicing\\TrustedInstaller.exe", process="icacls C:\\Windows\\sysmon64.exe", process="icacls \"C:\\Documents and Settings\\Administrator\\Start Menu\\Programs\\Startup\"", process="icacls \"C:\\Documents and Settings\\Administrator\\Start Menu\\Programs\\Startup\\*\"", process="icacls \"C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\"", process="icacls \"C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\*\"", process="icacls \"C:\\Program Files (x86)\\Mozilla Maintenance Service\\maintenanceservice.exe\"", process="icacls \"C:\\Program Files\\Amazon\\SSM\\\\\"", process="icacls \"C:\\Program Files\\Amazon\\SSM\\amazon-ssm-agent.exe\"", process="icacls \"C:\\Program Files\\Amazon\\SSM\\ssm-agent-worker.exe\"", process="icacls \"C:\\Program Files\\Amazon\\XenTools\\LiteAgent.exe\"", process="icacls \"C:\\Program Files\\Amazon\\cfn-bootstrap\\winhup.exe\"", process="icacls \"C:\\Program Files\\Aurora-Agent\\\\\"", process="icacls \"C:\\Program Files\\Aurora-Agent\\aurora-agent.exe\"", process="icacls \"C:\\Program Files\\Aurora-Agent\\tools\\\\\"", process="icacls \"C:\\Program Files\\Aurora-Agent\\tools\\aurora-dashboard.exe\"", process="icacls \"C:\\Program Files\\Mozilla Firefox\\\\\"", process="icacls \"C:\\Program Files\\Mozilla Firefox\\firefox.exe\"", process="icacls \"C:\\Program Files\\Notepad++\\\\\"", process="icacls \"C:\\Program Files\\Notepad++\\notepad++.exe\"", process="icacls \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\\\\"", process="icacls \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\"", process="icacls \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe\"", process="icacls \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\"", process="icacls \"C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\"", process="icacls \"C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\*\"", process="icacls \"C:\\Users\\Administrator\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\"", process="icacls \"C:\\Users\\Administrator\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\*\"", process="icacls \"C:\\Windows\\ADWS\\Microsoft.ActiveDirectory.WebServices.exe\"", process="icacls \"C:\\Windows\\ADWS\\\\\"", process="icacls \"C:\\Windows\\Explorer.EXE\"", process="icacls \"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\SMSvcHost.exe\"", process="icacls \"C:\\Windows\\SysWow64\\perfhost.exe\"", process="icacls \"C:\\Windows\\SystemApps\\Microsoft.Windows.Cortana_cw5n1h2txyewy\\SearchUI.exe\"", process="icacls \"C:\\Windows\\SystemApps\\Microsoft.Windows.Cortana_cw5n1h2txyewy\\\\\"", process="icacls \"C:\\Windows\\SystemApps\\ShellExperienceHost_cw5n1h2txyewy\\ShellExperienceHost.exe\"", process="icacls \"C:\\Windows\\SystemApps\\ShellExperienceHost_cw5n1h2txyewy\\\\\"", process="icacls \"C:\\Windows\\WinSxS\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.5771_none_7ee250a22208ec93\\\\\"", process="icacls \"C:\\Windows\\\\\"", process="icacls \"C:\\Windows\\servicing\\TrustedInstaller.exe\"", process="icacls \"C:\\Windows\\servicing\\\\\"", process="icacls \"C:\\Windows\\sysmon64.exe\"", process="icacls \"C:\\Windows\\winsxs\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.5771_none_7ee250a22208ec93\\TiWorker.exe\"", process_id="1260", process_id="1264", process_id="1268", process_id="1820", process_id="2080", process_id="2088", process_id="2164", process_id="2252", process_id="2776", process_id="2888", process_id="2944", process_id="2960", process_id="300", process_id="3084", process_id="3668", process_id="3872", process_id="4032", process_id="4188", process_id="4192", process_id="4328", process_id="4464", process_id="4540", process_id="4640", process_id="4660", process_id="4664", process_id="472", process_id="4724", process_id="4796", process_id="4892", process_id="5048", process_id="5080", process_id="5240", process_id="5392", process_id="5496", process_id="5756", process_id="5892", process_id="6012", process_id="6208", process_id="6328", process_id="6380", process_id="6392", process_id="6456", process_id="6508", process_id="6540", process_id="6596", process_id="6600", process_id="6640", process_id="6704", process_id="6732", process_id="6772", process_id="6796", process_id="6808", process_id="6812", process_id="6820", process_id="6828", process_id="6832", process_id="6844", process_id="6920", process_id="6928", process_id="6964", process_id="7000", process_id="7004", process_id="7020", process_id="7036", process_id="7068", process_id="7080", process_id="7092", process_id="7136", process_id="824", process_name="icacls.exe", risk_message="An excessive amount of icacls.exe was executed on ar-win-dc.attackrange.local attempting to modify permissions.", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="80.0", savedsearch_description="The following analytic identifies excessive usage of `cacls.exe`, `xcacls.exe` or `icacls.exe` application to change file or folder permission. This behavior is commonly seen where the adversary attempts to impair some users from deleting or accessing its malware components or artifact from the compromised system.", user="Administrator" 1686748349, search_name="ESCU - Windows WMI Process And Service List - Rule", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":20,\"impact\":20,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1047\"],\"nist\":[\"DE.AE\"]}", annotations._all="Windows Post-Exploitation", annotations._all="Installation", annotations._all="T1047", annotations._all="Prestige Ransomware", annotations._all="DE.AE", annotations._all="CIS 10", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1047", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:10", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748343.915660000", lastTime="2023-06-14T13:04:10", original_file_name="wmic.exe", parent_process="cmd.exe /c wmic service list full", parent_process_guid="{953948C6-BACA-6489-7403-00000000F902}", parent_process_name="cmd.exe", process="wmic service list full", process_guid="{953948C6-BACA-6489-7703-00000000F902}", process_id="7008", process_name="WMIC.exe", risk_message="wmi command wmic service list full to list processes and services in ar-win-dc.attackrange.local", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="4.0", savedsearch_description="The following analytic identifies suspicious process command line, where WMI is performing an event query looking for running processes or running services. This technique is commonly found where the adversary will identify services and system information on the compromised machine. During triage, review parallel processes within the same timeframe. Review the full script block to identify other related artifacts.", user="Administrator" 1686748349, search_name="ESCU - Windows WMI Process And Service List - Rule", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":20,\"impact\":20,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1047\"],\"nist\":[\"DE.AE\"]}", annotations._all="Windows Post-Exploitation", annotations._all="Installation", annotations._all="T1047", annotations._all="Prestige Ransomware", annotations._all="DE.AE", annotations._all="CIS 10", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1047", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:04", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748343.915660000", lastTime="2023-06-14T13:04:04", original_file_name="wmic.exe", parent_process="C:\\Windows\\system32\\cmd.exe /c wmic process list full|find /i \"executablepath\"|find /i /v \"system32\"|find \":\"", parent_process_guid="{953948C6-BAC4-6489-8602-00000000F902}", parent_process_name="cmd.exe", process="wmic process list full", process_guid="{953948C6-BAC4-6489-8702-00000000F902}", process_id="5560", process_name="WMIC.exe", risk_message="wmi command wmic process list full to list processes and services in ar-win-dc.attackrange.local", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="4.0", savedsearch_description="The following analytic identifies suspicious process command line, where WMI is performing an event query looking for running processes or running services. This technique is commonly found where the adversary will identify services and system information on the compromised machine. During triage, review parallel processes within the same timeframe. Review the full script block to identify other related artifacts.", user="Administrator" 1686748349, search_name="ESCU - Windows WMI Process And Service List - Rule", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":20,\"impact\":20,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1047\"],\"nist\":[\"DE.AE\"]}", annotations._all="Windows Post-Exploitation", annotations._all="Installation", annotations._all="T1047", annotations._all="Prestige Ransomware", annotations._all="DE.AE", annotations._all="CIS 10", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1047", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:03", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748343.915660000", lastTime="2023-06-14T13:04:03", original_file_name="wmic.exe", parent_process="C:\\Windows\\system32\\cmd.exe /c wmic process list full|find /i \"executablepath\"|find /i /v \"system32\"|find \":\"", parent_process_guid="{953948C6-BAC3-6489-1902-00000000F902}", parent_process_name="cmd.exe", process="wmic process list full", process_guid="{953948C6-BAC3-6489-1A02-00000000F902}", process_id="2268", process_name="WMIC.exe", risk_message="wmi command wmic process list full to list processes and services in ar-win-dc.attackrange.local", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="4.0", savedsearch_description="The following analytic identifies suspicious process command line, where WMI is performing an event query looking for running processes or running services. This technique is commonly found where the adversary will identify services and system information on the compromised machine. During triage, review parallel processes within the same timeframe. Review the full script block to identify other related artifacts.", user="Administrator" 1686748349, search_name="ESCU - Windows WMI Process And Service List - Rule", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":20,\"impact\":20,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1047\"],\"nist\":[\"DE.AE\"]}", annotations._all="Windows Post-Exploitation", annotations._all="Installation", annotations._all="T1047", annotations._all="Prestige Ransomware", annotations._all="DE.AE", annotations._all="CIS 10", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1047", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:10", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748343.915660000", lastTime="2023-06-14T13:04:10", original_file_name="unknown", parent_process="C:\\Windows\\System32\\cmd.exe", parent_process_guid="null", parent_process_name="cmd.exe", process="C:\\Windows\\System32\\wbem\\WMIC.exe service list full", process_guid="null", process_id="0x1b60", process_name="WMIC.exe", risk_message="wmi command C:\\Windows\\System32\\wbem\\WMIC.exe service list full to list processes and services in ar-win-dc.attackrange.local", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="4.0", savedsearch_description="The following analytic identifies suspicious process command line, where WMI is performing an event query looking for running processes or running services. This technique is commonly found where the adversary will identify services and system information on the compromised machine. During triage, review parallel processes within the same timeframe. Review the full script block to identify other related artifacts.", user="Administrator" 1686748349, search_name="ESCU - Windows WMI Process And Service List - Rule", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":20,\"impact\":20,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1047\"],\"nist\":[\"DE.AE\"]}", annotations._all="Windows Post-Exploitation", annotations._all="Installation", annotations._all="T1047", annotations._all="Prestige Ransomware", annotations._all="DE.AE", annotations._all="CIS 10", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1047", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:03", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748343.915660000", lastTime="2023-06-14T13:04:03", original_file_name="unknown", parent_process="C:\\Windows\\System32\\cmd.exe", parent_process_guid="null", parent_process_name="cmd.exe", process="C:\\Windows\\System32\\wbem\\WMIC.exe process list full", process_guid="null", process_id="0x8dc", process_name="WMIC.exe", risk_message="wmi command C:\\Windows\\System32\\wbem\\WMIC.exe process list full to list processes and services in ar-win-dc.attackrange.local", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="4.0", savedsearch_description="The following analytic identifies suspicious process command line, where WMI is performing an event query looking for running processes or running services. This technique is commonly found where the adversary will identify services and system information on the compromised machine. During triage, review parallel processes within the same timeframe. Review the full script block to identify other related artifacts.", user="Administrator" 1686748349, search_name="ESCU - Windows WMI Process And Service List - Rule", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":20,\"impact\":20,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1047\"],\"nist\":[\"DE.AE\"]}", annotations._all="Windows Post-Exploitation", annotations._all="Installation", annotations._all="T1047", annotations._all="Prestige Ransomware", annotations._all="DE.AE", annotations._all="CIS 10", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1047", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:04", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748343.915660000", lastTime="2023-06-14T13:04:04", original_file_name="unknown", parent_process="C:\\Windows\\System32\\cmd.exe", parent_process_guid="null", parent_process_name="cmd.exe", process="C:\\Windows\\System32\\wbem\\WMIC.exe process list full", process_guid="null", process_id="0x15b8", process_name="WMIC.exe", risk_message="wmi command C:\\Windows\\System32\\wbem\\WMIC.exe process list full to list processes and services in ar-win-dc.attackrange.local", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="4.0", savedsearch_description="The following analytic identifies suspicious process command line, where WMI is performing an event query looking for running processes or running services. This technique is commonly found where the adversary will identify services and system information on the compromised machine. During triage, review parallel processes within the same timeframe. Review the full script block to identify other related artifacts.", user="Administrator" 1686747840, search_name="ESCU - Windows Indirect Command Execution Via Series Of Forfiles - Rule", orig_time="1686747840", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":30,\"impact\":30,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.AE\"]}", annotations._all="DE.AE", annotations._all="Prestige Ransomware", annotations._all="CIS 10", annotations._all="Exploitation", annotations._all="Windows Post-Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.AE", count="53", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:01", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748318.336991000", lastTime="2023-06-14T13:04:36", parent_process="C:\\Windows\\System32\\cmd.exe", parent_process_name="cmd.exe", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m ADMINISTRATORS GROUPS\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m ARP\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m AlwaysInstallElevated?\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m AppCmd\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Audit Settings\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m CHECK IF YOU CAN MODIFY ANY SERVICE REGISTRY\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m CURRENT CLIPBOARD\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m CURRENT LOGGED USERS\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m CURRENT SHARES\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m CURRENT USER\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Cloud Credentials\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Credential Guard?\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m DATE and TIME\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m DNS CACHE\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m DPAPI MASTER KEYS\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m ENVIRONMENT\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m FIREWALL\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Files in registry that may contain credentials\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m GPP Password\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m GROUPS\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Hosts file\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m INSTALLED SOFTWARE\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m INTERFACES\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Kerberos Tickets\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m LAPS installed?\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m LSA protection?\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m MOUNTED DISKS\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m McAffee SiteList.xml\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Number of cached creds\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m PowerShell settings\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m ROUTES\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m RUN AT STARTUP\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m RUNNING PROCESSES\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Registered Anti-Virus(AV)\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Remote Desktop Credentials Manager\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m SAM and SYSTEM backups\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m SERVICE BINARY PERMISSIONS WITH WMIC and ICACLS\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m UAC Settings\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m UNQUOTED SERVICE PATHS\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m USED PORTS\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m USERS\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Unattended files\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m WDigest?\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m WEF Settings\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m WIFI\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m WINDOWS VAULT\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m WSUS\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO.0x1B[32m[*]0x1B[97m BASIC USER INFO\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO.0x1B[32m[*]0x1B[97m CREDENTIALS\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO.0x1B[32m[*]0x1B[97m DLL HIJACKING in PATHenv variable\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO.0x1B[32m[*]0x1B[97m NETWORK\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO.0x1B[32m[*]0x1B[97m SERVICE VULNERABILITIES\"", process_name="forfiles.exe", risk_message="excessive forfiles process execution in ar-win-dc.attackrange.local", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="9.0", savedsearch_description="This analytic is developed to detect suspicious excessive usage of forfiles.exe process. This event was seen in post exploitation tool WINPEAS that was used by Ransomware Prestige. Forfiles command lets you run a command on or pass arguments to multiple files. This Windows OS built-in tool being abused to list all files in specific directory or drive.", user="Administrator" 1686747780, search_name="ESCU - Windows Indirect Command Execution Via Series Of Forfiles - Rule", orig_time="1686747780", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":30,\"impact\":30,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.AE\"]}", annotations._all="DE.AE", annotations._all="Prestige Ransomware", annotations._all="CIS 10", annotations._all="Exploitation", annotations._all="Windows Post-Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.AE", count="31", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:15", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748318.336991000", lastTime="2023-06-14T13:03:17", parent_process="C:\\Windows\\System32\\cmd.exe", parent_process_name="cmd.exe", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m(((((((((((((((((((((((((((/0x1B[97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m(((((((((/,. 0x1B[92m,*//////*,.0x1B[32m ./(((((((((((.0x1B[97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m((,.,/((((((((((((((((((((/, */0x1B[97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m(((((((((/, 0x1B[92m,####################(0x1B[32m/..((((((((((.0x1B[97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m,/*,..*(((((((((((((((((((((((((((((((((,0x1B[97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m((((((((((((((((* 0x1B[94m*****0x1B[32m,,,/########## 0x1B[32m.(* ,((((((0x1B[97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m(((((((((((/* 0x1B[94m******************0x1B[32m/####### 0x1B[32m.(. ((((((0x1B[97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m(((((((((. ,0x1B[92m(############################(0x1B[32m../(((((((((.0x1B[97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m((((((.0x1B[92m.0x1B[94m******************0x1B[97m/@@@@@/0x1B[94m***0x1B[92m/######0x1B[32m /((((((0x1B[97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m, ,0x1B[92m0x1B[94m**********************0x1B[97m#@@@@@#@@@@0x1B[94m*********0x1B[92m##0x1B[32m((/ /((((0x1B[97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m,*/((((((((((((((((((/, 0x1B[92m.*//((//**,0x1B[32m .*((((((*0x1B[97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m,,.0x1B[92m.0x1B[94m**********************0x1B[97m@@@@@@@@@@(0x1B[94m***0x1B[92m,####0x1B[32m ../(((((0x1B[97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.((((0x1B[92m(############################################/0x1B[32m /((0x1B[97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.((0x1B[92m(####################/*******(###################0x1B[32m.((((0x1B[97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.((0x1B[92m(################(/0x1B[94m******0x1B[97m/@@@@@#0x1B[94m****************0x1B[32m.. /((0x1B[97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.(0x1B[92m(######################################(0x1B[94m************0x1B[32m..(0x1B[97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.(0x1B[92m(##################################(/0x1B[94m***************0x1B[32m..(0x1B[97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.(0x1B[92m(#############################(/0x1B[94m********************0x1B[32m.,(0x1B[97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.(0x1B[92m(########################(/0x1B[94m************************0x1B[32m..*(0x1B[97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.(0x1B[92m(##################(/**********(################(0x1B[94m**0x1B[32m...(0x1B[97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.(0x1B[92m(######(,.***.,(###################(..***(/0x1B[94m*********0x1B[32m..(0x1B[97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.(0x1B[92m(######*(#####((##################((######/(0x1B[94m********0x1B[32m..(0x1B[97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m..((((0x1B[92m(#########################################(0x1B[32m..(((((.0x1B[97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m..((0x1B[92m(##########0x1B[94m*********0x1B[97m/#@@@@@@@@@/0x1B[94m*************0x1B[32m,,..((((0x1B[97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m....((((0x1B[92m(#####################################(0x1B[32m .((((((.0x1B[97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m......((((0x1B[92m(#################################(0x1B[32m .(((((((.0x1B[97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[41mAny misuse of this software will not be the responsibility of the author or of any other collaborator.0x1B[40;97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[41mUse it at your own networks and/or with the network owner's permission.0x1B[40;97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[41mWinPEAS should be used for authorized penetration testing and/or educational purposes only.0x1B[40;97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m WINDOWS OS\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO.0x1B[32m[*]0x1B[97m BASIC SYSTEM INFO\"", process_name="forfiles.exe", risk_message="excessive forfiles process execution in ar-win-dc.attackrange.local", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="9.0", savedsearch_description="This analytic is developed to detect suspicious excessive usage of forfiles.exe process. This event was seen in post exploitation tool WINPEAS that was used by Ransomware Prestige. Forfiles command lets you run a command on or pass arguments to multiple files. This Windows OS built-in tool being abused to list all files in specific directory or drive.", user="Administrator" 1686748292, search_name="ESCU - Windows Credentials in Registry Reg Query - Rule", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1552.002\",\"T1552\"],\"nist\":[\"DE.AE\"]}", annotations._all="Windows Post-Exploitation", annotations._all="DE.AE", annotations._all="Prestige Ransomware", annotations._all="Exploitation", annotations._all="T1552.002", annotations._all="T1552", annotations._all="CIS 10", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1552.002", annotations.mitre_attack="T1552", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:36", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748284.469784000", lastTime="2023-06-14T13:04:36", original_file_name="unknown", parent_process="C:\\Windows\\System32\\cmd.exe", parent_process_guid="null", parent_process_name="cmd.exe", process="C:\\Windows\\System32\\reg.exe query HKLM\\SYSTEM\\CurrentControlSet\\Services\\SNMP /s", process_guid="null", process_id="0x12a8", process_name="reg.exe", risk_message="reg query commandline C:\\Windows\\System32\\reg.exe query HKLM\\SYSTEM\\CurrentControlSet\\Services\\SNMP /s in ar-win-dc.attackrange.local", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="25.0", savedsearch_description="The following analytic identifies a process command line related to the discovery of possible password or credentials in the registry. This technique is being abused by adversaries or post exploitation tools like winpeas to steal credentials in the registry in the targeted host. Registry can contain several sensitive information like username and credentials that can be used for privilege escalation, persistence or even in lateral movement. This Anomaly detection can be a good pivot to detect a suspicious process querying a registry related to password or private keys.", user="Administrator" 1686748292, search_name="ESCU - Windows Credentials in Registry Reg Query - Rule", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1552.002\",\"T1552\"],\"nist\":[\"DE.AE\"]}", annotations._all="Windows Post-Exploitation", annotations._all="DE.AE", annotations._all="Prestige Ransomware", annotations._all="Exploitation", annotations._all="T1552.002", annotations._all="T1552", annotations._all="CIS 10", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1552.002", annotations.mitre_attack="T1552", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:36", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748284.469784000", lastTime="2023-06-14T13:04:36", original_file_name="unknown", parent_process="C:\\Windows\\System32\\cmd.exe", parent_process_guid="null", parent_process_name="cmd.exe", process="C:\\Windows\\System32\\reg.exe query HKEY_LOCAL_MACHINE\\SOFTWARE\\RealVNC\\WinVNC4 /v password", process_guid="null", process_id="0x1a28", process_name="reg.exe", risk_message="reg query commandline C:\\Windows\\System32\\reg.exe query HKEY_LOCAL_MACHINE\\SOFTWARE\\RealVNC\\WinVNC4 /v password in ar-win-dc.attackrange.local", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="25.0", savedsearch_description="The following analytic identifies a process command line related to the discovery of possible password or credentials in the registry. This technique is being abused by adversaries or post exploitation tools like winpeas to steal credentials in the registry in the targeted host. Registry can contain several sensitive information like username and credentials that can be used for privilege escalation, persistence or even in lateral movement. This Anomaly detection can be a good pivot to detect a suspicious process querying a registry related to password or private keys.", user="Administrator" 1686748292, search_name="ESCU - Windows Credentials in Registry Reg Query - Rule", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1552.002\",\"T1552\"],\"nist\":[\"DE.AE\"]}", annotations._all="Windows Post-Exploitation", annotations._all="DE.AE", annotations._all="Prestige Ransomware", annotations._all="Exploitation", annotations._all="T1552.002", annotations._all="T1552", annotations._all="CIS 10", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1552.002", annotations.mitre_attack="T1552", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:36", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748284.469784000", lastTime="2023-06-14T13:04:36", original_file_name="unknown", parent_process="C:\\Windows\\System32\\cmd.exe", parent_process_guid="null", parent_process_name="cmd.exe", process="C:\\Windows\\System32\\reg.exe query HKCU\\Software\\TightVNC\\Server", process_guid="null", process_id="0x1a64", process_name="reg.exe", risk_message="reg query commandline C:\\Windows\\System32\\reg.exe query HKCU\\Software\\TightVNC\\Server in ar-win-dc.attackrange.local", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="25.0", savedsearch_description="The following analytic identifies a process command line related to the discovery of possible password or credentials in the registry. This technique is being abused by adversaries or post exploitation tools like winpeas to steal credentials in the registry in the targeted host. Registry can contain several sensitive information like username and credentials that can be used for privilege escalation, persistence or even in lateral movement. This Anomaly detection can be a good pivot to detect a suspicious process querying a registry related to password or private keys.", user="Administrator" 1686748292, search_name="ESCU - Windows Credentials in Registry Reg Query - Rule", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1552.002\",\"T1552\"],\"nist\":[\"DE.AE\"]}", annotations._all="Windows Post-Exploitation", annotations._all="DE.AE", annotations._all="Prestige Ransomware", annotations._all="Exploitation", annotations._all="T1552.002", annotations._all="T1552", annotations._all="CIS 10", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1552.002", annotations.mitre_attack="T1552", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:36", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748284.469784000", lastTime="2023-06-14T13:04:36", original_file_name="unknown", parent_process="C:\\Windows\\System32\\cmd.exe", parent_process_guid="null", parent_process_name="cmd.exe", process="C:\\Windows\\System32\\reg.exe query HKCU\\Software\\SimonTatham\\PuTTY\\Sessions /s", process_guid="null", process_id="0x338", process_name="reg.exe", risk_message="reg query commandline C:\\Windows\\System32\\reg.exe query HKCU\\Software\\SimonTatham\\PuTTY\\Sessions /s in ar-win-dc.attackrange.local", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="25.0", savedsearch_description="The following analytic identifies a process command line related to the discovery of possible password or credentials in the registry. This technique is being abused by adversaries or post exploitation tools like winpeas to steal credentials in the registry in the targeted host. Registry can contain several sensitive information like username and credentials that can be used for privilege escalation, persistence or even in lateral movement. This Anomaly detection can be a good pivot to detect a suspicious process querying a registry related to password or private keys.", user="Administrator" 1686748292, search_name="ESCU - Windows Credentials in Registry Reg Query - Rule", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1552.002\",\"T1552\"],\"nist\":[\"DE.AE\"]}", annotations._all="Windows Post-Exploitation", annotations._all="DE.AE", annotations._all="Prestige Ransomware", annotations._all="Exploitation", annotations._all="T1552.002", annotations._all="T1552", annotations._all="CIS 10", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1552.002", annotations.mitre_attack="T1552", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:36", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748284.469784000", lastTime="2023-06-14T13:04:36", original_file_name="unknown", parent_process="C:\\Windows\\System32\\cmd.exe", parent_process_guid="null", parent_process_name="cmd.exe", process="C:\\Windows\\System32\\reg.exe query HKCU\\Software\\OpenSSH\\Agent\\Keys /s", process_guid="null", process_id="0x1994", process_name="reg.exe", risk_message="reg query commandline C:\\Windows\\System32\\reg.exe query HKCU\\Software\\OpenSSH\\Agent\\Keys /s in ar-win-dc.attackrange.local", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="25.0", savedsearch_description="The following analytic identifies a process command line related to the discovery of possible password or credentials in the registry. This technique is being abused by adversaries or post exploitation tools like winpeas to steal credentials in the registry in the targeted host. Registry can contain several sensitive information like username and credentials that can be used for privilege escalation, persistence or even in lateral movement. This Anomaly detection can be a good pivot to detect a suspicious process querying a registry related to password or private keys.", user="Administrator" 1686748292, search_name="ESCU - Windows Credentials in Registry Reg Query - Rule", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1552.002\",\"T1552\"],\"nist\":[\"DE.AE\"]}", annotations._all="Windows Post-Exploitation", annotations._all="DE.AE", annotations._all="Prestige Ransomware", annotations._all="Exploitation", annotations._all="T1552.002", annotations._all="T1552", annotations._all="CIS 10", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1552.002", annotations.mitre_attack="T1552", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:36", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748284.469784000", lastTime="2023-06-14T13:04:36", original_file_name="unknown", parent_process="C:\\Windows\\System32\\cmd.exe", parent_process_guid="null", parent_process_name="cmd.exe", process="C:\\Windows\\System32\\reg.exe query HKCU\\Software\\ORL\\WinVNC3\\Password", process_guid="null", process_id="0x1b54", process_name="reg.exe", risk_message="reg query commandline C:\\Windows\\System32\\reg.exe query HKCU\\Software\\ORL\\WinVNC3\\Password in ar-win-dc.attackrange.local", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="25.0", savedsearch_description="The following analytic identifies a process command line related to the discovery of possible password or credentials in the registry. This technique is being abused by adversaries or post exploitation tools like winpeas to steal credentials in the registry in the targeted host. Registry can contain several sensitive information like username and credentials that can be used for privilege escalation, persistence or even in lateral movement. This Anomaly detection can be a good pivot to detect a suspicious process querying a registry related to password or private keys.", user="Administrator" 1686748292, search_name="ESCU - Windows Credentials in Registry Reg Query - Rule", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1552.002\",\"T1552\"],\"nist\":[\"DE.AE\"]}", annotations._all="Windows Post-Exploitation", annotations._all="DE.AE", annotations._all="Prestige Ransomware", annotations._all="Exploitation", annotations._all="T1552.002", annotations._all="T1552", annotations._all="CIS 10", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1552.002", annotations.mitre_attack="T1552", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:36", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748284.469784000", lastTime="2023-06-14T13:04:36", original_file_name="reg.exe", parent_process="\"cmd.exe\" /s /k pushd \"C:\\Temp\"", parent_process_guid="{953948C6-BA8E-6489-C200-00000000F902}", parent_process_name="cmd.exe", process="reg query HKLM\\SYSTEM\\CurrentControlSet\\Services\\SNMP /s", process_guid="{953948C6-BAE4-6489-7A0C-00000000F902}", process_id="4776", process_name="reg.exe", risk_message="reg query commandline reg query HKLM\\SYSTEM\\CurrentControlSet\\Services\\SNMP /s in ar-win-dc.attackrange.local", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="25.0", savedsearch_description="The following analytic identifies a process command line related to the discovery of possible password or credentials in the registry. This technique is being abused by adversaries or post exploitation tools like winpeas to steal credentials in the registry in the targeted host. Registry can contain several sensitive information like username and credentials that can be used for privilege escalation, persistence or even in lateral movement. This Anomaly detection can be a good pivot to detect a suspicious process querying a registry related to password or private keys.", user="Administrator" 1686748292, search_name="ESCU - Windows Credentials in Registry Reg Query - Rule", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1552.002\",\"T1552\"],\"nist\":[\"DE.AE\"]}", annotations._all="Windows Post-Exploitation", annotations._all="DE.AE", annotations._all="Prestige Ransomware", annotations._all="Exploitation", annotations._all="T1552.002", annotations._all="T1552", annotations._all="CIS 10", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1552.002", annotations.mitre_attack="T1552", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:36", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748284.469784000", lastTime="2023-06-14T13:04:36", original_file_name="reg.exe", parent_process="\"cmd.exe\" /s /k pushd \"C:\\Temp\"", parent_process_guid="{953948C6-BA8E-6489-C200-00000000F902}", parent_process_name="cmd.exe", process="reg query HKEY_LOCAL_MACHINE\\SOFTWARE\\RealVNC\\WinVNC4 /v password", process_guid="{953948C6-BAE4-6489-770C-00000000F902}", process_id="6696", process_name="reg.exe", risk_message="reg query commandline reg query HKEY_LOCAL_MACHINE\\SOFTWARE\\RealVNC\\WinVNC4 /v password in ar-win-dc.attackrange.local", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="25.0", savedsearch_description="The following analytic identifies a process command line related to the discovery of possible password or credentials in the registry. This technique is being abused by adversaries or post exploitation tools like winpeas to steal credentials in the registry in the targeted host. Registry can contain several sensitive information like username and credentials that can be used for privilege escalation, persistence or even in lateral movement. This Anomaly detection can be a good pivot to detect a suspicious process querying a registry related to password or private keys.", user="Administrator" 1686748292, search_name="ESCU - Windows Credentials in Registry Reg Query - Rule", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1552.002\",\"T1552\"],\"nist\":[\"DE.AE\"]}", annotations._all="Windows Post-Exploitation", annotations._all="DE.AE", annotations._all="Prestige Ransomware", annotations._all="Exploitation", annotations._all="T1552.002", annotations._all="T1552", annotations._all="CIS 10", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1552.002", annotations.mitre_attack="T1552", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:36", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748284.469784000", lastTime="2023-06-14T13:04:36", original_file_name="reg.exe", parent_process="\"cmd.exe\" /s /k pushd \"C:\\Temp\"", parent_process_guid="{953948C6-BA8E-6489-C200-00000000F902}", parent_process_name="cmd.exe", process="reg query HKCU\\Software\\TightVNC\\Server", process_guid="{953948C6-BAE4-6489-7B0C-00000000F902}", process_id="6756", process_name="reg.exe", risk_message="reg query commandline reg query HKCU\\Software\\TightVNC\\Server in ar-win-dc.attackrange.local", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="25.0", savedsearch_description="The following analytic identifies a process command line related to the discovery of possible password or credentials in the registry. This technique is being abused by adversaries or post exploitation tools like winpeas to steal credentials in the registry in the targeted host. Registry can contain several sensitive information like username and credentials that can be used for privilege escalation, persistence or even in lateral movement. This Anomaly detection can be a good pivot to detect a suspicious process querying a registry related to password or private keys.", user="Administrator" 1686748292, search_name="ESCU - Windows Credentials in Registry Reg Query - Rule", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1552.002\",\"T1552\"],\"nist\":[\"DE.AE\"]}", annotations._all="Windows Post-Exploitation", annotations._all="DE.AE", annotations._all="Prestige Ransomware", annotations._all="Exploitation", annotations._all="T1552.002", annotations._all="T1552", annotations._all="CIS 10", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1552.002", annotations.mitre_attack="T1552", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:36", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748284.469784000", lastTime="2023-06-14T13:04:36", original_file_name="reg.exe", parent_process="\"cmd.exe\" /s /k pushd \"C:\\Temp\"", parent_process_guid="{953948C6-BA8E-6489-C200-00000000F902}", parent_process_name="cmd.exe", process="reg query HKCU\\Software\\SimonTatham\\PuTTY\\Sessions /s", process_guid="{953948C6-BAE4-6489-7C0C-00000000F902}", process_id="824", process_name="reg.exe", risk_message="reg query commandline reg query HKCU\\Software\\SimonTatham\\PuTTY\\Sessions /s in ar-win-dc.attackrange.local", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="25.0", savedsearch_description="The following analytic identifies a process command line related to the discovery of possible password or credentials in the registry. This technique is being abused by adversaries or post exploitation tools like winpeas to steal credentials in the registry in the targeted host. Registry can contain several sensitive information like username and credentials that can be used for privilege escalation, persistence or even in lateral movement. This Anomaly detection can be a good pivot to detect a suspicious process querying a registry related to password or private keys.", user="Administrator" 1686748292, search_name="ESCU - Windows Credentials in Registry Reg Query - Rule", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1552.002\",\"T1552\"],\"nist\":[\"DE.AE\"]}", annotations._all="Windows Post-Exploitation", annotations._all="DE.AE", annotations._all="Prestige Ransomware", annotations._all="Exploitation", annotations._all="T1552.002", annotations._all="T1552", annotations._all="CIS 10", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1552.002", annotations.mitre_attack="T1552", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:36", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748284.469784000", lastTime="2023-06-14T13:04:36", original_file_name="reg.exe", parent_process="\"cmd.exe\" /s /k pushd \"C:\\Temp\"", parent_process_guid="{953948C6-BA8E-6489-C200-00000000F902}", parent_process_name="cmd.exe", process="reg query HKCU\\Software\\OpenSSH\\Agent\\Keys /s", process_guid="{953948C6-BAE4-6489-7D0C-00000000F902}", process_id="6548", process_name="reg.exe", risk_message="reg query commandline reg query HKCU\\Software\\OpenSSH\\Agent\\Keys /s in ar-win-dc.attackrange.local", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="25.0", savedsearch_description="The following analytic identifies a process command line related to the discovery of possible password or credentials in the registry. This technique is being abused by adversaries or post exploitation tools like winpeas to steal credentials in the registry in the targeted host. Registry can contain several sensitive information like username and credentials that can be used for privilege escalation, persistence or even in lateral movement. This Anomaly detection can be a good pivot to detect a suspicious process querying a registry related to password or private keys.", user="Administrator" 1686748292, search_name="ESCU - Windows Credentials in Registry Reg Query - Rule", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1552.002\",\"T1552\"],\"nist\":[\"DE.AE\"]}", annotations._all="Windows Post-Exploitation", annotations._all="DE.AE", annotations._all="Prestige Ransomware", annotations._all="Exploitation", annotations._all="T1552.002", annotations._all="T1552", annotations._all="CIS 10", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1552.002", annotations.mitre_attack="T1552", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:36", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748284.469784000", lastTime="2023-06-14T13:04:36", original_file_name="reg.exe", parent_process="\"cmd.exe\" /s /k pushd \"C:\\Temp\"", parent_process_guid="{953948C6-BA8E-6489-C200-00000000F902}", parent_process_name="cmd.exe", process="reg query HKCU\\Software\\ORL\\WinVNC3\\Password", process_guid="{953948C6-BAE4-6489-760C-00000000F902}", process_id="6996", process_name="reg.exe", risk_message="reg query commandline reg query HKCU\\Software\\ORL\\WinVNC3\\Password in ar-win-dc.attackrange.local", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="25.0", savedsearch_description="The following analytic identifies a process command line related to the discovery of possible password or credentials in the registry. This technique is being abused by adversaries or post exploitation tools like winpeas to steal credentials in the registry in the targeted host. Registry can contain several sensitive information like username and credentials that can be used for privilege escalation, persistence or even in lateral movement. This Anomaly detection can be a good pivot to detect a suspicious process querying a registry related to password or private keys.", user="Administrator" 1686748269, search_name="ESCU - Windows Credentials from Password Stores Query - Rule", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1555\"],\"nist\":[\"DE.AE\"]}", annotations._all="Exploitation", annotations._all="T1555", annotations._all="DE.AE", annotations._all="Prestige Ransomware", annotations._all="Windows Post-Exploitation", annotations._all="CIS 10", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1555", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:31", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748264.000419000", lastTime="2023-06-14T13:04:31", original_file_name="unknown", parent_process="C:\\Windows\\System32\\cmd.exe", parent_process_guid="null", parent_process_name="cmd.exe", process="C:\\Windows\\System32\\cmdkey.exe /list", process_guid="null", process_id="0xb90", process_name="cmdkey.exe", risk_message="a process cmdkey.exe was executed in ar-win-dc.attackrange.local to display stored username and credentials.", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="25.0", savedsearch_description="The following analytic identifies a process execution of Windows OS cmdkey.exe tool. This tool is being abused or used by several post exploitation tool such as winpeas that being used by ransomware prestige to list stored user names, passwords or credentials in the targeted Windows OS host. This information can be used by the attacker to gain privilege escalation and persistence in the targeted hosts for further attacks.", user="Administrator" 1686748269, search_name="ESCU - Windows Credentials from Password Stores Query - Rule", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1555\"],\"nist\":[\"DE.AE\"]}", annotations._all="Exploitation", annotations._all="T1555", annotations._all="DE.AE", annotations._all="Prestige Ransomware", annotations._all="Windows Post-Exploitation", annotations._all="CIS 10", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1555", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:31", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748264.000419000", lastTime="2023-06-14T13:04:31", original_file_name="cmdkey.exe", parent_process="\"cmd.exe\" /s /k pushd \"C:\\Temp\"", parent_process_guid="{953948C6-BA8E-6489-C200-00000000F902}", parent_process_name="cmd.exe", process="cmdkey /list", process_guid="{953948C6-BADF-6489-580C-00000000F902}", process_id="2960", process_name="cmdkey.exe", risk_message="a process cmdkey.exe was executed in ar-win-dc.attackrange.local to display stored username and credentials.", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="25.0", savedsearch_description="The following analytic identifies a process execution of Windows OS cmdkey.exe tool. This tool is being abused or used by several post exploitation tool such as winpeas that being used by ransomware prestige to list stored user names, passwords or credentials in the targeted Windows OS host. This information can be used by the attacker to gain privilege escalation and persistence in the targeted hosts for further attacks.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:10", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:04:10", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO.0x1B[32m[*]0x1B[97m SERVICE VULNERABILITIES\"", parent_process_id="4264", parent_process_name="forfiles.exe", process="/C ECHO.\\x1B[32m[*]\\x1B[97m SERVICE VULNERABILITIES", process_id="6384", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:06", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:04:06", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO.0x1B[32m[*]0x1B[97m NETWORK\"", parent_process_id="5040", parent_process_name="forfiles.exe", process="/C ECHO.\\x1B[32m[*]\\x1B[97m NETWORK", process_id="5584", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:31", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:04:31", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO.0x1B[32m[*]0x1B[97m DLL HIJACKING in PATHenv variable\"", parent_process_id="4188", parent_process_name="forfiles.exe", process="/C ECHO.\\x1B[32m[*]\\x1B[97m DLL HIJACKING in PATHenv variable", process_id="2604", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:31", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:04:31", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO.0x1B[32m[*]0x1B[97m CREDENTIALS\"", parent_process_id="4796", parent_process_name="forfiles.exe", process="/C ECHO.\\x1B[32m[*]\\x1B[97m CREDENTIALS", process_id="4112", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:08", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:04:08", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO.0x1B[32m[*]0x1B[97m BASIC USER INFO\"", parent_process_id="1472", parent_process_name="forfiles.exe", process="/C ECHO.\\x1B[32m[*]\\x1B[97m BASIC USER INFO", process_id="5888", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:17", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:03:17", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO.0x1B[32m[*]0x1B[97m BASIC SYSTEM INFO\"", parent_process_id="6808", parent_process_name="forfiles.exe", process="/C ECHO.\\x1B[32m[*]\\x1B[97m BASIC SYSTEM INFO", process_id="7128", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:03", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:04:03", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m WSUS\"", parent_process_id="5540", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m WSUS", process_id="6392", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:31", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:04:31", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m WINDOWS VAULT\"", parent_process_id="6992", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m WINDOWS VAULT", process_id="4744", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:17", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:03:17", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m WINDOWS OS\"", parent_process_id="2580", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m WINDOWS OS", process_id="4464", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:07", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:04:07", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m WIFI\"", parent_process_id="6536", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m WIFI", process_id="4776", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:01", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:04:01", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m WEF Settings\"", parent_process_id="3260", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m WEF Settings", process_id="6536", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:01", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:04:01", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m WDigest?\"", parent_process_id="2268", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m WDigest?", process_id="8", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:32", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:04:32", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Unattended files\"", parent_process_id="6844", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m Unattended files", process_id="5676", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:08", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:04:08", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m USERS\"", parent_process_id="6704", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m USERS", process_id="6732", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:06", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:04:06", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m USED PORTS\"", parent_process_id="6916", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m USED PORTS", process_id="5076", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:25", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:04:25", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m UNQUOTED SERVICE PATHS\"", parent_process_id="6372", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m UNQUOTED SERVICE PATHS", process_id="4268", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:01", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:04:01", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m UAC Settings\"", parent_process_id="7020", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m UAC Settings", process_id="6692", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:10", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:04:10", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m SERVICE BINARY PERMISSIONS WITH WMIC and ICACLS\"", parent_process_id="4376", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m SERVICE BINARY PERMISSIONS WITH WMIC and ICACLS", process_id="596", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:32", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:04:32", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m SAM and SYSTEM backups\"", parent_process_id="7104", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m SAM and SYSTEM backups", process_id="5780", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:02", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:04:02", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Remote Desktop Credentials Manager\"", parent_process_id="6744", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m Remote Desktop Credentials Manager", process_id="5328", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:01", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:04:01", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Registered Anti-Virus(AV)\"", parent_process_id="6904", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m Registered Anti-Virus(AV)", process_id="5624", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:03", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:04:03", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m RUNNING PROCESSES\"", parent_process_id="6936", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m RUNNING PROCESSES", process_id="4828", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:05", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:04:05", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m RUN AT STARTUP\"", parent_process_id="2248", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m RUN AT STARTUP", process_id="4680", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:07", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:04:07", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m ROUTES\"", parent_process_id="6224", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m ROUTES", process_id="376", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:02", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:04:02", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m PowerShell settings\"", parent_process_id="2080", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m PowerShell settings", process_id="6136", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:01", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:04:01", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Number of cached creds\"", parent_process_id="4796", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m Number of cached creds", process_id="6736", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:32", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:04:32", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m McAffee SiteList.xml\"", parent_process_id="7084", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m McAffee SiteList.xml", process_id="6532", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:02", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:04:02", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m MOUNTED DISKS\"", parent_process_id="6352", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m MOUNTED DISKS", process_id="5984", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:01", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:04:01", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m LSA protection?\"", parent_process_id="4280", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m LSA protection?", process_id="4200", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:01", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:04:01", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m LAPS installed?\"", parent_process_id="5068", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m LAPS installed?", process_id="6928", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:09", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:04:09", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Kerberos Tickets\"", parent_process_id="5964", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m Kerberos Tickets", process_id="6760", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:06", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:04:06", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m INTERFACES\"", parent_process_id="5632", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m INTERFACES", process_id="5548", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:02", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:04:02", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m INSTALLED SOFTWARE\"", parent_process_id="6560", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m INSTALLED SOFTWARE", process_id="4864", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:07", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:04:07", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Hosts file\"", parent_process_id="3088", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m Hosts file", process_id="5028", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:09", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:04:09", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m GROUPS\"", parent_process_id="6692", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m GROUPS", process_id="7004", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:34", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:04:34", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m GPP Password\"", parent_process_id="7036", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m GPP Password", process_id="5588", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:36", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:04:36", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Files in registry that may contain credentials\"", parent_process_id="5768", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m Files in registry that may contain credentials", process_id="4464", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:06", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:04:06", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m FIREWALL\"", parent_process_id="7052", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m FIREWALL", process_id="6844", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:02", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:04:02", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m ENVIRONMENT\"", parent_process_id="4328", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m ENVIRONMENT", process_id="1820", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:32", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:04:32", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m DPAPI MASTER KEYS\"", parent_process_id="7076", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m DPAPI MASTER KEYS", process_id="6332", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:31", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:04:31", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m DPAPI MASTER KEYS\"", parent_process_id="6824", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m DPAPI MASTER KEYS", process_id="4328", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:07", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:04:07", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m DNS CACHE\"", parent_process_id="6972", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m DNS CACHE", process_id="5176", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:01", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:04:01", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m DATE and TIME\"", parent_process_id="6532", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m DATE and TIME", process_id="6888", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:01", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:04:01", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Credential Guard?\"", parent_process_id="4828", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m Credential Guard?", process_id="2812", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:35", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:04:35", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Cloud Credentials\"", parent_process_id="2248", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m Cloud Credentials", process_id="2580", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:08", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:04:08", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m CURRENT USER\"", parent_process_id="2088", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m CURRENT USER", process_id="5656", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:06", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:04:06", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m CURRENT SHARES\"", parent_process_id="3844", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m CURRENT SHARES", process_id="4568", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:09", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:04:09", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m CURRENT LOGGED USERS\"", parent_process_id="6136", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m CURRENT LOGGED USERS", process_id="5588", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:09", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:04:09", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m CURRENT CLIPBOARD\"", parent_process_id="6224", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m CURRENT CLIPBOARD", process_id="6700", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:11", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:04:11", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m CHECK IF YOU CAN MODIFY ANY SERVICE REGISTRY\"", parent_process_id="472", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m CHECK IF YOU CAN MODIFY ANY SERVICE REGISTRY", process_id="7036", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:01", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:04:01", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Audit Settings\"", parent_process_id="4724", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m Audit Settings", process_id="5856", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:36", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:04:36", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m AppCmd\"", parent_process_id="2776", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m AppCmd", process_id="5892", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:06", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:04:06", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m AlwaysInstallElevated?\"", parent_process_id="6920", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m AlwaysInstallElevated?", process_id="6896", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:07", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:04:07", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m ARP\"", parent_process_id="7080", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m ARP", process_id="5496", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:09", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:04:09", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m ADMINISTRATORS GROUPS\"", parent_process_id="6828", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m ADMINISTRATORS GROUPS", process_id="6988", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:16", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:03:16", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[41mWinPEAS should be used for authorized penetration testing and/or educational purposes only.0x1B[40;97m\"", parent_process_id="6252", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[41mWinPEAS should be used for authorized penetration testing and/or educational purposes only.\\x1B[40;97m", process_id="4832", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:17", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:03:17", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[41mUse it at your own networks and/or with the network owner's permission.0x1B[40;97m\"", parent_process_id="5852", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[41mUse it at your own networks and/or with the network owner's permission.\\x1B[40;97m", process_id="1820", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:17", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:03:17", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[41mAny misuse of this software will not be the responsibility of the author or of any other collaborator.0x1B[40;97m\"", parent_process_id="6372", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[41mAny misuse of this software will not be the responsibility of the author or of any other collaborator.\\x1B[40;97m", process_id="5976", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:16", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:03:16", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m......((((0x1B[92m(#################################(0x1B[32m .(((((((.0x1B[97m\"", parent_process_id="6964", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[32m......((((\\x1B[92m(#################################(\\x1B[32m .(((((((.\\x1B[97m", process_id="6988", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:16", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:03:16", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m....((((0x1B[92m(#####################################(0x1B[32m .((((((.0x1B[97m\"", parent_process_id="6836", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[32m....((((\\x1B[92m(#####################################(\\x1B[32m .((((((.\\x1B[97m", process_id="6908", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:16", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:03:16", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m..((0x1B[92m(##########0x1B[94m*********0x1B[97m/#@@@@@@@@@/0x1B[94m*************0x1B[32m,,..((((0x1B[97m\"", parent_process_id="6720", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[32m..((\\x1B[92m(##########\\x1B[94m*********\\x1B[97m/#@@@@@@@@@/\\x1B[94m*************\\x1B[32m,,..((((\\x1B[97m", process_id="5808", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:16", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:03:16", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m..((((0x1B[92m(#########################################(0x1B[32m..(((((.0x1B[97m\"", parent_process_id="600", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[32m..((((\\x1B[92m(#########################################(\\x1B[32m..(((((.\\x1B[97m", process_id="6832", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:16", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:03:16", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.(0x1B[92m(######*(#####((##################((######/(0x1B[94m********0x1B[32m..(0x1B[97m\"", parent_process_id="6688", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[32m.(\\x1B[92m(######*(#####((##################((######/(\\x1B[94m********\\x1B[32m..(\\x1B[97m", process_id="2268", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:16", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:03:16", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.(0x1B[92m(######(,.***.,(###################(..***(/0x1B[94m*********0x1B[32m..(0x1B[97m\"", parent_process_id="4596", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[32m.(\\x1B[92m(######(,.***.,(###################(..***(/\\x1B[94m*********\\x1B[32m..(\\x1B[97m", process_id="5580", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:16", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:03:16", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.(0x1B[92m(##################(/**********(################(0x1B[94m**0x1B[32m...(0x1B[97m\"", parent_process_id="6740", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[32m.(\\x1B[92m(##################(/**********(################(\\x1B[94m**\\x1B[32m...(\\x1B[97m", process_id="4112", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:16", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:03:16", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.(0x1B[92m(########################(/0x1B[94m************************0x1B[32m..*(0x1B[97m\"", parent_process_id="1088", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[32m.(\\x1B[92m(########################(/\\x1B[94m************************\\x1B[32m..*(\\x1B[97m", process_id="4756", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:16", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:03:16", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.(0x1B[92m(#############################(/0x1B[94m********************0x1B[32m.,(0x1B[97m\"", parent_process_id="4268", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[32m.(\\x1B[92m(#############################(/\\x1B[94m********************\\x1B[32m.,(\\x1B[97m", process_id="4280", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:16", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:03:16", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.(0x1B[92m(##################################(/0x1B[94m***************0x1B[32m..(0x1B[97m\"", parent_process_id="6392", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[32m.(\\x1B[92m(##################################(/\\x1B[94m***************\\x1B[32m..(\\x1B[97m", process_id="2488", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:16", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:03:16", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.(0x1B[92m(######################################(0x1B[94m************0x1B[32m..(0x1B[97m\"", parent_process_id="5740", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[32m.(\\x1B[92m(######################################(\\x1B[94m************\\x1B[32m..(\\x1B[97m", process_id="6936", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:16", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:03:16", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.((0x1B[92m(################(/0x1B[94m******0x1B[97m/@@@@@#0x1B[94m****************0x1B[32m.. /((0x1B[97m\"", parent_process_id="5844", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[32m.((\\x1B[92m(################(/\\x1B[94m******\\x1B[97m/@@@@@#\\x1B[94m****************\\x1B[32m.. /((\\x1B[97m", process_id="2068", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:16", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:03:16", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.((0x1B[92m(####################/*******(###################0x1B[32m.((((0x1B[97m\"", parent_process_id="6596", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[32m.((\\x1B[92m(####################/*******(###################\\x1B[32m.((((\\x1B[97m", process_id="6796", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:16", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:03:16", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.((((0x1B[92m(############################################/0x1B[32m /((0x1B[97m\"", parent_process_id="2460", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[32m.((((\\x1B[92m(############################################/\\x1B[32m /((\\x1B[97m", process_id="5840", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:16", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:03:16", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m,,.0x1B[92m.0x1B[94m**********************0x1B[97m@@@@@@@@@@(0x1B[94m***0x1B[92m,####0x1B[32m ../(((((0x1B[97m\"", parent_process_id="6132", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[32m,,.\\x1B[92m.\\x1B[94m**********************\\x1B[97m@@@@@@@@@@(\\x1B[94m***\\x1B[92m,####\\x1B[32m ../(((((\\x1B[97m", process_id="6332", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:15", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:03:15", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m,*/((((((((((((((((((/, 0x1B[92m.*//((//**,0x1B[32m .*((((((*0x1B[97m\"", parent_process_id="5496", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[32m,*/((((((((((((((((((/, \\x1B[92m.*//((//**,\\x1B[32m .*((((((*\\x1B[97m", process_id="6348", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:16", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:03:16", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m, ,0x1B[92m0x1B[94m**********************0x1B[97m#@@@@@#@@@@0x1B[94m*********0x1B[92m##0x1B[32m((/ /((((0x1B[97m\"", parent_process_id="6012", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[32m, ,\\x1B[92m\\x1B[94m**********************\\x1B[97m#@@@@@#@@@@\\x1B[94m*********\\x1B[92m##\\x1B[32m((/ /((((\\x1B[97m", process_id="2924", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:16", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:03:16", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m((((((.0x1B[92m.0x1B[94m******************0x1B[97m/@@@@@/0x1B[94m***0x1B[92m/######0x1B[32m /((((((0x1B[97m\"", parent_process_id="5028", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[32m((((((.\\x1B[92m.\\x1B[94m******************\\x1B[97m/@@@@@/\\x1B[94m***\\x1B[92m/######\\x1B[32m /((((((\\x1B[97m", process_id="4724", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:16", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:03:16", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m(((((((((. ,0x1B[92m(############################(0x1B[32m../(((((((((.0x1B[97m\"", parent_process_id="7056", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[32m(((((((((. ,\\x1B[92m(############################(\\x1B[32m../(((((((((.\\x1B[97m", process_id="7060", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:15", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:03:15", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m(((((((((((/* 0x1B[94m******************0x1B[32m/####### 0x1B[32m.(. ((((((0x1B[97m\"", parent_process_id="5176", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[32m(((((((((((/* \\x1B[94m******************\\x1B[32m/####### \\x1B[32m.(. ((((((\\x1B[97m", process_id="4660", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:15", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:03:15", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m((((((((((((((((* 0x1B[94m*****0x1B[32m,,,/########## 0x1B[32m.(* ,((((((0x1B[97m\"", parent_process_id="6208", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[32m((((((((((((((((* \\x1B[94m*****\\x1B[32m,,,/########## \\x1B[32m.(* ,((((((\\x1B[97m", process_id="6380", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:15", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:03:15", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m,/*,..*(((((((((((((((((((((((((((((((((,0x1B[97m\"", parent_process_id="7144", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[32m,/*,..*(((((((((((((((((((((((((((((((((,\\x1B[97m", process_id="2604", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:16", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:03:16", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m(((((((((/, 0x1B[92m,####################(0x1B[32m/..((((((((((.0x1B[97m\"", parent_process_id="7084", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[32m(((((((((/, \\x1B[92m,####################(\\x1B[32m/..((((((((((.\\x1B[97m", process_id="3668", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:15", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:03:15", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m((,.,/((((((((((((((((((((/, */0x1B[97m\"", parent_process_id="3444", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[32m((,.,/((((((((((((((((((((/, */\\x1B[97m", process_id="6748", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:16", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:03:16", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m(((((((((/,. 0x1B[92m,*//////*,.0x1B[32m ./(((((((((((.0x1B[97m\"", parent_process_id="5980", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[32m(((((((((/,. \\x1B[92m,*//////*,.\\x1B[32m ./(((((((((((.\\x1B[97m", process_id="300", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:16", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:03:16", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m(((((((((((((((((((((((((((/0x1B[97m\"", parent_process_id="4780", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[32m(((((((((((((((((((((((((((/\\x1B[97m", process_id="7140", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:10", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:04:10", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO.0x1B[32m[*]0x1B[97m SERVICE VULNERABILITIES\"", parent_process_id="7088", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO.0x1B[32m[*]0x1B[97m SERVICE VULNERABILITIES\"", process_id="4264", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:06", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:04:06", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO.0x1B[32m[*]0x1B[97m NETWORK\"", parent_process_id="5228", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO.0x1B[32m[*]0x1B[97m NETWORK\"", process_id="5040", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:31", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:04:31", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO.0x1B[32m[*]0x1B[97m DLL HIJACKING in PATHenv variable\"", parent_process_id="6368", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO.0x1B[32m[*]0x1B[97m DLL HIJACKING in PATHenv variable\"", process_id="4188", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:31", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:04:31", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO.0x1B[32m[*]0x1B[97m CREDENTIALS\"", parent_process_id="6392", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO.0x1B[32m[*]0x1B[97m CREDENTIALS\"", process_id="4796", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:07", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:04:07", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO.0x1B[32m[*]0x1B[97m BASIC USER INFO\"", parent_process_id="6696", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO.0x1B[32m[*]0x1B[97m BASIC USER INFO\"", process_id="1472", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:17", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:03:17", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO.0x1B[32m[*]0x1B[97m BASIC SYSTEM INFO\"", parent_process_id="4660", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO.0x1B[32m[*]0x1B[97m BASIC SYSTEM INFO\"", process_id="6808", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:03", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:04:03", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m WSUS\"", parent_process_id="6896", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m WSUS\"", process_id="5540", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:31", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:04:31", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m WINDOWS VAULT\"", parent_process_id="3572", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m WINDOWS VAULT\"", process_id="6992", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:17", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:03:17", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m WINDOWS OS\"", parent_process_id="4724", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m WINDOWS OS\"", process_id="2580", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:07", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:04:07", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m WIFI\"", parent_process_id="5808", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m WIFI\"", process_id="6536", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:01", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:04:01", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m WEF Settings\"", parent_process_id="4264", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m WEF Settings\"", process_id="3260", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:01", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:04:01", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m WDigest?\"", parent_process_id="2960", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m WDigest?\"", process_id="2268", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:32", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:04:32", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Unattended files\"", parent_process_id="6088", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Unattended files\"", process_id="6844", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:08", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:04:08", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m USERS\"", parent_process_id="5544", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m USERS\"", process_id="6704", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:06", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:04:06", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m USED PORTS\"", parent_process_id="6828", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m USED PORTS\"", process_id="6916", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:25", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:04:25", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m UNQUOTED SERVICE PATHS\"", parent_process_id="6640", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m UNQUOTED SERVICE PATHS\"", process_id="6372", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:01", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:04:01", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m UAC Settings\"", parent_process_id="600", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m UAC Settings\"", process_id="7020", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:10", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:04:10", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m SERVICE BINARY PERMISSIONS WITH WMIC and ICACLS\"", parent_process_id="6572", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m SERVICE BINARY PERMISSIONS WITH WMIC and ICACLS\"", process_id="4376", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:32", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:04:32", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m SAM and SYSTEM backups\"", parent_process_id="5836", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m SAM and SYSTEM backups\"", process_id="7104", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:02", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:04:02", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Remote Desktop Credentials Manager\"", parent_process_id="4612", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Remote Desktop Credentials Manager\"", process_id="6744", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:01", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:04:01", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Registered Anti-Virus(AV)\"", parent_process_id="6908", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Registered Anti-Virus(AV)\"", process_id="6904", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:03", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:04:03", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m RUNNING PROCESSES\"", parent_process_id="5736", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m RUNNING PROCESSES\"", process_id="6936", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:05", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:04:05", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m RUN AT STARTUP\"", parent_process_id="5496", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m RUN AT STARTUP\"", process_id="2248", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:07", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:04:07", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m ROUTES\"", parent_process_id="7036", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m ROUTES\"", process_id="6224", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:02", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:04:02", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m PowerShell settings\"", parent_process_id="6768", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m PowerShell settings\"", process_id="2080", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:01", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:04:01", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Number of cached creds\"", parent_process_id="4804", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Number of cached creds\"", process_id="4796", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:32", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:04:32", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m McAffee SiteList.xml\"", parent_process_id="7156", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m McAffee SiteList.xml\"", process_id="7084", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:02", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:04:02", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m MOUNTED DISKS\"", parent_process_id="6376", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m MOUNTED DISKS\"", process_id="6352", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:01", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:04:01", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m LSA protection?\"", parent_process_id="6932", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m LSA protection?\"", process_id="4280", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:01", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:04:01", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m LAPS installed?\"", parent_process_id="5540", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m LAPS installed?\"", process_id="5068", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:09", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:04:09", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Kerberos Tickets\"", parent_process_id="5980", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Kerberos Tickets\"", process_id="5964", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:06", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:04:06", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m INTERFACES\"", parent_process_id="5240", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m INTERFACES\"", process_id="5632", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:02", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:04:02", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m INSTALLED SOFTWARE\"", parent_process_id="7024", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m INSTALLED SOFTWARE\"", process_id="6560", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:07", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:04:07", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Hosts file\"", parent_process_id="6656", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Hosts file\"", process_id="3088", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:09", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:04:09", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m GROUPS\"", parent_process_id="5632", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m GROUPS\"", process_id="6692", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:34", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:04:34", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m GPP Password\"", parent_process_id="5496", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m GPP Password\"", process_id="7036", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:36", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:04:36", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Files in registry that may contain credentials\"", parent_process_id="5656", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Files in registry that may contain credentials\"", process_id="5768", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:06", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:04:06", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m FIREWALL\"", parent_process_id="6456", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m FIREWALL\"", process_id="7052", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:02", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:04:02", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m ENVIRONMENT\"", parent_process_id="6892", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m ENVIRONMENT\"", process_id="4328", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:32", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:04:32", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m DPAPI MASTER KEYS\"", parent_process_id="6764", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m DPAPI MASTER KEYS\"", process_id="7076", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:31", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:04:31", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m DPAPI MASTER KEYS\"", parent_process_id="8", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m DPAPI MASTER KEYS\"", process_id="6824", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:07", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:04:07", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m DNS CACHE\"", parent_process_id="4808", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m DNS CACHE\"", process_id="6972", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:01", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:04:01", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m DATE and TIME\"", parent_process_id="6808", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m DATE and TIME\"", process_id="6532", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:01", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:04:01", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Credential Guard?\"", parent_process_id="5648", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Credential Guard?\"", process_id="4828", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:35", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:04:35", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Cloud Credentials\"", parent_process_id="5316", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Cloud Credentials\"", process_id="2248", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:08", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:04:08", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m CURRENT USER\"", parent_process_id="6924", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m CURRENT USER\"", process_id="2088", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:06", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:04:06", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m CURRENT SHARES\"", parent_process_id="6856", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m CURRENT SHARES\"", process_id="3844", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:09", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:04:09", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m CURRENT LOGGED USERS\"", parent_process_id="3792", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m CURRENT LOGGED USERS\"", process_id="6136", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:09", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:04:09", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m CURRENT CLIPBOARD\"", parent_process_id="2944", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m CURRENT CLIPBOARD\"", process_id="6224", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:11", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:04:11", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m CHECK IF YOU CAN MODIFY ANY SERVICE REGISTRY\"", parent_process_id="6376", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m CHECK IF YOU CAN MODIFY ANY SERVICE REGISTRY\"", process_id="472", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:01", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:04:01", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Audit Settings\"", parent_process_id="5808", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Audit Settings\"", process_id="4724", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:36", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:04:36", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m AppCmd\"", parent_process_id="5116", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m AppCmd\"", process_id="2776", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:06", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:04:06", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m AlwaysInstallElevated?\"", parent_process_id="4200", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m AlwaysInstallElevated?\"", process_id="6920", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:07", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:04:07", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m ARP\"", parent_process_id="528", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m ARP\"", process_id="7080", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:09", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:04:09", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m ADMINISTRATORS GROUPS\"", parent_process_id="6012", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m ADMINISTRATORS GROUPS\"", process_id="6828", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:16", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:03:16", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[41mWinPEAS should be used for authorized penetration testing and/or educational purposes only.0x1B[40;97m\"", parent_process_id="7132", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[41mWinPEAS should be used for authorized penetration testing and/or educational purposes only.0x1B[40;97m\"", process_id="6252", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:17", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:03:17", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[41mUse it at your own networks and/or with the network owner's permission.0x1B[40;97m\"", parent_process_id="5832", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[41mUse it at your own networks and/or with the network owner's permission.0x1B[40;97m\"", process_id="5852", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:17", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:03:17", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[41mAny misuse of this software will not be the responsibility of the author or of any other collaborator.0x1B[40;97m\"", parent_process_id="4664", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[41mAny misuse of this software will not be the responsibility of the author or of any other collaborator.0x1B[40;97m\"", process_id="6372", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:16", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:03:16", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m......((((0x1B[92m(#################################(0x1B[32m .(((((((.0x1B[97m\"", parent_process_id="6968", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m......((((0x1B[92m(#################################(0x1B[32m .(((((((.0x1B[97m\"", process_id="6964", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:16", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:03:16", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m....((((0x1B[92m(#####################################(0x1B[32m .((((((.0x1B[97m\"", parent_process_id="7004", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m....((((0x1B[92m(#####################################(0x1B[32m .((((((.0x1B[97m\"", process_id="6836", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:16", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:03:16", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m..((0x1B[92m(##########0x1B[94m*********0x1B[97m/#@@@@@@@@@/0x1B[94m*************0x1B[32m,,..((((0x1B[97m\"", parent_process_id="6612", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m..((0x1B[92m(##########0x1B[94m*********0x1B[97m/#@@@@@@@@@/0x1B[94m*************0x1B[32m,,..((((0x1B[97m\"", process_id="6720", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:16", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:03:16", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m..((((0x1B[92m(#########################################(0x1B[32m..(((((.0x1B[97m\"", parent_process_id="5072", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m..((((0x1B[92m(#########################################(0x1B[32m..(((((.0x1B[97m\"", process_id="600", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:16", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:03:16", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.(0x1B[92m(######*(#####((##################((######/(0x1B[94m********0x1B[32m..(0x1B[97m\"", parent_process_id="5544", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.(0x1B[92m(######*(#####((##################((######/(0x1B[94m********0x1B[32m..(0x1B[97m\"", process_id="6688", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:16", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:03:16", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.(0x1B[92m(######(,.***.,(###################(..***(/0x1B[94m*********0x1B[32m..(0x1B[97m\"", parent_process_id="5392", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.(0x1B[92m(######(,.***.,(###################(..***(/0x1B[94m*********0x1B[32m..(0x1B[97m\"", process_id="4596", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:16", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:03:16", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.(0x1B[92m(##################(/**********(################(0x1B[94m**0x1B[32m...(0x1B[97m\"", parent_process_id="6736", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.(0x1B[92m(##################(/**********(################(0x1B[94m**0x1B[32m...(0x1B[97m\"", process_id="6740", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:16", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:03:16", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.(0x1B[92m(########################(/0x1B[94m************************0x1B[32m..*(0x1B[97m\"", parent_process_id="7008", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.(0x1B[92m(########################(/0x1B[94m************************0x1B[32m..*(0x1B[97m\"", process_id="1088", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:16", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:03:16", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.(0x1B[92m(#############################(/0x1B[94m********************0x1B[32m.,(0x1B[97m\"", parent_process_id="4192", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.(0x1B[92m(#############################(/0x1B[94m********************0x1B[32m.,(0x1B[97m\"", process_id="4268", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:16", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:03:16", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.(0x1B[92m(##################################(/0x1B[94m***************0x1B[32m..(0x1B[97m\"", parent_process_id="5148", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.(0x1B[92m(##################################(/0x1B[94m***************0x1B[32m..(0x1B[97m\"", process_id="6392", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:16", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:03:16", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.(0x1B[92m(######################################(0x1B[94m************0x1B[32m..(0x1B[97m\"", parent_process_id="2812", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.(0x1B[92m(######################################(0x1B[94m************0x1B[32m..(0x1B[97m\"", process_id="5740", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:16", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:03:16", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.((0x1B[92m(################(/0x1B[94m******0x1B[97m/@@@@@#0x1B[94m****************0x1B[32m.. /((0x1B[97m\"", parent_process_id="5828", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.((0x1B[92m(################(/0x1B[94m******0x1B[97m/@@@@@#0x1B[94m****************0x1B[32m.. /((0x1B[97m\"", process_id="5844", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:16", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:03:16", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.((0x1B[92m(####################/*******(###################0x1B[32m.((((0x1B[97m\"", parent_process_id="7020", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.((0x1B[92m(####################/*******(###################0x1B[32m.((((0x1B[97m\"", process_id="6596", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:16", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:03:16", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.((((0x1B[92m(############################################/0x1B[32m /((0x1B[97m\"", parent_process_id="624", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.((((0x1B[92m(############################################/0x1B[32m /((0x1B[97m\"", process_id="2460", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:16", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:03:16", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m,,.0x1B[92m.0x1B[94m**********************0x1B[97m@@@@@@@@@@(0x1B[94m***0x1B[92m,####0x1B[32m ../(((((0x1B[97m\"", parent_process_id="6924", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m,,.0x1B[92m.0x1B[94m**********************0x1B[97m@@@@@@@@@@(0x1B[94m***0x1B[92m,####0x1B[32m ../(((((0x1B[97m\"", process_id="6132", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:15", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:03:15", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m,*/((((((((((((((((((/, 0x1B[92m.*//((//**,0x1B[32m .*((((((*0x1B[97m\"", parent_process_id="4664", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m,*/((((((((((((((((((/, 0x1B[92m.*//((//**,0x1B[32m .*((((((*0x1B[97m\"", process_id="5496", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:16", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:03:16", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m, ,0x1B[92m0x1B[94m**********************0x1B[97m#@@@@@#@@@@0x1B[94m*********0x1B[92m##0x1B[32m((/ /((((0x1B[97m\"", parent_process_id="6564", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m, ,0x1B[92m0x1B[94m**********************0x1B[97m#@@@@@#@@@@0x1B[94m*********0x1B[92m##0x1B[32m((/ /((((0x1B[97m\"", process_id="6012", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:15", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:03:15", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m((((((.0x1B[92m.0x1B[94m******************0x1B[97m/@@@@@/0x1B[94m***0x1B[92m/######0x1B[32m /((((((0x1B[97m\"", parent_process_id="5040", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m((((((.0x1B[92m.0x1B[94m******************0x1B[97m/@@@@@/0x1B[94m***0x1B[92m/######0x1B[32m /((((((0x1B[97m\"", process_id="5028", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:16", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:03:16", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m(((((((((. ,0x1B[92m(############################(0x1B[32m../(((((((((.0x1B[97m\"", parent_process_id="7048", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m(((((((((. ,0x1B[92m(############################(0x1B[32m../(((((((((.0x1B[97m\"", process_id="7056", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:15", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:03:15", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m(((((((((((/* 0x1B[94m******************0x1B[32m/####### 0x1B[32m.(. ((((((0x1B[97m\"", parent_process_id="4508", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m(((((((((((/* 0x1B[94m******************0x1B[32m/####### 0x1B[32m.(. ((((((0x1B[97m\"", process_id="5176", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:15", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:03:15", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m((((((((((((((((* 0x1B[94m*****0x1B[32m,,,/########## 0x1B[32m.(* ,((((((0x1B[97m\"", parent_process_id="5832", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m((((((((((((((((* 0x1B[94m*****0x1B[32m,,,/########## 0x1B[32m.(* ,((((((0x1B[97m\"", process_id="6208", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:15", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:03:15", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m,/*,..*(((((((((((((((((((((((((((((((((,0x1B[97m\"", parent_process_id="7132", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m,/*,..*(((((((((((((((((((((((((((((((((,0x1B[97m\"", process_id="7144", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:16", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:03:16", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m(((((((((/, 0x1B[92m,####################(0x1B[32m/..((((((((((.0x1B[97m\"", parent_process_id="528", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m(((((((((/, 0x1B[92m,####################(0x1B[32m/..((((((((((.0x1B[97m\"", process_id="7084", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:15", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:03:15", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m((,.,/((((((((((((((((((((/, */0x1B[97m\"", parent_process_id="3660", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m((,.,/((((((((((((((((((((/, */0x1B[97m\"", process_id="3444", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:16", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:03:16", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m(((((((((/,. 0x1B[92m,*//////*,.0x1B[32m ./(((((((((((.0x1B[97m\"", parent_process_id="472", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m(((((((((/,. 0x1B[92m,*//////*,.0x1B[32m ./(((((((((((.0x1B[97m\"", process_id="5980", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748256, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="T1202", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:16", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748251.390786000", lastTime="2023-06-14T13:03:16", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m(((((((((((((((((((((((((((/0x1B[97m\"", parent_process_id="3660", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m(((((((((((((((((((((((((((/0x1B[97m\"", process_id="4780", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686748237, search_name="ESCU - Windows Cached Domain Credentials Reg Query - Rule", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":30,\"impact\":30,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1003.005\",\"T1003\"],\"nist\":[\"DE.AE\"]}", annotations._all="DE.AE", annotations._all="Windows Post-Exploitation", annotations._all="T1003", annotations._all="Prestige Ransomware", annotations._all="T1003.005", annotations._all="Exploitation", annotations._all="CIS 10", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1003.005", annotations.mitre_attack="T1003", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:01", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748231.529752000", lastTime="2023-06-14T13:04:01", original_file_name="unknown", parent_process="C:\\Windows\\System32\\cmd.exe", parent_process_guid="null", parent_process_name="cmd.exe", process="C:\\Windows\\System32\\reg.exe query \"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\" /v CACHEDLOGONSCOUNT", process_guid="null", process_id="0x1010", process_name="reg.exe", risk_message="a process with commandline C:\\Windows\\System32\\reg.exe query \"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\" /v CACHEDLOGONSCOUNT tries to retrieve cache domain credential logon count in ar-win-dc.attackrange.local", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="9.0", savedsearch_description="The following analytic identifies a process command line related to the discovery of cache domain credential logon count in the registry. This Technique was being abused by several post exploitation tool like Winpeas where it query CachedLogonsCount registry value in Winlogon registry. This value can be good information about the login caching setting on the Windows OS target host. A value of 0 means login caching is disable and values > 50 caches only 50 login attempts. By default all versions of Windows 10 save cached logins except Windows Server 2008.", user="Administrator" 1686748237, search_name="ESCU - Windows Cached Domain Credentials Reg Query - Rule", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":30,\"impact\":30,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1003.005\",\"T1003\"],\"nist\":[\"DE.AE\"]}", annotations._all="DE.AE", annotations._all="Windows Post-Exploitation", annotations._all="T1003", annotations._all="Prestige Ransomware", annotations._all="T1003.005", annotations._all="Exploitation", annotations._all="CIS 10", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1003.005", annotations.mitre_attack="T1003", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:01", info_max_time="1686748200.000000000", info_min_time="1686747600.000000000", info_search_time="1686748231.529752000", lastTime="2023-06-14T13:04:01", original_file_name="reg.exe", parent_process="\"cmd.exe\" /s /k pushd \"C:\\Temp\"", parent_process_guid="{953948C6-BA8E-6489-C200-00000000F902}", parent_process_name="cmd.exe", process="reg query \"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\" /v CACHEDLOGONSCOUNT", process_guid="{953948C6-BAC1-6489-E601-00000000F902}", process_id="4112", process_name="reg.exe", risk_message="a process with commandline reg query \"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\" /v CACHEDLOGONSCOUNT tries to retrieve cache domain credential logon count in ar-win-dc.attackrange.local", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="9.0", savedsearch_description="The following analytic identifies a process command line related to the discovery of cache domain credential logon count in the registry. This Technique was being abused by several post exploitation tool like Winpeas where it query CachedLogonsCount registry value in Winlogon registry. This value can be good information about the login caching setting on the Windows OS target host. A value of 0 means login caching is disable and values > 50 caches only 50 login attempts. By default all versions of Windows 10 save cached logins except Windows Server 2008.", user="Administrator" 1686748134, search_name="ESCU - Windows ClipBoard Data via Get-ClipBoard - Rule", Computer="ar-win-dc.attackrange.local", EventCode="4104", ScriptBlockText="Get-Clipboard", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1115\"],\"nist\":[\"DE.AE\"]}", annotations._all="Windows Post-Exploitation", annotations._all="T1115", annotations._all="Exploitation", annotations._all="Prestige Ransomware", annotations._all="CIS 10", annotations._all="DE.AE", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1115", annotations.nist="DE.AE", count="1", firstTime="2023-06-14T13:04:10", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686748130.666078000", lastTime="2023-06-14T13:04:10", risk_message="powershell script Get-Clipboard execute Get-Clipboard commandlet in $dest$", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="25.0", savedsearch_description="The following analytic identifies a powershell script command to retrieve clipboard data. This technique was seen in several post exploitation tools like WINPEAS to steal sensitive information that was saved in clipboard. Using the Get-Clipboard powershell commandlet, adversaries can be able collect data stored in clipboard that might be a copied user name, password or other sensitive information.", user_id="'S-1-5-21-647039874-1738661239-2692048096-500'" 1686748129, search_name="ESCU - Windows Private Keys Discovery - Rule", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1552.004\",\"T1552\"],\"nist\":[\"DE.AE\"]}", annotations._all="Prestige Ransomware", annotations._all="Windows Post-Exploitation", annotations._all="Exploitation", annotations._all="CIS 10", annotations._all="T1552", annotations._all="T1552.004", annotations._all="DE.AE", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1552.004", annotations.mitre_attack="T1552", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:36", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686748120.216884000", lastTime="2023-06-14T13:04:36", original_file_name="unknown", parent_process="C:\\Windows\\System32\\cmd.exe", parent_process_guid="null", parent_process_name="cmd.exe", process="C:\\Windows\\system32\\cmd.exe /S /D /c\" dir /s/b /A:-D RDCMan.settings == *.rdg == SCClient.exe == *_history == .sudo_as_admin_successful == .profile == *bashrc == httpd.conf == *.plan == .htpasswd == .git-credentials == *.rhosts == hosts.equiv == Dockerfile == docker-compose.yml == appcmd.exe == TypedURLs == TypedURLsTime == History == Bookmarks == Cookies == \"Login Data\" == places.sqlite == key3.db == key4.db == credentials == credentials.db == access_tokens.db == accessTokens.json == legacy_credentials == azureProfile.json == unattend.txt == access.log == error.log == *.gpg == *.pgp == *config*.php == elasticsearch.y*ml == kibana.y*ml == *.p12 == *.der == *.csr == *.cer == known_hosts == id_rsa == id_dsa == *.ovpn == anaconda-ks.cfg == hostapd.conf == rsyncd.conf == cesi.conf == supervisord.conf == tomcat-users.xml == *.kdbx == KeePass.config == Ntds.dit == SAM == SYSTEM == FreeSSHDservice.ini == sysprep.inf == sysprep.xml == unattend.xml == unattended.xml == *vnc*.ini == *vnc*.c*nf* == *vnc*.txt == *vnc*.xml == groups.xml == services.xml == scheduledtasks.xml == printers.xml == drives.xml == datasources.xml == php.ini == https.conf == https-xampp.conf == httpd.conf == my.ini == my.cnf == access.log == error.log == server.xml == SiteList.xml == ConsoleHost_history.txt == setupinfo == setupinfo.bak 2>nul\"", process_guid="null", process_id="0xfc0", process_name="cmd.exe", risk_message="a process with commandline C:\\Windows\\system32\\cmd.exe /S /D /c\" dir /s/b /A:-D RDCMan.settings == *.rdg == SCClient.exe == *_history == .sudo_as_admin_successful == .profile == *bashrc == httpd.conf == *.plan == .htpasswd == .git-credentials == *.rhosts == hosts.equiv == Dockerfile == docker-compose.yml == appcmd.exe == TypedURLs == TypedURLsTime == History == Bookmarks == Cookies == \"Login Data\" == places.sqlite == key3.db == key4.db == credentials == credentials.db == access_tokens.db == accessTokens.json == legacy_credentials == azureProfile.json == unattend.txt == access.log == error.log == *.gpg == *.pgp == *config*.php == elasticsearch.y*ml == kibana.y*ml == *.p12 == *.der == *.csr == *.cer == known_hosts == id_rsa == id_dsa == *.ovpn == anaconda-ks.cfg == hostapd.conf == rsyncd.conf == cesi.conf == supervisord.conf == tomcat-users.xml == *.kdbx == KeePass.config == Ntds.dit == SAM == SYSTEM == FreeSSHDservice.ini == sysprep.inf == sysprep.xml == unattend.xml == unattended.xml == *vnc*.ini == *vnc*.c*nf* == *vnc*.txt == *vnc*.xml == groups.xml == services.xml == scheduledtasks.xml == printers.xml == drives.xml == datasources.xml == php.ini == https.conf == https-xampp.conf == httpd.conf == my.ini == my.cnf == access.log == error.log == server.xml == SiteList.xml == ConsoleHost_history.txt == setupinfo == setupinfo.bak 2>nul\" that can retrieve information related to private keys in ar-win-dc.attackrange.local", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="25.0", savedsearch_description="The following analytic identifies a process command line that retrieves information related to private keys files. This technique was seen in several post exploitation tools like winpeas that are being used by Ransomware Prestige to search for private key certificates on the compromised host for insecurely stored credentials. This files can be used by adversaries to gain privileges, persistence or remote service authentication to collect more sensitive information. Some private keys required password for operation, so in this case adversaries may need to have that passphrase either via keylogging or brute force attack.", user="Administrator" 1686748129, search_name="ESCU - Windows Private Keys Discovery - Rule", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1552.004\",\"T1552\"],\"nist\":[\"DE.AE\"]}", annotations._all="Prestige Ransomware", annotations._all="Windows Post-Exploitation", annotations._all="Exploitation", annotations._all="CIS 10", annotations._all="T1552", annotations._all="T1552.004", annotations._all="DE.AE", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1552.004", annotations.mitre_attack="T1552", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:36", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686748120.216884000", lastTime="2023-06-14T13:04:36", original_file_name="Cmd.Exe", parent_process="\"cmd.exe\" /s /k pushd \"C:\\Temp\"", parent_process_guid="{953948C6-BA8E-6489-C200-00000000F902}", parent_process_name="cmd.exe", process="C:\\Windows\\system32\\cmd.exe /S /D /c\" dir /s/b /A:-D RDCMan.settings == *.rdg == SCClient.exe == *_history == .sudo_as_admin_successful == .profile == *bashrc == httpd.conf == *.plan == .htpasswd == .git-credentials == *.rhosts == hosts.equiv == Dockerfile == docker-compose.yml == appcmd.exe == TypedURLs == TypedURLsTime == History == Bookmarks == Cookies == \"Login Data\" == places.sqlite == key3.db == key4.db == credentials == credentials.db == access_tokens.db == accessTokens.json == legacy_credentials == azureProfile.json == unattend.txt == access.log == error.log == *.gpg == *.pgp == *config*.php == elasticsearch.y*ml == kibana.y*ml == *.p12 == *.der == *.csr == *.cer == known_hosts == id_rsa == id_dsa == *.ovpn == anaconda-ks.cfg == hostapd.conf == rsyncd.conf == cesi.conf == supervisord.conf == tomcat-users.xml == *.kdbx == KeePass.config == Ntds.dit == SAM == SYSTEM == FreeSSHDservice.ini == sysprep.inf == sysprep.xml == unattend.xml == unattended.xml == *vnc*.ini == *vnc*.c*nf* == *vnc*.txt == *vnc*.xml == groups.xml == services.xml == scheduledtasks.xml == printers.xml == drives.xml == datasources.xml == php.ini == https.conf == https-xampp.conf == httpd.conf == my.ini == my.cnf == access.log == error.log == server.xml == SiteList.xml == ConsoleHost_history.txt == setupinfo == setupinfo.bak 2>nul\"", process_guid="{953948C6-BAE4-6489-7E0C-00000000F902}", process_id="4032", process_name="cmd.exe", risk_message="a process with commandline C:\\Windows\\system32\\cmd.exe /S /D /c\" dir /s/b /A:-D RDCMan.settings == *.rdg == SCClient.exe == *_history == .sudo_as_admin_successful == .profile == *bashrc == httpd.conf == *.plan == .htpasswd == .git-credentials == *.rhosts == hosts.equiv == Dockerfile == docker-compose.yml == appcmd.exe == TypedURLs == TypedURLsTime == History == Bookmarks == Cookies == \"Login Data\" == places.sqlite == key3.db == key4.db == credentials == credentials.db == access_tokens.db == accessTokens.json == legacy_credentials == azureProfile.json == unattend.txt == access.log == error.log == *.gpg == *.pgp == *config*.php == elasticsearch.y*ml == kibana.y*ml == *.p12 == *.der == *.csr == *.cer == known_hosts == id_rsa == id_dsa == *.ovpn == anaconda-ks.cfg == hostapd.conf == rsyncd.conf == cesi.conf == supervisord.conf == tomcat-users.xml == *.kdbx == KeePass.config == Ntds.dit == SAM == SYSTEM == FreeSSHDservice.ini == sysprep.inf == sysprep.xml == unattend.xml == unattended.xml == *vnc*.ini == *vnc*.c*nf* == *vnc*.txt == *vnc*.xml == groups.xml == services.xml == scheduledtasks.xml == printers.xml == drives.xml == datasources.xml == php.ini == https.conf == https-xampp.conf == httpd.conf == my.ini == my.cnf == access.log == error.log == server.xml == SiteList.xml == ConsoleHost_history.txt == setupinfo == setupinfo.bak 2>nul\" that can retrieve information related to private keys in ar-win-dc.attackrange.local", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="25.0", savedsearch_description="The following analytic identifies a process command line that retrieves information related to private keys files. This technique was seen in several post exploitation tools like winpeas that are being used by Ransomware Prestige to search for private key certificates on the compromised host for insecurely stored credentials. This files can be used by adversaries to gain privileges, persistence or remote service authentication to collect more sensitive information. Some private keys required password for operation, so in this case adversaries may need to have that passphrase either via keylogging or brute force attack.", user="Administrator" 1686748105, search_name="ESCU - Windows Security Support Provider Reg Query - Rule", analyticstories="Prestige Ransomware", analyticstories="Sneaky Active Directory Persistence Tricks", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\",\"Sneaky Active Directory Persistence Tricks\"],\"cis20\":[\"CIS 10\"],\"confidence\":30,\"impact\":30,\"kill_chain_phases\":[\"Installation\",\"Exploitation\"],\"mitre_attack\":[\"T1547.005\",\"T1547\"],\"nist\":[\"DE.AE\"]}", annotations._all="T1547.005", annotations._all="CIS 10", annotations._all="DE.AE", annotations._all="Installation", annotations._all="Exploitation", annotations._all="Sneaky Active Directory Persistence Tricks", annotations._all="T1547", annotations._all="Windows Post-Exploitation", annotations._all="Prestige Ransomware", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.analytic_story="Sneaky Active Directory Persistence Tricks", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1547.005", annotations.mitre_attack="T1547", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:01", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686748100.311461000", lastTime="2023-06-14T13:04:01", original_file_name="unknown", parent_process="C:\\Windows\\System32\\cmd.exe", parent_process_guid="null", parent_process_name="cmd.exe", process="C:\\Windows\\System32\\reg.exe QUERY \"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\LSA\" /v RunAsPPL", process_guid="null", process_id="0x146c", process_name="reg.exe", risk_message="process with reg query command line C:\\Windows\\System32\\reg.exe QUERY \"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\LSA\" /v RunAsPPL in ar-win-dc.attackrange.local", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="9.0", savedsearch_description="The following analytic identifies a process command line related to the discovery of possible Security Support Providers in the registry. This technique is being abused by adversaries or post exploitation tools like winpeas to gather LSA protection and configuration in the registry in the targeted host. This registry entry can contain several information related to LSA that validates users for local and remote sign-ins and enforces local security policies. Understanding LSA protection may give a good information in accessing LSA content in memory which is commonly attack by adversaries and tool like mimikatz to scrape password hashes or clear plain text passwords.", user="Administrator" 1686748105, search_name="ESCU - Windows Security Support Provider Reg Query - Rule", analyticstories="Prestige Ransomware", analyticstories="Sneaky Active Directory Persistence Tricks", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\",\"Sneaky Active Directory Persistence Tricks\"],\"cis20\":[\"CIS 10\"],\"confidence\":30,\"impact\":30,\"kill_chain_phases\":[\"Installation\",\"Exploitation\"],\"mitre_attack\":[\"T1547.005\",\"T1547\"],\"nist\":[\"DE.AE\"]}", annotations._all="T1547.005", annotations._all="CIS 10", annotations._all="DE.AE", annotations._all="Installation", annotations._all="Exploitation", annotations._all="Sneaky Active Directory Persistence Tricks", annotations._all="T1547", annotations._all="Windows Post-Exploitation", annotations._all="Prestige Ransomware", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.analytic_story="Sneaky Active Directory Persistence Tricks", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1547.005", annotations.mitre_attack="T1547", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:01", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686748100.311461000", lastTime="2023-06-14T13:04:01", original_file_name="unknown", parent_process="C:\\Windows\\System32\\cmd.exe", parent_process_guid="null", parent_process_name="cmd.exe", process="C:\\Windows\\System32\\reg.exe QUERY \"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\LSA\" /v LsaCfgFlags", process_guid="null", process_id="0x854", process_name="reg.exe", risk_message="process with reg query command line C:\\Windows\\System32\\reg.exe QUERY \"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\LSA\" /v LsaCfgFlags in ar-win-dc.attackrange.local", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="9.0", savedsearch_description="The following analytic identifies a process command line related to the discovery of possible Security Support Providers in the registry. This technique is being abused by adversaries or post exploitation tools like winpeas to gather LSA protection and configuration in the registry in the targeted host. This registry entry can contain several information related to LSA that validates users for local and remote sign-ins and enforces local security policies. Understanding LSA protection may give a good information in accessing LSA content in memory which is commonly attack by adversaries and tool like mimikatz to scrape password hashes or clear plain text passwords.", user="Administrator" 1686748105, search_name="ESCU - Windows Security Support Provider Reg Query - Rule", analyticstories="Prestige Ransomware", analyticstories="Sneaky Active Directory Persistence Tricks", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\",\"Sneaky Active Directory Persistence Tricks\"],\"cis20\":[\"CIS 10\"],\"confidence\":30,\"impact\":30,\"kill_chain_phases\":[\"Installation\",\"Exploitation\"],\"mitre_attack\":[\"T1547.005\",\"T1547\"],\"nist\":[\"DE.AE\"]}", annotations._all="T1547.005", annotations._all="CIS 10", annotations._all="DE.AE", annotations._all="Installation", annotations._all="Exploitation", annotations._all="Sneaky Active Directory Persistence Tricks", annotations._all="T1547", annotations._all="Windows Post-Exploitation", annotations._all="Prestige Ransomware", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.analytic_story="Sneaky Active Directory Persistence Tricks", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1547.005", annotations.mitre_attack="T1547", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:01", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686748100.311461000", lastTime="2023-06-14T13:04:01", original_file_name="reg.exe", parent_process="\"cmd.exe\" /s /k pushd \"C:\\Temp\"", parent_process_guid="{953948C6-BA8E-6489-C200-00000000F902}", parent_process_name="cmd.exe", process="REG QUERY \"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\LSA\" /v RunAsPPL", process_guid="{953948C6-BAC1-6489-DA01-00000000F902}", process_id="5228", process_name="reg.exe", risk_message="process with reg query command line REG QUERY \"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\LSA\" /v RunAsPPL in ar-win-dc.attackrange.local", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="9.0", savedsearch_description="The following analytic identifies a process command line related to the discovery of possible Security Support Providers in the registry. This technique is being abused by adversaries or post exploitation tools like winpeas to gather LSA protection and configuration in the registry in the targeted host. This registry entry can contain several information related to LSA that validates users for local and remote sign-ins and enforces local security policies. Understanding LSA protection may give a good information in accessing LSA content in memory which is commonly attack by adversaries and tool like mimikatz to scrape password hashes or clear plain text passwords.", user="Administrator" 1686748105, search_name="ESCU - Windows Security Support Provider Reg Query - Rule", analyticstories="Prestige Ransomware", analyticstories="Sneaky Active Directory Persistence Tricks", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\",\"Sneaky Active Directory Persistence Tricks\"],\"cis20\":[\"CIS 10\"],\"confidence\":30,\"impact\":30,\"kill_chain_phases\":[\"Installation\",\"Exploitation\"],\"mitre_attack\":[\"T1547.005\",\"T1547\"],\"nist\":[\"DE.AE\"]}", annotations._all="T1547.005", annotations._all="CIS 10", annotations._all="DE.AE", annotations._all="Installation", annotations._all="Exploitation", annotations._all="Sneaky Active Directory Persistence Tricks", annotations._all="T1547", annotations._all="Windows Post-Exploitation", annotations._all="Prestige Ransomware", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.analytic_story="Sneaky Active Directory Persistence Tricks", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1547.005", annotations.mitre_attack="T1547", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:01", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686748100.311461000", lastTime="2023-06-14T13:04:01", original_file_name="reg.exe", parent_process="\"cmd.exe\" /s /k pushd \"C:\\Temp\"", parent_process_guid="{953948C6-BA8E-6489-C200-00000000F902}", parent_process_name="cmd.exe", process="REG QUERY \"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\LSA\" /v LsaCfgFlags", process_guid="{953948C6-BAC1-6489-DE01-00000000F902}", process_id="2132", process_name="reg.exe", risk_message="process with reg query command line REG QUERY \"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\LSA\" /v LsaCfgFlags in ar-win-dc.attackrange.local", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="9.0", savedsearch_description="The following analytic identifies a process command line related to the discovery of possible Security Support Providers in the registry. This technique is being abused by adversaries or post exploitation tools like winpeas to gather LSA protection and configuration in the registry in the targeted host. This registry entry can contain several information related to LSA that validates users for local and remote sign-ins and enforces local security policies. Understanding LSA protection may give a good information in accessing LSA content in memory which is commonly attack by adversaries and tool like mimikatz to scrape password hashes or clear plain text passwords.", user="Administrator" 1686748070, search_name="ESCU - Create or delete windows shares using net exe - Rule", analyticstories="CISA AA22-277A", analyticstories="Hidden Cobra Malware", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Hidden Cobra Malware\",\"CISA AA22-277A\",\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1070\",\"T1070.005\"],\"nist\":[\"DE.CM\"]}", annotations._all="Windows Post-Exploitation", annotations._all="CISA AA22-277A", annotations._all="CIS 10", annotations._all="Exploitation", annotations._all="Prestige Ransomware", annotations._all="T1070.005", annotations._all="DE.CM", annotations._all="T1070", annotations._all="Hidden Cobra Malware", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Hidden Cobra Malware", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1070", annotations.mitre_attack="T1070.005", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:06", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686748064.365324000", lastTime="2023-06-14T13:04:06", original_file_name="net.exe", parent_process="\"cmd.exe\" /s /k pushd \"C:\\Temp\"", process="net share", process_name="net.exe", risk_message="An instance of $parent_process_name$ spawning net.exe was identified on endpoint ar-win-dc.attackrange.local by user Administrator enumerating Windows file shares.", risk_object="net.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="This search looks for the creation or deletion of hidden shares using net.exe.", user="Administrator" 1686747840, search_name="ESCU - Excessive Usage Of Cacls App - Rule", orig_time="1686747840", analyticstories="Azorult", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", analyticstories="XMRig", annotations="{\"analytic_story\":[\"XMRig\",\"Azorult\",\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":100,\"impact\":80,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1222\"],\"nist\":[\"DE.AE\"]}", annotations._all="T1222", annotations._all="Exploitation", annotations._all="Prestige Ransomware", annotations._all="XMRig", annotations._all="CIS 10", annotations._all="Azorult", annotations._all="DE.AE", annotations._all="Windows Post-Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="XMRig", annotations.analytic_story="Azorult", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1222", annotations.nist="DE.AE", count="88", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:00", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686748062.019840000", lastTime="2023-06-14T13:04:00", parent_process="C:\\Windows\\System32\\cmd.exe", parent_process_name="cmd.exe", process="C:\\Windows\\System32\\icacls.exe \"C:\\Documents and Settings\\Administrator\\Start Menu\\Programs\\Startup\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Documents and Settings\\Administrator\\Start Menu\\Programs\\Startup\\*\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\*\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files (x86)\\Mozilla Maintenance Service\\maintenanceservice.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Amazon\\SSM\\\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Amazon\\SSM\\amazon-ssm-agent.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Amazon\\SSM\\ssm-agent-worker.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Amazon\\XenTools\\LiteAgent.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Amazon\\cfn-bootstrap\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Amazon\\cfn-bootstrap\\winhup.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Aurora-Agent\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Aurora-Agent\\\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Aurora-Agent\\aurora-agent.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Aurora-Agent\\tools\\\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Aurora-Agent\\tools\\aurora-dashboard.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Git\\cmd\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Mozilla Firefox\\\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Mozilla Firefox\\firefox.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Notepad++\\\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Notepad++\\notepad++.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\*\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\ProgramData\\chocolatey\\bin\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Python311\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Python311\\Scripts\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Users\\Administrator\\AppData\\Local\\Microsoft\\WindowsApps\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Users\\Administrator\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Users\\Administrator\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\*\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\ADWS\\Microsoft.ActiveDirectory.WebServices.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\ADWS\\\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\Explorer.EXE\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\SMSvcHost.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\SysWow64\\perfhost.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\System32\\Wbem\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\SystemApps\\Microsoft.Windows.Cortana_cw5n1h2txyewy\\SearchUI.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\SystemApps\\Microsoft.Windows.Cortana_cw5n1h2txyewy\\\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\SystemApps\\ShellExperienceHost_cw5n1h2txyewy\\ShellExperienceHost.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\SystemApps\\ShellExperienceHost_cw5n1h2txyewy\\\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\WinSxS\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.5771_none_7ee250a22208ec93\\\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\servicing\\TrustedInstaller.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\servicing\\\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\sysmon64.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\system32\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\winsxs\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.5771_none_7ee250a22208ec93\\TiWorker.exe\"", process="C:\\Windows\\System32\\icacls.exe \"c:\\Program Files\\ansible\\sysmon\"", process="C:\\Windows\\System32\\icacls.exe C:\\Windows\\ADWS\\Microsoft.ActiveDirectory.WebServices.exe", process="C:\\Windows\\System32\\icacls.exe C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\SMSvcHost.exe", process="C:\\Windows\\System32\\icacls.exe C:\\Windows\\SysWow64\\perfhost.exe", process="C:\\Windows\\System32\\icacls.exe C:\\Windows\\servicing\\TrustedInstaller.exe", process="C:\\Windows\\System32\\icacls.exe C:\\Windows\\sysmon64.exe", process_id="0x105c", process_id="0x1060", process_id="0x10e8", process_id="0x1170", process_id="0x11bc", process_id="0x1220", process_id="0x1234", process_id="0x1238", process_id="0x1274", process_id="0x12bc", process_id="0x12c", process_id="0x131c", process_id="0x138c", process_id="0x13b8", process_id="0x13d8", process_id="0x1478", process_id="0x1510", process_id="0x1578", process_id="0x15d0", process_id="0x167c", process_id="0x1704", process_id="0x1760", process_id="0x177c", process_id="0x1840", process_id="0x18b8", process_id="0x18d0", process_id="0x18ec", process_id="0x18f8", process_id="0x1938", process_id="0x196c", process_id="0x198c", process_id="0x19c4", process_id="0x19c8", process_id="0x19f0", process_id="0x1a30", process_id="0x1a4c", process_id="0x1a74", process_id="0x1a8c", process_id="0x1a98", process_id="0x1a9c", process_id="0x1aa4", process_id="0x1aac", process_id="0x1ab0", process_id="0x1abc", process_id="0x1afc", process_id="0x1b00", process_id="0x1b08", process_id="0x1b10", process_id="0x1b34", process_id="0x1b58", process_id="0x1b5c", process_id="0x1b6c", process_id="0x1b7c", process_id="0x1b9c", process_id="0x1ba8", process_id="0x1bb4", process_id="0x1be0", process_id="0x1d8", process_id="0x338", process_id="0x4ec", process_id="0x4f0", process_id="0x4f4", process_id="0x71c", process_id="0x820", process_id="0x828", process_id="0x874", process_id="0x8cc", process_id="0xa14", process_id="0xad8", process_id="0xb48", process_id="0xb80", process_id="0xb90", process_id="0xc0c", process_id="0xe54", process_id="0xf20", process_id="0xfc0", process_name="icacls.exe", risk_message="An excessive amount of icacls.exe was executed on ar-win-dc.attackrange.local attempting to modify permissions.", risk_object="icacls.exe", risk_object_type="other", risk_score="80.0", savedsearch_description="The following analytic identifies excessive usage of `cacls.exe`, `xcacls.exe` or `icacls.exe` application to change file or folder permission. This behavior is commonly seen where the adversary attempts to impair some users from deleting or accessing its malware components or artifact from the compromised system.", user="Administrator" 1686748070, search_name="ESCU - Create or delete windows shares using net exe - Rule", analyticstories="CISA AA22-277A", analyticstories="Hidden Cobra Malware", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Hidden Cobra Malware\",\"CISA AA22-277A\",\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1070\",\"T1070.005\"],\"nist\":[\"DE.CM\"]}", annotations._all="Windows Post-Exploitation", annotations._all="CISA AA22-277A", annotations._all="CIS 10", annotations._all="Exploitation", annotations._all="Prestige Ransomware", annotations._all="T1070.005", annotations._all="DE.CM", annotations._all="T1070", annotations._all="Hidden Cobra Malware", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Hidden Cobra Malware", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1070", annotations.mitre_attack="T1070.005", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:06", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686748064.365324000", lastTime="2023-06-14T13:04:06", original_file_name="net.exe", parent_process="\"cmd.exe\" /s /k pushd \"C:\\Temp\"", process="net share", process_name="net.exe", risk_message="An instance of $parent_process_name$ spawning net.exe was identified on endpoint ar-win-dc.attackrange.local by user Administrator enumerating Windows file shares.", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="25.0", savedsearch_description="This search looks for the creation or deletion of hidden shares using net.exe.", user="Administrator" 1686748070, search_name="ESCU - Create or delete windows shares using net exe - Rule", analyticstories="CISA AA22-277A", analyticstories="Hidden Cobra Malware", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Hidden Cobra Malware\",\"CISA AA22-277A\",\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1070\",\"T1070.005\"],\"nist\":[\"DE.CM\"]}", annotations._all="Windows Post-Exploitation", annotations._all="CISA AA22-277A", annotations._all="CIS 10", annotations._all="Exploitation", annotations._all="Prestige Ransomware", annotations._all="T1070.005", annotations._all="DE.CM", annotations._all="T1070", annotations._all="Hidden Cobra Malware", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Hidden Cobra Malware", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1070", annotations.mitre_attack="T1070.005", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:06", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686748064.365324000", lastTime="2023-06-14T13:04:06", original_file_name="net.exe", parent_process="\"cmd.exe\" /s /k pushd \"C:\\Temp\"", process="net share", process_name="net.exe", risk_message="An instance of $parent_process_name$ spawning net.exe was identified on endpoint ar-win-dc.attackrange.local by user Administrator enumerating Windows file shares.", risk_object="Administrator", risk_object_type="user", risk_score="25.0", savedsearch_description="This search looks for the creation or deletion of hidden shares using net.exe.", user="Administrator" 1686748070, search_name="ESCU - Create or delete windows shares using net exe - Rule", analyticstories="CISA AA22-277A", analyticstories="Hidden Cobra Malware", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Hidden Cobra Malware\",\"CISA AA22-277A\",\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1070\",\"T1070.005\"],\"nist\":[\"DE.CM\"]}", annotations._all="Windows Post-Exploitation", annotations._all="CISA AA22-277A", annotations._all="CIS 10", annotations._all="Exploitation", annotations._all="Prestige Ransomware", annotations._all="T1070.005", annotations._all="DE.CM", annotations._all="T1070", annotations._all="Hidden Cobra Malware", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Hidden Cobra Malware", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1070", annotations.mitre_attack="T1070.005", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:06", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686748064.365324000", lastTime="2023-06-14T13:04:06", original_file_name="unknown", parent_process="C:\\Windows\\System32\\net.exe", process="C:\\Windows\\system32\\net1 share", process_name="net1.exe", risk_message="An instance of $parent_process_name$ spawning net1.exe was identified on endpoint ar-win-dc.attackrange.local by user Administrator enumerating Windows file shares.", risk_object="net1.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="This search looks for the creation or deletion of hidden shares using net.exe.", user="Administrator" 1686748070, search_name="ESCU - Create or delete windows shares using net exe - Rule", analyticstories="CISA AA22-277A", analyticstories="Hidden Cobra Malware", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Hidden Cobra Malware\",\"CISA AA22-277A\",\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1070\",\"T1070.005\"],\"nist\":[\"DE.CM\"]}", annotations._all="Windows Post-Exploitation", annotations._all="CISA AA22-277A", annotations._all="CIS 10", annotations._all="Exploitation", annotations._all="Prestige Ransomware", annotations._all="T1070.005", annotations._all="DE.CM", annotations._all="T1070", annotations._all="Hidden Cobra Malware", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Hidden Cobra Malware", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1070", annotations.mitre_attack="T1070.005", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:06", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686748064.365324000", lastTime="2023-06-14T13:04:06", original_file_name="unknown", parent_process="C:\\Windows\\System32\\net.exe", process="C:\\Windows\\system32\\net1 share", process_name="net1.exe", risk_message="An instance of $parent_process_name$ spawning net1.exe was identified on endpoint ar-win-dc.attackrange.local by user Administrator enumerating Windows file shares.", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="25.0", savedsearch_description="This search looks for the creation or deletion of hidden shares using net.exe.", user="Administrator" 1686748070, search_name="ESCU - Create or delete windows shares using net exe - Rule", analyticstories="CISA AA22-277A", analyticstories="Hidden Cobra Malware", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Hidden Cobra Malware\",\"CISA AA22-277A\",\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1070\",\"T1070.005\"],\"nist\":[\"DE.CM\"]}", annotations._all="Windows Post-Exploitation", annotations._all="CISA AA22-277A", annotations._all="CIS 10", annotations._all="Exploitation", annotations._all="Prestige Ransomware", annotations._all="T1070.005", annotations._all="DE.CM", annotations._all="T1070", annotations._all="Hidden Cobra Malware", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Hidden Cobra Malware", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1070", annotations.mitre_attack="T1070.005", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:06", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686748064.365324000", lastTime="2023-06-14T13:04:06", original_file_name="unknown", parent_process="C:\\Windows\\System32\\net.exe", process="C:\\Windows\\system32\\net1 share", process_name="net1.exe", risk_message="An instance of $parent_process_name$ spawning net1.exe was identified on endpoint ar-win-dc.attackrange.local by user Administrator enumerating Windows file shares.", risk_object="Administrator", risk_object_type="user", risk_score="25.0", savedsearch_description="This search looks for the creation or deletion of hidden shares using net.exe.", user="Administrator" 1686748070, search_name="ESCU - Create or delete windows shares using net exe - Rule", analyticstories="CISA AA22-277A", analyticstories="Hidden Cobra Malware", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Hidden Cobra Malware\",\"CISA AA22-277A\",\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1070\",\"T1070.005\"],\"nist\":[\"DE.CM\"]}", annotations._all="Windows Post-Exploitation", annotations._all="CISA AA22-277A", annotations._all="CIS 10", annotations._all="Exploitation", annotations._all="Prestige Ransomware", annotations._all="T1070.005", annotations._all="DE.CM", annotations._all="T1070", annotations._all="Hidden Cobra Malware", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Hidden Cobra Malware", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1070", annotations.mitre_attack="T1070.005", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:06", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686748064.365324000", lastTime="2023-06-14T13:04:06", original_file_name="net1.exe", parent_process="net share", process="C:\\Windows\\system32\\net1 share", process_name="net1.exe", risk_message="An instance of $parent_process_name$ spawning net1.exe was identified on endpoint ar-win-dc.attackrange.local by user Administrator enumerating Windows file shares.", risk_object="net1.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="This search looks for the creation or deletion of hidden shares using net.exe.", user="Administrator" 1686748070, search_name="ESCU - Create or delete windows shares using net exe - Rule", analyticstories="CISA AA22-277A", analyticstories="Hidden Cobra Malware", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Hidden Cobra Malware\",\"CISA AA22-277A\",\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1070\",\"T1070.005\"],\"nist\":[\"DE.CM\"]}", annotations._all="Windows Post-Exploitation", annotations._all="CISA AA22-277A", annotations._all="CIS 10", annotations._all="Exploitation", annotations._all="Prestige Ransomware", annotations._all="T1070.005", annotations._all="DE.CM", annotations._all="T1070", annotations._all="Hidden Cobra Malware", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Hidden Cobra Malware", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1070", annotations.mitre_attack="T1070.005", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:06", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686748064.365324000", lastTime="2023-06-14T13:04:06", original_file_name="net1.exe", parent_process="net share", process="C:\\Windows\\system32\\net1 share", process_name="net1.exe", risk_message="An instance of $parent_process_name$ spawning net1.exe was identified on endpoint ar-win-dc.attackrange.local by user Administrator enumerating Windows file shares.", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="25.0", savedsearch_description="This search looks for the creation or deletion of hidden shares using net.exe.", user="Administrator" 1686748070, search_name="ESCU - Create or delete windows shares using net exe - Rule", analyticstories="CISA AA22-277A", analyticstories="Hidden Cobra Malware", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Hidden Cobra Malware\",\"CISA AA22-277A\",\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1070\",\"T1070.005\"],\"nist\":[\"DE.CM\"]}", annotations._all="Windows Post-Exploitation", annotations._all="CISA AA22-277A", annotations._all="CIS 10", annotations._all="Exploitation", annotations._all="Prestige Ransomware", annotations._all="T1070.005", annotations._all="DE.CM", annotations._all="T1070", annotations._all="Hidden Cobra Malware", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Hidden Cobra Malware", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1070", annotations.mitre_attack="T1070.005", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:06", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686748064.365324000", lastTime="2023-06-14T13:04:06", original_file_name="net1.exe", parent_process="net share", process="C:\\Windows\\system32\\net1 share", process_name="net1.exe", risk_message="An instance of $parent_process_name$ spawning net1.exe was identified on endpoint ar-win-dc.attackrange.local by user Administrator enumerating Windows file shares.", risk_object="Administrator", risk_object_type="user", risk_score="25.0", savedsearch_description="This search looks for the creation or deletion of hidden shares using net.exe.", user="Administrator" 1686748070, search_name="ESCU - Create or delete windows shares using net exe - Rule", analyticstories="CISA AA22-277A", analyticstories="Hidden Cobra Malware", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Hidden Cobra Malware\",\"CISA AA22-277A\",\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1070\",\"T1070.005\"],\"nist\":[\"DE.CM\"]}", annotations._all="Windows Post-Exploitation", annotations._all="CISA AA22-277A", annotations._all="CIS 10", annotations._all="Exploitation", annotations._all="Prestige Ransomware", annotations._all="T1070.005", annotations._all="DE.CM", annotations._all="T1070", annotations._all="Hidden Cobra Malware", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Hidden Cobra Malware", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1070", annotations.mitre_attack="T1070.005", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:06", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686748064.365324000", lastTime="2023-06-14T13:04:06", original_file_name="unknown", parent_process="C:\\Windows\\System32\\cmd.exe", process="C:\\Windows\\System32\\net.exe share", process_name="net.exe", risk_message="An instance of $parent_process_name$ spawning net.exe was identified on endpoint ar-win-dc.attackrange.local by user Administrator enumerating Windows file shares.", risk_object="net.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="This search looks for the creation or deletion of hidden shares using net.exe.", user="Administrator" 1686748070, search_name="ESCU - Create or delete windows shares using net exe - Rule", analyticstories="CISA AA22-277A", analyticstories="Hidden Cobra Malware", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Hidden Cobra Malware\",\"CISA AA22-277A\",\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1070\",\"T1070.005\"],\"nist\":[\"DE.CM\"]}", annotations._all="Windows Post-Exploitation", annotations._all="CISA AA22-277A", annotations._all="CIS 10", annotations._all="Exploitation", annotations._all="Prestige Ransomware", annotations._all="T1070.005", annotations._all="DE.CM", annotations._all="T1070", annotations._all="Hidden Cobra Malware", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Hidden Cobra Malware", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1070", annotations.mitre_attack="T1070.005", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:06", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686748064.365324000", lastTime="2023-06-14T13:04:06", original_file_name="unknown", parent_process="C:\\Windows\\System32\\cmd.exe", process="C:\\Windows\\System32\\net.exe share", process_name="net.exe", risk_message="An instance of $parent_process_name$ spawning net.exe was identified on endpoint ar-win-dc.attackrange.local by user Administrator enumerating Windows file shares.", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="25.0", savedsearch_description="This search looks for the creation or deletion of hidden shares using net.exe.", user="Administrator" 1686748070, search_name="ESCU - Create or delete windows shares using net exe - Rule", analyticstories="CISA AA22-277A", analyticstories="Hidden Cobra Malware", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Hidden Cobra Malware\",\"CISA AA22-277A\",\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1070\",\"T1070.005\"],\"nist\":[\"DE.CM\"]}", annotations._all="Windows Post-Exploitation", annotations._all="CISA AA22-277A", annotations._all="CIS 10", annotations._all="Exploitation", annotations._all="Prestige Ransomware", annotations._all="T1070.005", annotations._all="DE.CM", annotations._all="T1070", annotations._all="Hidden Cobra Malware", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Hidden Cobra Malware", annotations.analytic_story="CISA AA22-277A", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1070", annotations.mitre_attack="T1070.005", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:06", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686748064.365324000", lastTime="2023-06-14T13:04:06", original_file_name="unknown", parent_process="C:\\Windows\\System32\\cmd.exe", process="C:\\Windows\\System32\\net.exe share", process_name="net.exe", risk_message="An instance of $parent_process_name$ spawning net.exe was identified on endpoint ar-win-dc.attackrange.local by user Administrator enumerating Windows file shares.", risk_object="Administrator", risk_object_type="user", risk_score="25.0", savedsearch_description="This search looks for the creation or deletion of hidden shares using net.exe.", user="Administrator" 1686747840, search_name="ESCU - Excessive Usage Of Cacls App - Rule", orig_time="1686747840", analyticstories="Azorult", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", analyticstories="XMRig", annotations="{\"analytic_story\":[\"XMRig\",\"Azorult\",\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":100,\"impact\":80,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1222\"],\"nist\":[\"DE.AE\"]}", annotations._all="T1222", annotations._all="Exploitation", annotations._all="Prestige Ransomware", annotations._all="XMRig", annotations._all="CIS 10", annotations._all="Azorult", annotations._all="DE.AE", annotations._all="Windows Post-Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="XMRig", annotations.analytic_story="Azorult", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1222", annotations.nist="DE.AE", count="88", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:00", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686748062.019840000", lastTime="2023-06-14T13:04:00", parent_process="C:\\Windows\\System32\\cmd.exe", parent_process_name="cmd.exe", process="C:\\Windows\\System32\\icacls.exe \"C:\\Documents and Settings\\Administrator\\Start Menu\\Programs\\Startup\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Documents and Settings\\Administrator\\Start Menu\\Programs\\Startup\\*\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\*\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files (x86)\\Mozilla Maintenance Service\\maintenanceservice.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Amazon\\SSM\\\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Amazon\\SSM\\amazon-ssm-agent.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Amazon\\SSM\\ssm-agent-worker.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Amazon\\XenTools\\LiteAgent.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Amazon\\cfn-bootstrap\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Amazon\\cfn-bootstrap\\winhup.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Aurora-Agent\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Aurora-Agent\\\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Aurora-Agent\\aurora-agent.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Aurora-Agent\\tools\\\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Aurora-Agent\\tools\\aurora-dashboard.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Git\\cmd\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Mozilla Firefox\\\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Mozilla Firefox\\firefox.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Notepad++\\\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\Notepad++\\notepad++.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\*\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\ProgramData\\chocolatey\\bin\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Python311\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Python311\\Scripts\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Users\\Administrator\\AppData\\Local\\Microsoft\\WindowsApps\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Users\\Administrator\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Users\\Administrator\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\*\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\ADWS\\Microsoft.ActiveDirectory.WebServices.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\ADWS\\\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\Explorer.EXE\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\SMSvcHost.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\SysWow64\\perfhost.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\System32\\Wbem\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\SystemApps\\Microsoft.Windows.Cortana_cw5n1h2txyewy\\SearchUI.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\SystemApps\\Microsoft.Windows.Cortana_cw5n1h2txyewy\\\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\SystemApps\\ShellExperienceHost_cw5n1h2txyewy\\ShellExperienceHost.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\SystemApps\\ShellExperienceHost_cw5n1h2txyewy\\\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\WinSxS\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.5771_none_7ee250a22208ec93\\\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\servicing\\TrustedInstaller.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\servicing\\\\\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\sysmon64.exe\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\system32\"", process="C:\\Windows\\System32\\icacls.exe \"C:\\Windows\\winsxs\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.5771_none_7ee250a22208ec93\\TiWorker.exe\"", process="C:\\Windows\\System32\\icacls.exe \"c:\\Program Files\\ansible\\sysmon\"", process="C:\\Windows\\System32\\icacls.exe C:\\Windows\\ADWS\\Microsoft.ActiveDirectory.WebServices.exe", process="C:\\Windows\\System32\\icacls.exe C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\SMSvcHost.exe", process="C:\\Windows\\System32\\icacls.exe C:\\Windows\\SysWow64\\perfhost.exe", process="C:\\Windows\\System32\\icacls.exe C:\\Windows\\servicing\\TrustedInstaller.exe", process="C:\\Windows\\System32\\icacls.exe C:\\Windows\\sysmon64.exe", process_id="0x105c", process_id="0x1060", process_id="0x10e8", process_id="0x1170", process_id="0x11bc", process_id="0x1220", process_id="0x1234", process_id="0x1238", process_id="0x1274", process_id="0x12bc", process_id="0x12c", process_id="0x131c", process_id="0x138c", process_id="0x13b8", process_id="0x13d8", process_id="0x1478", process_id="0x1510", process_id="0x1578", process_id="0x15d0", process_id="0x167c", process_id="0x1704", process_id="0x1760", process_id="0x177c", process_id="0x1840", process_id="0x18b8", process_id="0x18d0", process_id="0x18ec", process_id="0x18f8", process_id="0x1938", process_id="0x196c", process_id="0x198c", process_id="0x19c4", process_id="0x19c8", process_id="0x19f0", process_id="0x1a30", process_id="0x1a4c", process_id="0x1a74", process_id="0x1a8c", process_id="0x1a98", process_id="0x1a9c", process_id="0x1aa4", process_id="0x1aac", process_id="0x1ab0", process_id="0x1abc", process_id="0x1afc", process_id="0x1b00", process_id="0x1b08", process_id="0x1b10", process_id="0x1b34", process_id="0x1b58", process_id="0x1b5c", process_id="0x1b6c", process_id="0x1b7c", process_id="0x1b9c", process_id="0x1ba8", process_id="0x1bb4", process_id="0x1be0", process_id="0x1d8", process_id="0x338", process_id="0x4ec", process_id="0x4f0", process_id="0x4f4", process_id="0x71c", process_id="0x820", process_id="0x828", process_id="0x874", process_id="0x8cc", process_id="0xa14", process_id="0xad8", process_id="0xb48", process_id="0xb80", process_id="0xb90", process_id="0xc0c", process_id="0xe54", process_id="0xf20", process_id="0xfc0", process_name="icacls.exe", risk_message="An excessive amount of icacls.exe was executed on ar-win-dc.attackrange.local attempting to modify permissions.", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="80.0", savedsearch_description="The following analytic identifies excessive usage of `cacls.exe`, `xcacls.exe` or `icacls.exe` application to change file or folder permission. This behavior is commonly seen where the adversary attempts to impair some users from deleting or accessing its malware components or artifact from the compromised system.", user="Administrator" 1686747840, search_name="ESCU - Excessive Usage Of Cacls App - Rule", orig_time="1686747840", analyticstories="Azorult", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", analyticstories="XMRig", annotations="{\"analytic_story\":[\"XMRig\",\"Azorult\",\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":100,\"impact\":80,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1222\"],\"nist\":[\"DE.AE\"]}", annotations._all="T1222", annotations._all="Exploitation", annotations._all="Prestige Ransomware", annotations._all="XMRig", annotations._all="CIS 10", annotations._all="Azorult", annotations._all="DE.AE", annotations._all="Windows Post-Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="XMRig", annotations.analytic_story="Azorult", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1222", annotations.nist="DE.AE", count="76", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:00", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686748062.019840000", lastTime="2023-06-14T13:04:00", parent_process="\"cmd.exe\" /s /k pushd \"C:\\Temp\"", parent_process_name="cmd.exe", process="icacls C:\\Windows\\ADWS\\Microsoft.ActiveDirectory.WebServices.exe", process="icacls C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\SMSvcHost.exe", process="icacls C:\\Windows\\SysWow64\\perfhost.exe", process="icacls C:\\Windows\\servicing\\TrustedInstaller.exe", process="icacls C:\\Windows\\sysmon64.exe", process="icacls \"C:\\Documents and Settings\\Administrator\\Start Menu\\Programs\\Startup\"", process="icacls \"C:\\Documents and Settings\\Administrator\\Start Menu\\Programs\\Startup\\*\"", process="icacls \"C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\"", process="icacls \"C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\*\"", process="icacls \"C:\\Program Files (x86)\\Mozilla Maintenance Service\\maintenanceservice.exe\"", process="icacls \"C:\\Program Files\\Amazon\\SSM\\\\\"", process="icacls \"C:\\Program Files\\Amazon\\SSM\\amazon-ssm-agent.exe\"", process="icacls \"C:\\Program Files\\Amazon\\SSM\\ssm-agent-worker.exe\"", process="icacls \"C:\\Program Files\\Amazon\\XenTools\\LiteAgent.exe\"", process="icacls \"C:\\Program Files\\Amazon\\cfn-bootstrap\\winhup.exe\"", process="icacls \"C:\\Program Files\\Aurora-Agent\\\\\"", process="icacls \"C:\\Program Files\\Aurora-Agent\\aurora-agent.exe\"", process="icacls \"C:\\Program Files\\Aurora-Agent\\tools\\\\\"", process="icacls \"C:\\Program Files\\Aurora-Agent\\tools\\aurora-dashboard.exe\"", process="icacls \"C:\\Program Files\\Mozilla Firefox\\\\\"", process="icacls \"C:\\Program Files\\Mozilla Firefox\\firefox.exe\"", process="icacls \"C:\\Program Files\\Notepad++\\\\\"", process="icacls \"C:\\Program Files\\Notepad++\\notepad++.exe\"", process="icacls \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\\\\"", process="icacls \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\"", process="icacls \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe\"", process="icacls \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\"", process="icacls \"C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\"", process="icacls \"C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\*\"", process="icacls \"C:\\Users\\Administrator\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\"", process="icacls \"C:\\Users\\Administrator\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\*\"", process="icacls \"C:\\Windows\\ADWS\\Microsoft.ActiveDirectory.WebServices.exe\"", process="icacls \"C:\\Windows\\ADWS\\\\\"", process="icacls \"C:\\Windows\\Explorer.EXE\"", process="icacls \"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\SMSvcHost.exe\"", process="icacls \"C:\\Windows\\SysWow64\\perfhost.exe\"", process="icacls \"C:\\Windows\\SystemApps\\Microsoft.Windows.Cortana_cw5n1h2txyewy\\SearchUI.exe\"", process="icacls \"C:\\Windows\\SystemApps\\Microsoft.Windows.Cortana_cw5n1h2txyewy\\\\\"", process="icacls \"C:\\Windows\\SystemApps\\ShellExperienceHost_cw5n1h2txyewy\\ShellExperienceHost.exe\"", process="icacls \"C:\\Windows\\SystemApps\\ShellExperienceHost_cw5n1h2txyewy\\\\\"", process="icacls \"C:\\Windows\\WinSxS\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.5771_none_7ee250a22208ec93\\\\\"", process="icacls \"C:\\Windows\\\\\"", process="icacls \"C:\\Windows\\servicing\\TrustedInstaller.exe\"", process="icacls \"C:\\Windows\\servicing\\\\\"", process="icacls \"C:\\Windows\\sysmon64.exe\"", process="icacls \"C:\\Windows\\winsxs\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.5771_none_7ee250a22208ec93\\TiWorker.exe\"", process_id="1260", process_id="1264", process_id="1268", process_id="1820", process_id="2080", process_id="2088", process_id="2164", process_id="2252", process_id="2776", process_id="2888", process_id="2944", process_id="2960", process_id="300", process_id="3084", process_id="3668", process_id="3872", process_id="4032", process_id="4188", process_id="4192", process_id="4328", process_id="4464", process_id="4540", process_id="4640", process_id="4660", process_id="4664", process_id="472", process_id="4724", process_id="4796", process_id="4892", process_id="5048", process_id="5080", process_id="5240", process_id="5392", process_id="5496", process_id="5756", process_id="5892", process_id="6012", process_id="6208", process_id="6328", process_id="6380", process_id="6392", process_id="6456", process_id="6508", process_id="6540", process_id="6596", process_id="6600", process_id="6640", process_id="6704", process_id="6732", process_id="6772", process_id="6796", process_id="6808", process_id="6812", process_id="6820", process_id="6828", process_id="6832", process_id="6844", process_id="6920", process_id="6928", process_id="6964", process_id="7000", process_id="7004", process_id="7020", process_id="7036", process_id="7068", process_id="7080", process_id="7092", process_id="7136", process_id="824", process_name="icacls.exe", risk_message="An excessive amount of icacls.exe was executed on ar-win-dc.attackrange.local attempting to modify permissions.", risk_object="icacls.exe", risk_object_type="other", risk_score="80.0", savedsearch_description="The following analytic identifies excessive usage of `cacls.exe`, `xcacls.exe` or `icacls.exe` application to change file or folder permission. This behavior is commonly seen where the adversary attempts to impair some users from deleting or accessing its malware components or artifact from the compromised system.", user="Administrator" 1686747840, search_name="ESCU - Excessive Usage Of Cacls App - Rule", orig_time="1686747840", analyticstories="Azorult", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", analyticstories="XMRig", annotations="{\"analytic_story\":[\"XMRig\",\"Azorult\",\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":100,\"impact\":80,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1222\"],\"nist\":[\"DE.AE\"]}", annotations._all="T1222", annotations._all="Exploitation", annotations._all="Prestige Ransomware", annotations._all="XMRig", annotations._all="CIS 10", annotations._all="Azorult", annotations._all="DE.AE", annotations._all="Windows Post-Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="XMRig", annotations.analytic_story="Azorult", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1222", annotations.nist="DE.AE", count="76", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:00", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686748062.019840000", lastTime="2023-06-14T13:04:00", parent_process="\"cmd.exe\" /s /k pushd \"C:\\Temp\"", parent_process_name="cmd.exe", process="icacls C:\\Windows\\ADWS\\Microsoft.ActiveDirectory.WebServices.exe", process="icacls C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\SMSvcHost.exe", process="icacls C:\\Windows\\SysWow64\\perfhost.exe", process="icacls C:\\Windows\\servicing\\TrustedInstaller.exe", process="icacls C:\\Windows\\sysmon64.exe", process="icacls \"C:\\Documents and Settings\\Administrator\\Start Menu\\Programs\\Startup\"", process="icacls \"C:\\Documents and Settings\\Administrator\\Start Menu\\Programs\\Startup\\*\"", process="icacls \"C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\"", process="icacls \"C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\*\"", process="icacls \"C:\\Program Files (x86)\\Mozilla Maintenance Service\\maintenanceservice.exe\"", process="icacls \"C:\\Program Files\\Amazon\\SSM\\\\\"", process="icacls \"C:\\Program Files\\Amazon\\SSM\\amazon-ssm-agent.exe\"", process="icacls \"C:\\Program Files\\Amazon\\SSM\\ssm-agent-worker.exe\"", process="icacls \"C:\\Program Files\\Amazon\\XenTools\\LiteAgent.exe\"", process="icacls \"C:\\Program Files\\Amazon\\cfn-bootstrap\\winhup.exe\"", process="icacls \"C:\\Program Files\\Aurora-Agent\\\\\"", process="icacls \"C:\\Program Files\\Aurora-Agent\\aurora-agent.exe\"", process="icacls \"C:\\Program Files\\Aurora-Agent\\tools\\\\\"", process="icacls \"C:\\Program Files\\Aurora-Agent\\tools\\aurora-dashboard.exe\"", process="icacls \"C:\\Program Files\\Mozilla Firefox\\\\\"", process="icacls \"C:\\Program Files\\Mozilla Firefox\\firefox.exe\"", process="icacls \"C:\\Program Files\\Notepad++\\\\\"", process="icacls \"C:\\Program Files\\Notepad++\\notepad++.exe\"", process="icacls \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\\\\"", process="icacls \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\"", process="icacls \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe\"", process="icacls \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\"", process="icacls \"C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\"", process="icacls \"C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\*\"", process="icacls \"C:\\Users\\Administrator\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\"", process="icacls \"C:\\Users\\Administrator\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\*\"", process="icacls \"C:\\Windows\\ADWS\\Microsoft.ActiveDirectory.WebServices.exe\"", process="icacls \"C:\\Windows\\ADWS\\\\\"", process="icacls \"C:\\Windows\\Explorer.EXE\"", process="icacls \"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\SMSvcHost.exe\"", process="icacls \"C:\\Windows\\SysWow64\\perfhost.exe\"", process="icacls \"C:\\Windows\\SystemApps\\Microsoft.Windows.Cortana_cw5n1h2txyewy\\SearchUI.exe\"", process="icacls \"C:\\Windows\\SystemApps\\Microsoft.Windows.Cortana_cw5n1h2txyewy\\\\\"", process="icacls \"C:\\Windows\\SystemApps\\ShellExperienceHost_cw5n1h2txyewy\\ShellExperienceHost.exe\"", process="icacls \"C:\\Windows\\SystemApps\\ShellExperienceHost_cw5n1h2txyewy\\\\\"", process="icacls \"C:\\Windows\\WinSxS\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.5771_none_7ee250a22208ec93\\\\\"", process="icacls \"C:\\Windows\\\\\"", process="icacls \"C:\\Windows\\servicing\\TrustedInstaller.exe\"", process="icacls \"C:\\Windows\\servicing\\\\\"", process="icacls \"C:\\Windows\\sysmon64.exe\"", process="icacls \"C:\\Windows\\winsxs\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.5771_none_7ee250a22208ec93\\TiWorker.exe\"", process_id="1260", process_id="1264", process_id="1268", process_id="1820", process_id="2080", process_id="2088", process_id="2164", process_id="2252", process_id="2776", process_id="2888", process_id="2944", process_id="2960", process_id="300", process_id="3084", process_id="3668", process_id="3872", process_id="4032", process_id="4188", process_id="4192", process_id="4328", process_id="4464", process_id="4540", process_id="4640", process_id="4660", process_id="4664", process_id="472", process_id="4724", process_id="4796", process_id="4892", process_id="5048", process_id="5080", process_id="5240", process_id="5392", process_id="5496", process_id="5756", process_id="5892", process_id="6012", process_id="6208", process_id="6328", process_id="6380", process_id="6392", process_id="6456", process_id="6508", process_id="6540", process_id="6596", process_id="6600", process_id="6640", process_id="6704", process_id="6732", process_id="6772", process_id="6796", process_id="6808", process_id="6812", process_id="6820", process_id="6828", process_id="6832", process_id="6844", process_id="6920", process_id="6928", process_id="6964", process_id="7000", process_id="7004", process_id="7020", process_id="7036", process_id="7068", process_id="7080", process_id="7092", process_id="7136", process_id="824", process_name="icacls.exe", risk_message="An excessive amount of icacls.exe was executed on ar-win-dc.attackrange.local attempting to modify permissions.", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="80.0", savedsearch_description="The following analytic identifies excessive usage of `cacls.exe`, `xcacls.exe` or `icacls.exe` application to change file or folder permission. This behavior is commonly seen where the adversary attempts to impair some users from deleting or accessing its malware components or artifact from the compromised system.", user="Administrator" 1686748049, search_name="ESCU - Windows WMI Process And Service List - Rule", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":20,\"impact\":20,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1047\"],\"nist\":[\"DE.AE\"]}", annotations._all="Windows Post-Exploitation", annotations._all="DE.AE", annotations._all="Prestige Ransomware", annotations._all="T1047", annotations._all="CIS 10", annotations._all="Installation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1047", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:10", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686748042.612314000", lastTime="2023-06-14T13:04:10", original_file_name="wmic.exe", parent_process="cmd.exe /c wmic service list full", parent_process_guid="{953948C6-BACA-6489-7403-00000000F902}", parent_process_name="cmd.exe", process="wmic service list full", process_guid="{953948C6-BACA-6489-7703-00000000F902}", process_id="7008", process_name="WMIC.exe", risk_message="wmi command wmic service list full to list processes and services in ar-win-dc.attackrange.local", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="4.0", savedsearch_description="The following analytic identifies suspicious process command line, where WMI is performing an event query looking for running processes or running services. This technique is commonly found where the adversary will identify services and system information on the compromised machine. During triage, review parallel processes within the same timeframe. Review the full script block to identify other related artifacts.", user="Administrator" 1686748049, search_name="ESCU - Windows WMI Process And Service List - Rule", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":20,\"impact\":20,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1047\"],\"nist\":[\"DE.AE\"]}", annotations._all="Windows Post-Exploitation", annotations._all="DE.AE", annotations._all="Prestige Ransomware", annotations._all="T1047", annotations._all="CIS 10", annotations._all="Installation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1047", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:04", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686748042.612314000", lastTime="2023-06-14T13:04:04", original_file_name="wmic.exe", parent_process="C:\\Windows\\system32\\cmd.exe /c wmic process list full|find /i \"executablepath\"|find /i /v \"system32\"|find \":\"", parent_process_guid="{953948C6-BAC4-6489-8602-00000000F902}", parent_process_name="cmd.exe", process="wmic process list full", process_guid="{953948C6-BAC4-6489-8702-00000000F902}", process_id="5560", process_name="WMIC.exe", risk_message="wmi command wmic process list full to list processes and services in ar-win-dc.attackrange.local", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="4.0", savedsearch_description="The following analytic identifies suspicious process command line, where WMI is performing an event query looking for running processes or running services. This technique is commonly found where the adversary will identify services and system information on the compromised machine. During triage, review parallel processes within the same timeframe. Review the full script block to identify other related artifacts.", user="Administrator" 1686748049, search_name="ESCU - Windows WMI Process And Service List - Rule", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":20,\"impact\":20,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1047\"],\"nist\":[\"DE.AE\"]}", annotations._all="Windows Post-Exploitation", annotations._all="DE.AE", annotations._all="Prestige Ransomware", annotations._all="T1047", annotations._all="CIS 10", annotations._all="Installation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1047", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:03", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686748042.612314000", lastTime="2023-06-14T13:04:03", original_file_name="wmic.exe", parent_process="C:\\Windows\\system32\\cmd.exe /c wmic process list full|find /i \"executablepath\"|find /i /v \"system32\"|find \":\"", parent_process_guid="{953948C6-BAC3-6489-1902-00000000F902}", parent_process_name="cmd.exe", process="wmic process list full", process_guid="{953948C6-BAC3-6489-1A02-00000000F902}", process_id="2268", process_name="WMIC.exe", risk_message="wmi command wmic process list full to list processes and services in ar-win-dc.attackrange.local", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="4.0", savedsearch_description="The following analytic identifies suspicious process command line, where WMI is performing an event query looking for running processes or running services. This technique is commonly found where the adversary will identify services and system information on the compromised machine. During triage, review parallel processes within the same timeframe. Review the full script block to identify other related artifacts.", user="Administrator" 1686748049, search_name="ESCU - Windows WMI Process And Service List - Rule", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":20,\"impact\":20,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1047\"],\"nist\":[\"DE.AE\"]}", annotations._all="Windows Post-Exploitation", annotations._all="DE.AE", annotations._all="Prestige Ransomware", annotations._all="T1047", annotations._all="CIS 10", annotations._all="Installation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1047", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:10", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686748042.612314000", lastTime="2023-06-14T13:04:10", original_file_name="unknown", parent_process="C:\\Windows\\System32\\cmd.exe", parent_process_guid="null", parent_process_name="cmd.exe", process="C:\\Windows\\System32\\wbem\\WMIC.exe service list full", process_guid="null", process_id="0x1b60", process_name="WMIC.exe", risk_message="wmi command C:\\Windows\\System32\\wbem\\WMIC.exe service list full to list processes and services in ar-win-dc.attackrange.local", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="4.0", savedsearch_description="The following analytic identifies suspicious process command line, where WMI is performing an event query looking for running processes or running services. This technique is commonly found where the adversary will identify services and system information on the compromised machine. During triage, review parallel processes within the same timeframe. Review the full script block to identify other related artifacts.", user="Administrator" 1686748049, search_name="ESCU - Windows WMI Process And Service List - Rule", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":20,\"impact\":20,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1047\"],\"nist\":[\"DE.AE\"]}", annotations._all="Windows Post-Exploitation", annotations._all="DE.AE", annotations._all="Prestige Ransomware", annotations._all="T1047", annotations._all="CIS 10", annotations._all="Installation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1047", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:03", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686748042.612314000", lastTime="2023-06-14T13:04:03", original_file_name="unknown", parent_process="C:\\Windows\\System32\\cmd.exe", parent_process_guid="null", parent_process_name="cmd.exe", process="C:\\Windows\\System32\\wbem\\WMIC.exe process list full", process_guid="null", process_id="0x8dc", process_name="WMIC.exe", risk_message="wmi command C:\\Windows\\System32\\wbem\\WMIC.exe process list full to list processes and services in ar-win-dc.attackrange.local", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="4.0", savedsearch_description="The following analytic identifies suspicious process command line, where WMI is performing an event query looking for running processes or running services. This technique is commonly found where the adversary will identify services and system information on the compromised machine. During triage, review parallel processes within the same timeframe. Review the full script block to identify other related artifacts.", user="Administrator" 1686748049, search_name="ESCU - Windows WMI Process And Service List - Rule", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":20,\"impact\":20,\"kill_chain_phases\":[\"Installation\"],\"mitre_attack\":[\"T1047\"],\"nist\":[\"DE.AE\"]}", annotations._all="Windows Post-Exploitation", annotations._all="DE.AE", annotations._all="Prestige Ransomware", annotations._all="T1047", annotations._all="CIS 10", annotations._all="Installation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Installation", annotations.mitre_attack="T1047", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:04", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686748042.612314000", lastTime="2023-06-14T13:04:04", original_file_name="unknown", parent_process="C:\\Windows\\System32\\cmd.exe", parent_process_guid="null", parent_process_name="cmd.exe", process="C:\\Windows\\System32\\wbem\\WMIC.exe process list full", process_guid="null", process_id="0x15b8", process_name="WMIC.exe", risk_message="wmi command C:\\Windows\\System32\\wbem\\WMIC.exe process list full to list processes and services in ar-win-dc.attackrange.local", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="4.0", savedsearch_description="The following analytic identifies suspicious process command line, where WMI is performing an event query looking for running processes or running services. This technique is commonly found where the adversary will identify services and system information on the compromised machine. During triage, review parallel processes within the same timeframe. Review the full script block to identify other related artifacts.", user="Administrator" 1686747840, search_name="ESCU - Windows Indirect Command Execution Via Series Of Forfiles - Rule", orig_time="1686747840", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":30,\"impact\":30,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.AE\"]}", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Prestige Ransomware", annotations._all="DE.AE", annotations._all="Exploitation", annotations._all="Windows Post-Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.AE", count="53", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:00", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686748017.471386000", lastTime="2023-06-14T13:04:00", parent_process="C:\\Windows\\System32\\cmd.exe", parent_process_name="cmd.exe", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m ADMINISTRATORS GROUPS\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m ARP\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m AlwaysInstallElevated?\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m AppCmd\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Audit Settings\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m CHECK IF YOU CAN MODIFY ANY SERVICE REGISTRY\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m CURRENT CLIPBOARD\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m CURRENT LOGGED USERS\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m CURRENT SHARES\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m CURRENT USER\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Cloud Credentials\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Credential Guard?\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m DATE and TIME\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m DNS CACHE\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m DPAPI MASTER KEYS\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m ENVIRONMENT\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m FIREWALL\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Files in registry that may contain credentials\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m GPP Password\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m GROUPS\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Hosts file\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m INSTALLED SOFTWARE\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m INTERFACES\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Kerberos Tickets\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m LAPS installed?\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m LSA protection?\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m MOUNTED DISKS\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m McAffee SiteList.xml\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Number of cached creds\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m PowerShell settings\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m ROUTES\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m RUN AT STARTUP\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m RUNNING PROCESSES\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Registered Anti-Virus(AV)\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Remote Desktop Credentials Manager\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m SAM and SYSTEM backups\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m SERVICE BINARY PERMISSIONS WITH WMIC and ICACLS\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m UAC Settings\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m UNQUOTED SERVICE PATHS\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m USED PORTS\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m USERS\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Unattended files\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m WDigest?\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m WEF Settings\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m WIFI\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m WINDOWS VAULT\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m WSUS\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO.0x1B[32m[*]0x1B[97m BASIC USER INFO\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO.0x1B[32m[*]0x1B[97m CREDENTIALS\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO.0x1B[32m[*]0x1B[97m DLL HIJACKING in PATHenv variable\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO.0x1B[32m[*]0x1B[97m NETWORK\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO.0x1B[32m[*]0x1B[97m SERVICE VULNERABILITIES\"", process_name="forfiles.exe", risk_message="excessive forfiles process execution in ar-win-dc.attackrange.local", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="9.0", savedsearch_description="This analytic is developed to detect suspicious excessive usage of forfiles.exe process. This event was seen in post exploitation tool WINPEAS that was used by Ransomware Prestige. Forfiles command lets you run a command on or pass arguments to multiple files. This Windows OS built-in tool being abused to list all files in specific directory or drive.", user="Administrator" 1686747780, search_name="ESCU - Windows Indirect Command Execution Via Series Of Forfiles - Rule", orig_time="1686747780", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":30,\"impact\":30,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.AE\"]}", annotations._all="CIS 10", annotations._all="T1202", annotations._all="Prestige Ransomware", annotations._all="DE.AE", annotations._all="Exploitation", annotations._all="Windows Post-Exploitation", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.AE", count="31", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:00", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686748017.471386000", lastTime="2023-06-14T13:03:00", parent_process="C:\\Windows\\System32\\cmd.exe", parent_process_name="cmd.exe", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m(((((((((((((((((((((((((((/0x1B[97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m(((((((((/,. 0x1B[92m,*//////*,.0x1B[32m ./(((((((((((.0x1B[97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m((,.,/((((((((((((((((((((/, */0x1B[97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m(((((((((/, 0x1B[92m,####################(0x1B[32m/..((((((((((.0x1B[97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m,/*,..*(((((((((((((((((((((((((((((((((,0x1B[97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m((((((((((((((((* 0x1B[94m*****0x1B[32m,,,/########## 0x1B[32m.(* ,((((((0x1B[97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m(((((((((((/* 0x1B[94m******************0x1B[32m/####### 0x1B[32m.(. ((((((0x1B[97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m(((((((((. ,0x1B[92m(############################(0x1B[32m../(((((((((.0x1B[97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m((((((.0x1B[92m.0x1B[94m******************0x1B[97m/@@@@@/0x1B[94m***0x1B[92m/######0x1B[32m /((((((0x1B[97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m, ,0x1B[92m0x1B[94m**********************0x1B[97m#@@@@@#@@@@0x1B[94m*********0x1B[92m##0x1B[32m((/ /((((0x1B[97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m,*/((((((((((((((((((/, 0x1B[92m.*//((//**,0x1B[32m .*((((((*0x1B[97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m,,.0x1B[92m.0x1B[94m**********************0x1B[97m@@@@@@@@@@(0x1B[94m***0x1B[92m,####0x1B[32m ../(((((0x1B[97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.((((0x1B[92m(############################################/0x1B[32m /((0x1B[97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.((0x1B[92m(####################/*******(###################0x1B[32m.((((0x1B[97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.((0x1B[92m(################(/0x1B[94m******0x1B[97m/@@@@@#0x1B[94m****************0x1B[32m.. /((0x1B[97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.(0x1B[92m(######################################(0x1B[94m************0x1B[32m..(0x1B[97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.(0x1B[92m(##################################(/0x1B[94m***************0x1B[32m..(0x1B[97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.(0x1B[92m(#############################(/0x1B[94m********************0x1B[32m.,(0x1B[97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.(0x1B[92m(########################(/0x1B[94m************************0x1B[32m..*(0x1B[97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.(0x1B[92m(##################(/**********(################(0x1B[94m**0x1B[32m...(0x1B[97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.(0x1B[92m(######(,.***.,(###################(..***(/0x1B[94m*********0x1B[32m..(0x1B[97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.(0x1B[92m(######*(#####((##################((######/(0x1B[94m********0x1B[32m..(0x1B[97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m..((((0x1B[92m(#########################################(0x1B[32m..(((((.0x1B[97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m..((0x1B[92m(##########0x1B[94m*********0x1B[97m/#@@@@@@@@@/0x1B[94m*************0x1B[32m,,..((((0x1B[97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m....((((0x1B[92m(#####################################(0x1B[32m .((((((.0x1B[97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m......((((0x1B[92m(#################################(0x1B[32m .(((((((.0x1B[97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[41mAny misuse of this software will not be the responsibility of the author or of any other collaborator.0x1B[40;97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[41mUse it at your own networks and/or with the network owner's permission.0x1B[40;97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[41mWinPEAS should be used for authorized penetration testing and/or educational purposes only.0x1B[40;97m\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m WINDOWS OS\"", process="C:\\Windows\\System32\\forfiles.exe /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO.0x1B[32m[*]0x1B[97m BASIC SYSTEM INFO\"", process_name="forfiles.exe", risk_message="excessive forfiles process execution in ar-win-dc.attackrange.local", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="9.0", savedsearch_description="This analytic is developed to detect suspicious excessive usage of forfiles.exe process. This event was seen in post exploitation tool WINPEAS that was used by Ransomware Prestige. Forfiles command lets you run a command on or pass arguments to multiple files. This Windows OS built-in tool being abused to list all files in specific directory or drive.", user="Administrator" 1686747993, search_name="ESCU - Windows Credentials in Registry Reg Query - Rule", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1552.002\",\"T1552\"],\"nist\":[\"DE.AE\"]}", annotations._all="T1552", annotations._all="CIS 10", annotations._all="DE.AE", annotations._all="Exploitation", annotations._all="Prestige Ransomware", annotations._all="Windows Post-Exploitation", annotations._all="T1552.002", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1552.002", annotations.mitre_attack="T1552", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:36", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747984.704335000", lastTime="2023-06-14T13:04:36", original_file_name="unknown", parent_process="C:\\Windows\\System32\\cmd.exe", parent_process_guid="null", parent_process_name="cmd.exe", process="C:\\Windows\\System32\\reg.exe query HKLM\\SYSTEM\\CurrentControlSet\\Services\\SNMP /s", process_guid="null", process_id="0x12a8", process_name="reg.exe", risk_message="reg query commandline C:\\Windows\\System32\\reg.exe query HKLM\\SYSTEM\\CurrentControlSet\\Services\\SNMP /s in ar-win-dc.attackrange.local", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="25.0", savedsearch_description="The following analytic identifies a process command line related to the discovery of possible password or credentials in the registry. This technique is being abused by adversaries or post exploitation tools like winpeas to steal credentials in the registry in the targeted host. Registry can contain several sensitive information like username and credentials that can be used for privilege escalation, persistence or even in lateral movement. This Anomaly detection can be a good pivot to detect a suspicious process querying a registry related to password or private keys.", user="Administrator" 1686747993, search_name="ESCU - Windows Credentials in Registry Reg Query - Rule", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1552.002\",\"T1552\"],\"nist\":[\"DE.AE\"]}", annotations._all="T1552", annotations._all="CIS 10", annotations._all="DE.AE", annotations._all="Exploitation", annotations._all="Prestige Ransomware", annotations._all="Windows Post-Exploitation", annotations._all="T1552.002", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1552.002", annotations.mitre_attack="T1552", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:36", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747984.704335000", lastTime="2023-06-14T13:04:36", original_file_name="unknown", parent_process="C:\\Windows\\System32\\cmd.exe", parent_process_guid="null", parent_process_name="cmd.exe", process="C:\\Windows\\System32\\reg.exe query HKEY_LOCAL_MACHINE\\SOFTWARE\\RealVNC\\WinVNC4 /v password", process_guid="null", process_id="0x1a28", process_name="reg.exe", risk_message="reg query commandline C:\\Windows\\System32\\reg.exe query HKEY_LOCAL_MACHINE\\SOFTWARE\\RealVNC\\WinVNC4 /v password in ar-win-dc.attackrange.local", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="25.0", savedsearch_description="The following analytic identifies a process command line related to the discovery of possible password or credentials in the registry. This technique is being abused by adversaries or post exploitation tools like winpeas to steal credentials in the registry in the targeted host. Registry can contain several sensitive information like username and credentials that can be used for privilege escalation, persistence or even in lateral movement. This Anomaly detection can be a good pivot to detect a suspicious process querying a registry related to password or private keys.", user="Administrator" 1686747993, search_name="ESCU - Windows Credentials in Registry Reg Query - Rule", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1552.002\",\"T1552\"],\"nist\":[\"DE.AE\"]}", annotations._all="T1552", annotations._all="CIS 10", annotations._all="DE.AE", annotations._all="Exploitation", annotations._all="Prestige Ransomware", annotations._all="Windows Post-Exploitation", annotations._all="T1552.002", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1552.002", annotations.mitre_attack="T1552", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:36", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747984.704335000", lastTime="2023-06-14T13:04:36", original_file_name="unknown", parent_process="C:\\Windows\\System32\\cmd.exe", parent_process_guid="null", parent_process_name="cmd.exe", process="C:\\Windows\\System32\\reg.exe query HKCU\\Software\\TightVNC\\Server", process_guid="null", process_id="0x1a64", process_name="reg.exe", risk_message="reg query commandline C:\\Windows\\System32\\reg.exe query HKCU\\Software\\TightVNC\\Server in ar-win-dc.attackrange.local", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="25.0", savedsearch_description="The following analytic identifies a process command line related to the discovery of possible password or credentials in the registry. This technique is being abused by adversaries or post exploitation tools like winpeas to steal credentials in the registry in the targeted host. Registry can contain several sensitive information like username and credentials that can be used for privilege escalation, persistence or even in lateral movement. This Anomaly detection can be a good pivot to detect a suspicious process querying a registry related to password or private keys.", user="Administrator" 1686747993, search_name="ESCU - Windows Credentials in Registry Reg Query - Rule", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1552.002\",\"T1552\"],\"nist\":[\"DE.AE\"]}", annotations._all="T1552", annotations._all="CIS 10", annotations._all="DE.AE", annotations._all="Exploitation", annotations._all="Prestige Ransomware", annotations._all="Windows Post-Exploitation", annotations._all="T1552.002", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1552.002", annotations.mitre_attack="T1552", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:36", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747984.704335000", lastTime="2023-06-14T13:04:36", original_file_name="unknown", parent_process="C:\\Windows\\System32\\cmd.exe", parent_process_guid="null", parent_process_name="cmd.exe", process="C:\\Windows\\System32\\reg.exe query HKCU\\Software\\SimonTatham\\PuTTY\\Sessions /s", process_guid="null", process_id="0x338", process_name="reg.exe", risk_message="reg query commandline C:\\Windows\\System32\\reg.exe query HKCU\\Software\\SimonTatham\\PuTTY\\Sessions /s in ar-win-dc.attackrange.local", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="25.0", savedsearch_description="The following analytic identifies a process command line related to the discovery of possible password or credentials in the registry. This technique is being abused by adversaries or post exploitation tools like winpeas to steal credentials in the registry in the targeted host. Registry can contain several sensitive information like username and credentials that can be used for privilege escalation, persistence or even in lateral movement. This Anomaly detection can be a good pivot to detect a suspicious process querying a registry related to password or private keys.", user="Administrator" 1686747993, search_name="ESCU - Windows Credentials in Registry Reg Query - Rule", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1552.002\",\"T1552\"],\"nist\":[\"DE.AE\"]}", annotations._all="T1552", annotations._all="CIS 10", annotations._all="DE.AE", annotations._all="Exploitation", annotations._all="Prestige Ransomware", annotations._all="Windows Post-Exploitation", annotations._all="T1552.002", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1552.002", annotations.mitre_attack="T1552", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:36", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747984.704335000", lastTime="2023-06-14T13:04:36", original_file_name="unknown", parent_process="C:\\Windows\\System32\\cmd.exe", parent_process_guid="null", parent_process_name="cmd.exe", process="C:\\Windows\\System32\\reg.exe query HKCU\\Software\\OpenSSH\\Agent\\Keys /s", process_guid="null", process_id="0x1994", process_name="reg.exe", risk_message="reg query commandline C:\\Windows\\System32\\reg.exe query HKCU\\Software\\OpenSSH\\Agent\\Keys /s in ar-win-dc.attackrange.local", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="25.0", savedsearch_description="The following analytic identifies a process command line related to the discovery of possible password or credentials in the registry. This technique is being abused by adversaries or post exploitation tools like winpeas to steal credentials in the registry in the targeted host. Registry can contain several sensitive information like username and credentials that can be used for privilege escalation, persistence or even in lateral movement. This Anomaly detection can be a good pivot to detect a suspicious process querying a registry related to password or private keys.", user="Administrator" 1686747993, search_name="ESCU - Windows Credentials in Registry Reg Query - Rule", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1552.002\",\"T1552\"],\"nist\":[\"DE.AE\"]}", annotations._all="T1552", annotations._all="CIS 10", annotations._all="DE.AE", annotations._all="Exploitation", annotations._all="Prestige Ransomware", annotations._all="Windows Post-Exploitation", annotations._all="T1552.002", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1552.002", annotations.mitre_attack="T1552", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:36", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747984.704335000", lastTime="2023-06-14T13:04:36", original_file_name="unknown", parent_process="C:\\Windows\\System32\\cmd.exe", parent_process_guid="null", parent_process_name="cmd.exe", process="C:\\Windows\\System32\\reg.exe query HKCU\\Software\\ORL\\WinVNC3\\Password", process_guid="null", process_id="0x1b54", process_name="reg.exe", risk_message="reg query commandline C:\\Windows\\System32\\reg.exe query HKCU\\Software\\ORL\\WinVNC3\\Password in ar-win-dc.attackrange.local", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="25.0", savedsearch_description="The following analytic identifies a process command line related to the discovery of possible password or credentials in the registry. This technique is being abused by adversaries or post exploitation tools like winpeas to steal credentials in the registry in the targeted host. Registry can contain several sensitive information like username and credentials that can be used for privilege escalation, persistence or even in lateral movement. This Anomaly detection can be a good pivot to detect a suspicious process querying a registry related to password or private keys.", user="Administrator" 1686747993, search_name="ESCU - Windows Credentials in Registry Reg Query - Rule", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1552.002\",\"T1552\"],\"nist\":[\"DE.AE\"]}", annotations._all="T1552", annotations._all="CIS 10", annotations._all="DE.AE", annotations._all="Exploitation", annotations._all="Prestige Ransomware", annotations._all="Windows Post-Exploitation", annotations._all="T1552.002", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1552.002", annotations.mitre_attack="T1552", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:36", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747984.704335000", lastTime="2023-06-14T13:04:36", original_file_name="reg.exe", parent_process="\"cmd.exe\" /s /k pushd \"C:\\Temp\"", parent_process_guid="{953948C6-BA8E-6489-C200-00000000F902}", parent_process_name="cmd.exe", process="reg query HKLM\\SYSTEM\\CurrentControlSet\\Services\\SNMP /s", process_guid="{953948C6-BAE4-6489-7A0C-00000000F902}", process_id="4776", process_name="reg.exe", risk_message="reg query commandline reg query HKLM\\SYSTEM\\CurrentControlSet\\Services\\SNMP /s in ar-win-dc.attackrange.local", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="25.0", savedsearch_description="The following analytic identifies a process command line related to the discovery of possible password or credentials in the registry. This technique is being abused by adversaries or post exploitation tools like winpeas to steal credentials in the registry in the targeted host. Registry can contain several sensitive information like username and credentials that can be used for privilege escalation, persistence or even in lateral movement. This Anomaly detection can be a good pivot to detect a suspicious process querying a registry related to password or private keys.", user="Administrator" 1686747993, search_name="ESCU - Windows Credentials in Registry Reg Query - Rule", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1552.002\",\"T1552\"],\"nist\":[\"DE.AE\"]}", annotations._all="T1552", annotations._all="CIS 10", annotations._all="DE.AE", annotations._all="Exploitation", annotations._all="Prestige Ransomware", annotations._all="Windows Post-Exploitation", annotations._all="T1552.002", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1552.002", annotations.mitre_attack="T1552", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:36", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747984.704335000", lastTime="2023-06-14T13:04:36", original_file_name="reg.exe", parent_process="\"cmd.exe\" /s /k pushd \"C:\\Temp\"", parent_process_guid="{953948C6-BA8E-6489-C200-00000000F902}", parent_process_name="cmd.exe", process="reg query HKEY_LOCAL_MACHINE\\SOFTWARE\\RealVNC\\WinVNC4 /v password", process_guid="{953948C6-BAE4-6489-770C-00000000F902}", process_id="6696", process_name="reg.exe", risk_message="reg query commandline reg query HKEY_LOCAL_MACHINE\\SOFTWARE\\RealVNC\\WinVNC4 /v password in ar-win-dc.attackrange.local", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="25.0", savedsearch_description="The following analytic identifies a process command line related to the discovery of possible password or credentials in the registry. This technique is being abused by adversaries or post exploitation tools like winpeas to steal credentials in the registry in the targeted host. Registry can contain several sensitive information like username and credentials that can be used for privilege escalation, persistence or even in lateral movement. This Anomaly detection can be a good pivot to detect a suspicious process querying a registry related to password or private keys.", user="Administrator" 1686747993, search_name="ESCU - Windows Credentials in Registry Reg Query - Rule", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1552.002\",\"T1552\"],\"nist\":[\"DE.AE\"]}", annotations._all="T1552", annotations._all="CIS 10", annotations._all="DE.AE", annotations._all="Exploitation", annotations._all="Prestige Ransomware", annotations._all="Windows Post-Exploitation", annotations._all="T1552.002", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1552.002", annotations.mitre_attack="T1552", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:36", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747984.704335000", lastTime="2023-06-14T13:04:36", original_file_name="reg.exe", parent_process="\"cmd.exe\" /s /k pushd \"C:\\Temp\"", parent_process_guid="{953948C6-BA8E-6489-C200-00000000F902}", parent_process_name="cmd.exe", process="reg query HKCU\\Software\\TightVNC\\Server", process_guid="{953948C6-BAE4-6489-7B0C-00000000F902}", process_id="6756", process_name="reg.exe", risk_message="reg query commandline reg query HKCU\\Software\\TightVNC\\Server in ar-win-dc.attackrange.local", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="25.0", savedsearch_description="The following analytic identifies a process command line related to the discovery of possible password or credentials in the registry. This technique is being abused by adversaries or post exploitation tools like winpeas to steal credentials in the registry in the targeted host. Registry can contain several sensitive information like username and credentials that can be used for privilege escalation, persistence or even in lateral movement. This Anomaly detection can be a good pivot to detect a suspicious process querying a registry related to password or private keys.", user="Administrator" 1686747993, search_name="ESCU - Windows Credentials in Registry Reg Query - Rule", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1552.002\",\"T1552\"],\"nist\":[\"DE.AE\"]}", annotations._all="T1552", annotations._all="CIS 10", annotations._all="DE.AE", annotations._all="Exploitation", annotations._all="Prestige Ransomware", annotations._all="Windows Post-Exploitation", annotations._all="T1552.002", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1552.002", annotations.mitre_attack="T1552", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:36", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747984.704335000", lastTime="2023-06-14T13:04:36", original_file_name="reg.exe", parent_process="\"cmd.exe\" /s /k pushd \"C:\\Temp\"", parent_process_guid="{953948C6-BA8E-6489-C200-00000000F902}", parent_process_name="cmd.exe", process="reg query HKCU\\Software\\SimonTatham\\PuTTY\\Sessions /s", process_guid="{953948C6-BAE4-6489-7C0C-00000000F902}", process_id="824", process_name="reg.exe", risk_message="reg query commandline reg query HKCU\\Software\\SimonTatham\\PuTTY\\Sessions /s in ar-win-dc.attackrange.local", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="25.0", savedsearch_description="The following analytic identifies a process command line related to the discovery of possible password or credentials in the registry. This technique is being abused by adversaries or post exploitation tools like winpeas to steal credentials in the registry in the targeted host. Registry can contain several sensitive information like username and credentials that can be used for privilege escalation, persistence or even in lateral movement. This Anomaly detection can be a good pivot to detect a suspicious process querying a registry related to password or private keys.", user="Administrator" 1686747993, search_name="ESCU - Windows Credentials in Registry Reg Query - Rule", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1552.002\",\"T1552\"],\"nist\":[\"DE.AE\"]}", annotations._all="T1552", annotations._all="CIS 10", annotations._all="DE.AE", annotations._all="Exploitation", annotations._all="Prestige Ransomware", annotations._all="Windows Post-Exploitation", annotations._all="T1552.002", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1552.002", annotations.mitre_attack="T1552", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:36", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747984.704335000", lastTime="2023-06-14T13:04:36", original_file_name="reg.exe", parent_process="\"cmd.exe\" /s /k pushd \"C:\\Temp\"", parent_process_guid="{953948C6-BA8E-6489-C200-00000000F902}", parent_process_name="cmd.exe", process="reg query HKCU\\Software\\OpenSSH\\Agent\\Keys /s", process_guid="{953948C6-BAE4-6489-7D0C-00000000F902}", process_id="6548", process_name="reg.exe", risk_message="reg query commandline reg query HKCU\\Software\\OpenSSH\\Agent\\Keys /s in ar-win-dc.attackrange.local", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="25.0", savedsearch_description="The following analytic identifies a process command line related to the discovery of possible password or credentials in the registry. This technique is being abused by adversaries or post exploitation tools like winpeas to steal credentials in the registry in the targeted host. Registry can contain several sensitive information like username and credentials that can be used for privilege escalation, persistence or even in lateral movement. This Anomaly detection can be a good pivot to detect a suspicious process querying a registry related to password or private keys.", user="Administrator" 1686747993, search_name="ESCU - Windows Credentials in Registry Reg Query - Rule", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1552.002\",\"T1552\"],\"nist\":[\"DE.AE\"]}", annotations._all="T1552", annotations._all="CIS 10", annotations._all="DE.AE", annotations._all="Exploitation", annotations._all="Prestige Ransomware", annotations._all="Windows Post-Exploitation", annotations._all="T1552.002", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1552.002", annotations.mitre_attack="T1552", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:36", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747984.704335000", lastTime="2023-06-14T13:04:36", original_file_name="reg.exe", parent_process="\"cmd.exe\" /s /k pushd \"C:\\Temp\"", parent_process_guid="{953948C6-BA8E-6489-C200-00000000F902}", parent_process_name="cmd.exe", process="reg query HKCU\\Software\\ORL\\WinVNC3\\Password", process_guid="{953948C6-BAE4-6489-760C-00000000F902}", process_id="6996", process_name="reg.exe", risk_message="reg query commandline reg query HKCU\\Software\\ORL\\WinVNC3\\Password in ar-win-dc.attackrange.local", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="25.0", savedsearch_description="The following analytic identifies a process command line related to the discovery of possible password or credentials in the registry. This technique is being abused by adversaries or post exploitation tools like winpeas to steal credentials in the registry in the targeted host. Registry can contain several sensitive information like username and credentials that can be used for privilege escalation, persistence or even in lateral movement. This Anomaly detection can be a good pivot to detect a suspicious process querying a registry related to password or private keys.", user="Administrator" 1686747970, search_name="ESCU - Windows Credentials from Password Stores Query - Rule", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1555\"],\"nist\":[\"DE.AE\"]}", annotations._all="CIS 10", annotations._all="T1555", annotations._all="Exploitation", annotations._all="DE.AE", annotations._all="Windows Post-Exploitation", annotations._all="Prestige Ransomware", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1555", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:31", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747965.193132000", lastTime="2023-06-14T13:04:31", original_file_name="unknown", parent_process="C:\\Windows\\System32\\cmd.exe", parent_process_guid="null", parent_process_name="cmd.exe", process="C:\\Windows\\System32\\cmdkey.exe /list", process_guid="null", process_id="0xb90", process_name="cmdkey.exe", risk_message="a process cmdkey.exe was executed in ar-win-dc.attackrange.local to display stored username and credentials.", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="25.0", savedsearch_description="The following analytic identifies a process execution of Windows OS cmdkey.exe tool. This tool is being abused or used by several post exploitation tool such as winpeas that being used by ransomware prestige to list stored user names, passwords or credentials in the targeted Windows OS host. This information can be used by the attacker to gain privilege escalation and persistence in the targeted hosts for further attacks.", user="Administrator" 1686747970, search_name="ESCU - Windows Credentials from Password Stores Query - Rule", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1555\"],\"nist\":[\"DE.AE\"]}", annotations._all="CIS 10", annotations._all="T1555", annotations._all="Exploitation", annotations._all="DE.AE", annotations._all="Windows Post-Exploitation", annotations._all="Prestige Ransomware", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1555", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:31", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747965.193132000", lastTime="2023-06-14T13:04:31", original_file_name="cmdkey.exe", parent_process="\"cmd.exe\" /s /k pushd \"C:\\Temp\"", parent_process_guid="{953948C6-BA8E-6489-C200-00000000F902}", parent_process_name="cmd.exe", process="cmdkey /list", process_guid="{953948C6-BADF-6489-580C-00000000F902}", process_id="2960", process_name="cmdkey.exe", risk_message="a process cmdkey.exe was executed in ar-win-dc.attackrange.local to display stored username and credentials.", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="25.0", savedsearch_description="The following analytic identifies a process execution of Windows OS cmdkey.exe tool. This tool is being abused or used by several post exploitation tool such as winpeas that being used by ransomware prestige to list stored user names, passwords or credentials in the targeted Windows OS host. This information can be used by the attacker to gain privilege escalation and persistence in the targeted hosts for further attacks.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:10", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:04:10", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO.0x1B[32m[*]0x1B[97m SERVICE VULNERABILITIES\"", parent_process_id="4264", parent_process_name="forfiles.exe", process="/C ECHO.\\x1B[32m[*]\\x1B[97m SERVICE VULNERABILITIES", process_id="6384", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:06", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:04:06", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO.0x1B[32m[*]0x1B[97m NETWORK\"", parent_process_id="5040", parent_process_name="forfiles.exe", process="/C ECHO.\\x1B[32m[*]\\x1B[97m NETWORK", process_id="5584", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:31", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:04:31", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO.0x1B[32m[*]0x1B[97m DLL HIJACKING in PATHenv variable\"", parent_process_id="4188", parent_process_name="forfiles.exe", process="/C ECHO.\\x1B[32m[*]\\x1B[97m DLL HIJACKING in PATHenv variable", process_id="2604", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:31", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:04:31", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO.0x1B[32m[*]0x1B[97m CREDENTIALS\"", parent_process_id="4796", parent_process_name="forfiles.exe", process="/C ECHO.\\x1B[32m[*]\\x1B[97m CREDENTIALS", process_id="4112", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:08", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:04:08", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO.0x1B[32m[*]0x1B[97m BASIC USER INFO\"", parent_process_id="1472", parent_process_name="forfiles.exe", process="/C ECHO.\\x1B[32m[*]\\x1B[97m BASIC USER INFO", process_id="5888", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:17", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:03:17", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO.0x1B[32m[*]0x1B[97m BASIC SYSTEM INFO\"", parent_process_id="6808", parent_process_name="forfiles.exe", process="/C ECHO.\\x1B[32m[*]\\x1B[97m BASIC SYSTEM INFO", process_id="7128", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:03", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:04:03", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m WSUS\"", parent_process_id="5540", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m WSUS", process_id="6392", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:31", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:04:31", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m WINDOWS VAULT\"", parent_process_id="6992", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m WINDOWS VAULT", process_id="4744", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:17", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:03:17", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m WINDOWS OS\"", parent_process_id="2580", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m WINDOWS OS", process_id="4464", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:07", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:04:07", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m WIFI\"", parent_process_id="6536", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m WIFI", process_id="4776", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:01", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:04:01", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m WEF Settings\"", parent_process_id="3260", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m WEF Settings", process_id="6536", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:01", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:04:01", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m WDigest?\"", parent_process_id="2268", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m WDigest?", process_id="8", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:32", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:04:32", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Unattended files\"", parent_process_id="6844", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m Unattended files", process_id="5676", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:08", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:04:08", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m USERS\"", parent_process_id="6704", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m USERS", process_id="6732", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:06", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:04:06", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m USED PORTS\"", parent_process_id="6916", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m USED PORTS", process_id="5076", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:25", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:04:25", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m UNQUOTED SERVICE PATHS\"", parent_process_id="6372", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m UNQUOTED SERVICE PATHS", process_id="4268", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:01", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:04:01", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m UAC Settings\"", parent_process_id="7020", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m UAC Settings", process_id="6692", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:10", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:04:10", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m SERVICE BINARY PERMISSIONS WITH WMIC and ICACLS\"", parent_process_id="4376", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m SERVICE BINARY PERMISSIONS WITH WMIC and ICACLS", process_id="596", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:32", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:04:32", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m SAM and SYSTEM backups\"", parent_process_id="7104", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m SAM and SYSTEM backups", process_id="5780", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:02", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:04:02", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Remote Desktop Credentials Manager\"", parent_process_id="6744", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m Remote Desktop Credentials Manager", process_id="5328", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:01", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:04:01", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Registered Anti-Virus(AV)\"", parent_process_id="6904", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m Registered Anti-Virus(AV)", process_id="5624", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:03", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:04:03", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m RUNNING PROCESSES\"", parent_process_id="6936", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m RUNNING PROCESSES", process_id="4828", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:05", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:04:05", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m RUN AT STARTUP\"", parent_process_id="2248", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m RUN AT STARTUP", process_id="4680", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:07", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:04:07", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m ROUTES\"", parent_process_id="6224", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m ROUTES", process_id="376", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:02", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:04:02", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m PowerShell settings\"", parent_process_id="2080", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m PowerShell settings", process_id="6136", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:01", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:04:01", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Number of cached creds\"", parent_process_id="4796", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m Number of cached creds", process_id="6736", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:32", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:04:32", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m McAffee SiteList.xml\"", parent_process_id="7084", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m McAffee SiteList.xml", process_id="6532", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:02", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:04:02", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m MOUNTED DISKS\"", parent_process_id="6352", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m MOUNTED DISKS", process_id="5984", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:01", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:04:01", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m LSA protection?\"", parent_process_id="4280", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m LSA protection?", process_id="4200", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:01", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:04:01", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m LAPS installed?\"", parent_process_id="5068", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m LAPS installed?", process_id="6928", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:09", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:04:09", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Kerberos Tickets\"", parent_process_id="5964", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m Kerberos Tickets", process_id="6760", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:06", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:04:06", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m INTERFACES\"", parent_process_id="5632", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m INTERFACES", process_id="5548", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:02", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:04:02", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m INSTALLED SOFTWARE\"", parent_process_id="6560", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m INSTALLED SOFTWARE", process_id="4864", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:07", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:04:07", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Hosts file\"", parent_process_id="3088", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m Hosts file", process_id="5028", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:09", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:04:09", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m GROUPS\"", parent_process_id="6692", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m GROUPS", process_id="7004", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:34", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:04:34", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m GPP Password\"", parent_process_id="7036", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m GPP Password", process_id="5588", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:36", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:04:36", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Files in registry that may contain credentials\"", parent_process_id="5768", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m Files in registry that may contain credentials", process_id="4464", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:06", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:04:06", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m FIREWALL\"", parent_process_id="7052", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m FIREWALL", process_id="6844", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:02", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:04:02", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m ENVIRONMENT\"", parent_process_id="4328", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m ENVIRONMENT", process_id="1820", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:32", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:04:32", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m DPAPI MASTER KEYS\"", parent_process_id="7076", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m DPAPI MASTER KEYS", process_id="6332", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:31", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:04:31", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m DPAPI MASTER KEYS\"", parent_process_id="6824", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m DPAPI MASTER KEYS", process_id="4328", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:07", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:04:07", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m DNS CACHE\"", parent_process_id="6972", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m DNS CACHE", process_id="5176", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:01", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:04:01", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m DATE and TIME\"", parent_process_id="6532", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m DATE and TIME", process_id="6888", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:01", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:04:01", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Credential Guard?\"", parent_process_id="4828", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m Credential Guard?", process_id="2812", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:35", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:04:35", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Cloud Credentials\"", parent_process_id="2248", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m Cloud Credentials", process_id="2580", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:08", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:04:08", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m CURRENT USER\"", parent_process_id="2088", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m CURRENT USER", process_id="5656", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:06", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:04:06", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m CURRENT SHARES\"", parent_process_id="3844", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m CURRENT SHARES", process_id="4568", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:09", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:04:09", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m CURRENT LOGGED USERS\"", parent_process_id="6136", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m CURRENT LOGGED USERS", process_id="5588", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:09", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:04:09", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m CURRENT CLIPBOARD\"", parent_process_id="6224", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m CURRENT CLIPBOARD", process_id="6700", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:11", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:04:11", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m CHECK IF YOU CAN MODIFY ANY SERVICE REGISTRY\"", parent_process_id="472", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m CHECK IF YOU CAN MODIFY ANY SERVICE REGISTRY", process_id="7036", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:01", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:04:01", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Audit Settings\"", parent_process_id="4724", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m Audit Settings", process_id="5856", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:36", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:04:36", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m AppCmd\"", parent_process_id="2776", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m AppCmd", process_id="5892", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:06", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:04:06", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m AlwaysInstallElevated?\"", parent_process_id="6920", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m AlwaysInstallElevated?", process_id="6896", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:07", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:04:07", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m ARP\"", parent_process_id="7080", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m ARP", process_id="5496", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:09", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:04:09", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m ADMINISTRATORS GROUPS\"", parent_process_id="6828", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[33m[+]\\x1B[97m ADMINISTRATORS GROUPS", process_id="6988", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:16", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:03:16", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[41mWinPEAS should be used for authorized penetration testing and/or educational purposes only.0x1B[40;97m\"", parent_process_id="6252", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[41mWinPEAS should be used for authorized penetration testing and/or educational purposes only.\\x1B[40;97m", process_id="4832", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:17", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:03:17", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[41mUse it at your own networks and/or with the network owner's permission.0x1B[40;97m\"", parent_process_id="5852", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[41mUse it at your own networks and/or with the network owner's permission.\\x1B[40;97m", process_id="1820", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:17", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:03:17", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[41mAny misuse of this software will not be the responsibility of the author or of any other collaborator.0x1B[40;97m\"", parent_process_id="6372", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[41mAny misuse of this software will not be the responsibility of the author or of any other collaborator.\\x1B[40;97m", process_id="5976", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:16", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:03:16", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m......((((0x1B[92m(#################################(0x1B[32m .(((((((.0x1B[97m\"", parent_process_id="6964", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[32m......((((\\x1B[92m(#################################(\\x1B[32m .(((((((.\\x1B[97m", process_id="6988", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:16", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:03:16", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m....((((0x1B[92m(#####################################(0x1B[32m .((((((.0x1B[97m\"", parent_process_id="6836", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[32m....((((\\x1B[92m(#####################################(\\x1B[32m .((((((.\\x1B[97m", process_id="6908", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:16", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:03:16", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m..((0x1B[92m(##########0x1B[94m*********0x1B[97m/#@@@@@@@@@/0x1B[94m*************0x1B[32m,,..((((0x1B[97m\"", parent_process_id="6720", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[32m..((\\x1B[92m(##########\\x1B[94m*********\\x1B[97m/#@@@@@@@@@/\\x1B[94m*************\\x1B[32m,,..((((\\x1B[97m", process_id="5808", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:16", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:03:16", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m..((((0x1B[92m(#########################################(0x1B[32m..(((((.0x1B[97m\"", parent_process_id="600", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[32m..((((\\x1B[92m(#########################################(\\x1B[32m..(((((.\\x1B[97m", process_id="6832", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:16", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:03:16", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.(0x1B[92m(######*(#####((##################((######/(0x1B[94m********0x1B[32m..(0x1B[97m\"", parent_process_id="6688", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[32m.(\\x1B[92m(######*(#####((##################((######/(\\x1B[94m********\\x1B[32m..(\\x1B[97m", process_id="2268", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:16", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:03:16", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.(0x1B[92m(######(,.***.,(###################(..***(/0x1B[94m*********0x1B[32m..(0x1B[97m\"", parent_process_id="4596", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[32m.(\\x1B[92m(######(,.***.,(###################(..***(/\\x1B[94m*********\\x1B[32m..(\\x1B[97m", process_id="5580", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:16", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:03:16", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.(0x1B[92m(##################(/**********(################(0x1B[94m**0x1B[32m...(0x1B[97m\"", parent_process_id="6740", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[32m.(\\x1B[92m(##################(/**********(################(\\x1B[94m**\\x1B[32m...(\\x1B[97m", process_id="4112", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:16", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:03:16", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.(0x1B[92m(########################(/0x1B[94m************************0x1B[32m..*(0x1B[97m\"", parent_process_id="1088", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[32m.(\\x1B[92m(########################(/\\x1B[94m************************\\x1B[32m..*(\\x1B[97m", process_id="4756", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:16", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:03:16", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.(0x1B[92m(#############################(/0x1B[94m********************0x1B[32m.,(0x1B[97m\"", parent_process_id="4268", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[32m.(\\x1B[92m(#############################(/\\x1B[94m********************\\x1B[32m.,(\\x1B[97m", process_id="4280", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:16", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:03:16", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.(0x1B[92m(##################################(/0x1B[94m***************0x1B[32m..(0x1B[97m\"", parent_process_id="6392", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[32m.(\\x1B[92m(##################################(/\\x1B[94m***************\\x1B[32m..(\\x1B[97m", process_id="2488", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:16", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:03:16", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.(0x1B[92m(######################################(0x1B[94m************0x1B[32m..(0x1B[97m\"", parent_process_id="5740", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[32m.(\\x1B[92m(######################################(\\x1B[94m************\\x1B[32m..(\\x1B[97m", process_id="6936", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:16", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:03:16", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.((0x1B[92m(################(/0x1B[94m******0x1B[97m/@@@@@#0x1B[94m****************0x1B[32m.. /((0x1B[97m\"", parent_process_id="5844", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[32m.((\\x1B[92m(################(/\\x1B[94m******\\x1B[97m/@@@@@#\\x1B[94m****************\\x1B[32m.. /((\\x1B[97m", process_id="2068", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:16", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:03:16", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.((0x1B[92m(####################/*******(###################0x1B[32m.((((0x1B[97m\"", parent_process_id="6596", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[32m.((\\x1B[92m(####################/*******(###################\\x1B[32m.((((\\x1B[97m", process_id="6796", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:16", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:03:16", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.((((0x1B[92m(############################################/0x1B[32m /((0x1B[97m\"", parent_process_id="2460", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[32m.((((\\x1B[92m(############################################/\\x1B[32m /((\\x1B[97m", process_id="5840", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:16", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:03:16", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m,,.0x1B[92m.0x1B[94m**********************0x1B[97m@@@@@@@@@@(0x1B[94m***0x1B[92m,####0x1B[32m ../(((((0x1B[97m\"", parent_process_id="6132", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[32m,,.\\x1B[92m.\\x1B[94m**********************\\x1B[97m@@@@@@@@@@(\\x1B[94m***\\x1B[92m,####\\x1B[32m ../(((((\\x1B[97m", process_id="6332", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:15", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:03:15", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m,*/((((((((((((((((((/, 0x1B[92m.*//((//**,0x1B[32m .*((((((*0x1B[97m\"", parent_process_id="5496", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[32m,*/((((((((((((((((((/, \\x1B[92m.*//((//**,\\x1B[32m .*((((((*\\x1B[97m", process_id="6348", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:16", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:03:16", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m, ,0x1B[92m0x1B[94m**********************0x1B[97m#@@@@@#@@@@0x1B[94m*********0x1B[92m##0x1B[32m((/ /((((0x1B[97m\"", parent_process_id="6012", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[32m, ,\\x1B[92m\\x1B[94m**********************\\x1B[97m#@@@@@#@@@@\\x1B[94m*********\\x1B[92m##\\x1B[32m((/ /((((\\x1B[97m", process_id="2924", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:16", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:03:16", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m((((((.0x1B[92m.0x1B[94m******************0x1B[97m/@@@@@/0x1B[94m***0x1B[92m/######0x1B[32m /((((((0x1B[97m\"", parent_process_id="5028", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[32m((((((.\\x1B[92m.\\x1B[94m******************\\x1B[97m/@@@@@/\\x1B[94m***\\x1B[92m/######\\x1B[32m /((((((\\x1B[97m", process_id="4724", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:16", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:03:16", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m(((((((((. ,0x1B[92m(############################(0x1B[32m../(((((((((.0x1B[97m\"", parent_process_id="7056", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[32m(((((((((. ,\\x1B[92m(############################(\\x1B[32m../(((((((((.\\x1B[97m", process_id="7060", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:15", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:03:15", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m(((((((((((/* 0x1B[94m******************0x1B[32m/####### 0x1B[32m.(. ((((((0x1B[97m\"", parent_process_id="5176", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[32m(((((((((((/* \\x1B[94m******************\\x1B[32m/####### \\x1B[32m.(. ((((((\\x1B[97m", process_id="4660", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:15", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:03:15", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m((((((((((((((((* 0x1B[94m*****0x1B[32m,,,/########## 0x1B[32m.(* ,((((((0x1B[97m\"", parent_process_id="6208", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[32m((((((((((((((((* \\x1B[94m*****\\x1B[32m,,,/########## \\x1B[32m.(* ,((((((\\x1B[97m", process_id="6380", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:15", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:03:15", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m,/*,..*(((((((((((((((((((((((((((((((((,0x1B[97m\"", parent_process_id="7144", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[32m,/*,..*(((((((((((((((((((((((((((((((((,\\x1B[97m", process_id="2604", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:16", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:03:16", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m(((((((((/, 0x1B[92m,####################(0x1B[32m/..((((((((((.0x1B[97m\"", parent_process_id="7084", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[32m(((((((((/, \\x1B[92m,####################(\\x1B[32m/..((((((((((.\\x1B[97m", process_id="3668", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:15", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:03:15", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m((,.,/((((((((((((((((((((/, */0x1B[97m\"", parent_process_id="3444", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[32m((,.,/((((((((((((((((((((/, */\\x1B[97m", process_id="6748", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:16", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:03:16", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m(((((((((/,. 0x1B[92m,*//////*,.0x1B[32m ./(((((((((((.0x1B[97m\"", parent_process_id="5980", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[32m(((((((((/,. \\x1B[92m,*//////*,.\\x1B[32m ./(((((((((((.\\x1B[97m", process_id="300", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:16", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:03:16", parent_process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m(((((((((((((((((((((((((((/0x1B[97m\"", parent_process_id="4780", parent_process_name="forfiles.exe", process="/C ECHO. \\x1B[32m(((((((((((((((((((((((((((/\\x1B[97m", process_id="7140", process_name="cmd.exe", process_path="C:\\Windows\\System32\\cmd.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process cmd.exe", risk_object="cmd.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:10", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:04:10", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO.0x1B[32m[*]0x1B[97m SERVICE VULNERABILITIES\"", parent_process_id="7088", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO.0x1B[32m[*]0x1B[97m SERVICE VULNERABILITIES\"", process_id="4264", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:06", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:04:06", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO.0x1B[32m[*]0x1B[97m NETWORK\"", parent_process_id="5228", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO.0x1B[32m[*]0x1B[97m NETWORK\"", process_id="5040", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:31", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:04:31", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO.0x1B[32m[*]0x1B[97m DLL HIJACKING in PATHenv variable\"", parent_process_id="6368", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO.0x1B[32m[*]0x1B[97m DLL HIJACKING in PATHenv variable\"", process_id="4188", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:31", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:04:31", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO.0x1B[32m[*]0x1B[97m CREDENTIALS\"", parent_process_id="6392", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO.0x1B[32m[*]0x1B[97m CREDENTIALS\"", process_id="4796", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:07", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:04:07", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO.0x1B[32m[*]0x1B[97m BASIC USER INFO\"", parent_process_id="6696", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO.0x1B[32m[*]0x1B[97m BASIC USER INFO\"", process_id="1472", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:17", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:03:17", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO.0x1B[32m[*]0x1B[97m BASIC SYSTEM INFO\"", parent_process_id="4660", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO.0x1B[32m[*]0x1B[97m BASIC SYSTEM INFO\"", process_id="6808", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:03", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:04:03", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m WSUS\"", parent_process_id="6896", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m WSUS\"", process_id="5540", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:31", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:04:31", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m WINDOWS VAULT\"", parent_process_id="3572", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m WINDOWS VAULT\"", process_id="6992", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:17", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:03:17", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m WINDOWS OS\"", parent_process_id="4724", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m WINDOWS OS\"", process_id="2580", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:07", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:04:07", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m WIFI\"", parent_process_id="5808", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m WIFI\"", process_id="6536", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:01", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:04:01", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m WEF Settings\"", parent_process_id="4264", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m WEF Settings\"", process_id="3260", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:01", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:04:01", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m WDigest?\"", parent_process_id="2960", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m WDigest?\"", process_id="2268", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:32", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:04:32", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Unattended files\"", parent_process_id="6088", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Unattended files\"", process_id="6844", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:08", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:04:08", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m USERS\"", parent_process_id="5544", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m USERS\"", process_id="6704", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:06", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:04:06", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m USED PORTS\"", parent_process_id="6828", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m USED PORTS\"", process_id="6916", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:25", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:04:25", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m UNQUOTED SERVICE PATHS\"", parent_process_id="6640", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m UNQUOTED SERVICE PATHS\"", process_id="6372", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:01", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:04:01", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m UAC Settings\"", parent_process_id="600", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m UAC Settings\"", process_id="7020", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:10", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:04:10", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m SERVICE BINARY PERMISSIONS WITH WMIC and ICACLS\"", parent_process_id="6572", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m SERVICE BINARY PERMISSIONS WITH WMIC and ICACLS\"", process_id="4376", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:32", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:04:32", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m SAM and SYSTEM backups\"", parent_process_id="5836", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m SAM and SYSTEM backups\"", process_id="7104", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:02", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:04:02", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Remote Desktop Credentials Manager\"", parent_process_id="4612", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Remote Desktop Credentials Manager\"", process_id="6744", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:01", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:04:01", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Registered Anti-Virus(AV)\"", parent_process_id="6908", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Registered Anti-Virus(AV)\"", process_id="6904", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:03", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:04:03", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m RUNNING PROCESSES\"", parent_process_id="5736", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m RUNNING PROCESSES\"", process_id="6936", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:05", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:04:05", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m RUN AT STARTUP\"", parent_process_id="5496", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m RUN AT STARTUP\"", process_id="2248", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:07", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:04:07", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m ROUTES\"", parent_process_id="7036", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m ROUTES\"", process_id="6224", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:02", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:04:02", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m PowerShell settings\"", parent_process_id="6768", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m PowerShell settings\"", process_id="2080", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:01", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:04:01", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Number of cached creds\"", parent_process_id="4804", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Number of cached creds\"", process_id="4796", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:32", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:04:32", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m McAffee SiteList.xml\"", parent_process_id="7156", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m McAffee SiteList.xml\"", process_id="7084", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:02", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:04:02", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m MOUNTED DISKS\"", parent_process_id="6376", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m MOUNTED DISKS\"", process_id="6352", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:01", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:04:01", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m LSA protection?\"", parent_process_id="6932", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m LSA protection?\"", process_id="4280", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:01", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:04:01", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m LAPS installed?\"", parent_process_id="5540", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m LAPS installed?\"", process_id="5068", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:09", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:04:09", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Kerberos Tickets\"", parent_process_id="5980", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Kerberos Tickets\"", process_id="5964", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:06", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:04:06", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m INTERFACES\"", parent_process_id="5240", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m INTERFACES\"", process_id="5632", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:02", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:04:02", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m INSTALLED SOFTWARE\"", parent_process_id="7024", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m INSTALLED SOFTWARE\"", process_id="6560", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:07", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:04:07", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Hosts file\"", parent_process_id="6656", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Hosts file\"", process_id="3088", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:09", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:04:09", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m GROUPS\"", parent_process_id="5632", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m GROUPS\"", process_id="6692", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:34", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:04:34", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m GPP Password\"", parent_process_id="5496", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m GPP Password\"", process_id="7036", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:36", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:04:36", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Files in registry that may contain credentials\"", parent_process_id="5656", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Files in registry that may contain credentials\"", process_id="5768", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:06", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:04:06", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m FIREWALL\"", parent_process_id="6456", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m FIREWALL\"", process_id="7052", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:02", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:04:02", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m ENVIRONMENT\"", parent_process_id="6892", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m ENVIRONMENT\"", process_id="4328", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:32", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:04:32", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m DPAPI MASTER KEYS\"", parent_process_id="6764", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m DPAPI MASTER KEYS\"", process_id="7076", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:31", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:04:31", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m DPAPI MASTER KEYS\"", parent_process_id="8", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m DPAPI MASTER KEYS\"", process_id="6824", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:07", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:04:07", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m DNS CACHE\"", parent_process_id="4808", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m DNS CACHE\"", process_id="6972", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:01", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:04:01", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m DATE and TIME\"", parent_process_id="6808", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m DATE and TIME\"", process_id="6532", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:01", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:04:01", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Credential Guard?\"", parent_process_id="5648", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Credential Guard?\"", process_id="4828", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:35", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:04:35", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Cloud Credentials\"", parent_process_id="5316", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Cloud Credentials\"", process_id="2248", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:08", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:04:08", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m CURRENT USER\"", parent_process_id="6924", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m CURRENT USER\"", process_id="2088", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:06", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:04:06", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m CURRENT SHARES\"", parent_process_id="6856", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m CURRENT SHARES\"", process_id="3844", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:09", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:04:09", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m CURRENT LOGGED USERS\"", parent_process_id="3792", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m CURRENT LOGGED USERS\"", process_id="6136", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:09", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:04:09", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m CURRENT CLIPBOARD\"", parent_process_id="2944", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m CURRENT CLIPBOARD\"", process_id="6224", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:11", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:04:11", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m CHECK IF YOU CAN MODIFY ANY SERVICE REGISTRY\"", parent_process_id="6376", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m CHECK IF YOU CAN MODIFY ANY SERVICE REGISTRY\"", process_id="472", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:01", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:04:01", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Audit Settings\"", parent_process_id="5808", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m Audit Settings\"", process_id="4724", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:36", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:04:36", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m AppCmd\"", parent_process_id="5116", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m AppCmd\"", process_id="2776", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:06", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:04:06", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m AlwaysInstallElevated?\"", parent_process_id="4200", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m AlwaysInstallElevated?\"", process_id="6920", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:07", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:04:07", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m ARP\"", parent_process_id="528", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m ARP\"", process_id="7080", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:09", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:04:09", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m ADMINISTRATORS GROUPS\"", parent_process_id="6012", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[33m[+]0x1B[97m ADMINISTRATORS GROUPS\"", process_id="6828", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:16", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:03:16", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[41mWinPEAS should be used for authorized penetration testing and/or educational purposes only.0x1B[40;97m\"", parent_process_id="7132", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[41mWinPEAS should be used for authorized penetration testing and/or educational purposes only.0x1B[40;97m\"", process_id="6252", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:17", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:03:17", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[41mUse it at your own networks and/or with the network owner's permission.0x1B[40;97m\"", parent_process_id="5832", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[41mUse it at your own networks and/or with the network owner's permission.0x1B[40;97m\"", process_id="5852", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:17", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:03:17", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[41mAny misuse of this software will not be the responsibility of the author or of any other collaborator.0x1B[40;97m\"", parent_process_id="4664", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[41mAny misuse of this software will not be the responsibility of the author or of any other collaborator.0x1B[40;97m\"", process_id="6372", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:16", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:03:16", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m......((((0x1B[92m(#################################(0x1B[32m .(((((((.0x1B[97m\"", parent_process_id="6968", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m......((((0x1B[92m(#################################(0x1B[32m .(((((((.0x1B[97m\"", process_id="6964", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:16", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:03:16", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m....((((0x1B[92m(#####################################(0x1B[32m .((((((.0x1B[97m\"", parent_process_id="7004", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m....((((0x1B[92m(#####################################(0x1B[32m .((((((.0x1B[97m\"", process_id="6836", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:16", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:03:16", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m..((0x1B[92m(##########0x1B[94m*********0x1B[97m/#@@@@@@@@@/0x1B[94m*************0x1B[32m,,..((((0x1B[97m\"", parent_process_id="6612", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m..((0x1B[92m(##########0x1B[94m*********0x1B[97m/#@@@@@@@@@/0x1B[94m*************0x1B[32m,,..((((0x1B[97m\"", process_id="6720", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:16", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:03:16", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m..((((0x1B[92m(#########################################(0x1B[32m..(((((.0x1B[97m\"", parent_process_id="5072", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m..((((0x1B[92m(#########################################(0x1B[32m..(((((.0x1B[97m\"", process_id="600", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:16", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:03:16", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.(0x1B[92m(######*(#####((##################((######/(0x1B[94m********0x1B[32m..(0x1B[97m\"", parent_process_id="5544", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.(0x1B[92m(######*(#####((##################((######/(0x1B[94m********0x1B[32m..(0x1B[97m\"", process_id="6688", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:16", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:03:16", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.(0x1B[92m(######(,.***.,(###################(..***(/0x1B[94m*********0x1B[32m..(0x1B[97m\"", parent_process_id="5392", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.(0x1B[92m(######(,.***.,(###################(..***(/0x1B[94m*********0x1B[32m..(0x1B[97m\"", process_id="4596", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:16", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:03:16", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.(0x1B[92m(##################(/**********(################(0x1B[94m**0x1B[32m...(0x1B[97m\"", parent_process_id="6736", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.(0x1B[92m(##################(/**********(################(0x1B[94m**0x1B[32m...(0x1B[97m\"", process_id="6740", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:16", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:03:16", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.(0x1B[92m(########################(/0x1B[94m************************0x1B[32m..*(0x1B[97m\"", parent_process_id="7008", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.(0x1B[92m(########################(/0x1B[94m************************0x1B[32m..*(0x1B[97m\"", process_id="1088", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:16", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:03:16", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.(0x1B[92m(#############################(/0x1B[94m********************0x1B[32m.,(0x1B[97m\"", parent_process_id="4192", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.(0x1B[92m(#############################(/0x1B[94m********************0x1B[32m.,(0x1B[97m\"", process_id="4268", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:16", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:03:16", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.(0x1B[92m(##################################(/0x1B[94m***************0x1B[32m..(0x1B[97m\"", parent_process_id="5148", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.(0x1B[92m(##################################(/0x1B[94m***************0x1B[32m..(0x1B[97m\"", process_id="6392", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:16", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:03:16", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.(0x1B[92m(######################################(0x1B[94m************0x1B[32m..(0x1B[97m\"", parent_process_id="2812", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.(0x1B[92m(######################################(0x1B[94m************0x1B[32m..(0x1B[97m\"", process_id="5740", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:16", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:03:16", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.((0x1B[92m(################(/0x1B[94m******0x1B[97m/@@@@@#0x1B[94m****************0x1B[32m.. /((0x1B[97m\"", parent_process_id="5828", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.((0x1B[92m(################(/0x1B[94m******0x1B[97m/@@@@@#0x1B[94m****************0x1B[32m.. /((0x1B[97m\"", process_id="5844", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:16", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:03:16", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.((0x1B[92m(####################/*******(###################0x1B[32m.((((0x1B[97m\"", parent_process_id="7020", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.((0x1B[92m(####################/*******(###################0x1B[32m.((((0x1B[97m\"", process_id="6596", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:16", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:03:16", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.((((0x1B[92m(############################################/0x1B[32m /((0x1B[97m\"", parent_process_id="624", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m.((((0x1B[92m(############################################/0x1B[32m /((0x1B[97m\"", process_id="2460", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:16", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:03:16", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m,,.0x1B[92m.0x1B[94m**********************0x1B[97m@@@@@@@@@@(0x1B[94m***0x1B[92m,####0x1B[32m ../(((((0x1B[97m\"", parent_process_id="6924", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m,,.0x1B[92m.0x1B[94m**********************0x1B[97m@@@@@@@@@@(0x1B[94m***0x1B[92m,####0x1B[32m ../(((((0x1B[97m\"", process_id="6132", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:15", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:03:15", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m,*/((((((((((((((((((/, 0x1B[92m.*//((//**,0x1B[32m .*((((((*0x1B[97m\"", parent_process_id="4664", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m,*/((((((((((((((((((/, 0x1B[92m.*//((//**,0x1B[32m .*((((((*0x1B[97m\"", process_id="5496", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:16", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:03:16", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m, ,0x1B[92m0x1B[94m**********************0x1B[97m#@@@@@#@@@@0x1B[94m*********0x1B[92m##0x1B[32m((/ /((((0x1B[97m\"", parent_process_id="6564", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m, ,0x1B[92m0x1B[94m**********************0x1B[97m#@@@@@#@@@@0x1B[94m*********0x1B[92m##0x1B[32m((/ /((((0x1B[97m\"", process_id="6012", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:15", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:03:15", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m((((((.0x1B[92m.0x1B[94m******************0x1B[97m/@@@@@/0x1B[94m***0x1B[92m/######0x1B[32m /((((((0x1B[97m\"", parent_process_id="5040", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m((((((.0x1B[92m.0x1B[94m******************0x1B[97m/@@@@@/0x1B[94m***0x1B[92m/######0x1B[32m /((((((0x1B[97m\"", process_id="5028", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:16", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:03:16", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m(((((((((. ,0x1B[92m(############################(0x1B[32m../(((((((((.0x1B[97m\"", parent_process_id="7048", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m(((((((((. ,0x1B[92m(############################(0x1B[32m../(((((((((.0x1B[97m\"", process_id="7056", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:15", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:03:15", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m(((((((((((/* 0x1B[94m******************0x1B[32m/####### 0x1B[32m.(. ((((((0x1B[97m\"", parent_process_id="4508", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m(((((((((((/* 0x1B[94m******************0x1B[32m/####### 0x1B[32m.(. ((((((0x1B[97m\"", process_id="5176", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:15", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:03:15", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m((((((((((((((((* 0x1B[94m*****0x1B[32m,,,/########## 0x1B[32m.(* ,((((((0x1B[97m\"", parent_process_id="5832", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m((((((((((((((((* 0x1B[94m*****0x1B[32m,,,/########## 0x1B[32m.(* ,((((((0x1B[97m\"", process_id="6208", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:15", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:03:15", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m,/*,..*(((((((((((((((((((((((((((((((((,0x1B[97m\"", parent_process_id="7132", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m,/*,..*(((((((((((((((((((((((((((((((((,0x1B[97m\"", process_id="7144", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:16", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:03:16", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m(((((((((/, 0x1B[92m,####################(0x1B[32m/..((((((((((.0x1B[97m\"", parent_process_id="528", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m(((((((((/, 0x1B[92m,####################(0x1B[32m/..((((((((((.0x1B[97m\"", process_id="7084", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:15", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:03:15", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m((,.,/((((((((((((((((((((/, */0x1B[97m\"", parent_process_id="3660", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m((,.,/((((((((((((((((((((/, */0x1B[97m\"", process_id="3444", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:16", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:03:16", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m(((((((((/,. 0x1B[92m,*//////*,.0x1B[32m ./(((((((((((.0x1B[97m\"", parent_process_id="472", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m(((((((((/,. 0x1B[92m,*//////*,.0x1B[32m ./(((((((((((.0x1B[97m\"", process_id="5980", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747958, search_name="ESCU - Windows Indirect Command Execution Via forfiles - Rule", analyticstories="Living Off The Land", annotations="{\"analytic_story\":[\"Living Off The Land\"],\"cis20\":[\"CIS 10\"],\"confidence\":50,\"impact\":50,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1202\"],\"nist\":[\"DE.CM\"]}", annotations._all="Living Off The Land", annotations._all="CIS 10", annotations._all="DE.CM", annotations._all="Exploitation", annotations._all="T1202", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Living Off The Land", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1202", annotations.nist="DE.CM", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:03:16", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747952.760098000", lastTime="2023-06-14T13:03:16", parent_process="C:\\Windows\\system32\\cmd.exe /c FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m(((((((((((((((((((((((((((/0x1B[97m\"", parent_process_id="3660", parent_process_name="cmd.exe", process="FORFILES.EXE /P C:\\Temp\\ /M winpeas.bat /C \"CMD /C ECHO. 0x1B[32m(((((((((((((((((((((((((((/0x1B[97m\"", process_id="4780", process_name="forfiles.exe", process_path="C:\\Windows\\System32\\forfiles.exe", risk_message="The Program Compatability Assistant (pcalua.exe) launched the process forfiles.exe", risk_object="forfiles.exe", risk_object_type="other", risk_score="25.0", savedsearch_description="The following analytic detects programs that have been started by forfiles.exe. According to Microsoft, the 'The forfiles command lets you run a command on or pass arguments to multiple files'. While this tool can be used to start legitimate programs, usually within the context of a batch script, it has been observed being used to evade protections on command line execution.", user="Administrator" 1686747938, search_name="ESCU - Windows Cached Domain Credentials Reg Query - Rule", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":30,\"impact\":30,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1003.005\",\"T1003\"],\"nist\":[\"DE.AE\"]}", annotations._all="T1003", annotations._all="Windows Post-Exploitation", annotations._all="CIS 10", annotations._all="T1003.005", annotations._all="Exploitation", annotations._all="DE.AE", annotations._all="Prestige Ransomware", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1003.005", annotations.mitre_attack="T1003", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:01", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747931.978808000", lastTime="2023-06-14T13:04:01", original_file_name="unknown", parent_process="C:\\Windows\\System32\\cmd.exe", parent_process_guid="null", parent_process_name="cmd.exe", process="C:\\Windows\\System32\\reg.exe query \"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\" /v CACHEDLOGONSCOUNT", process_guid="null", process_id="0x1010", process_name="reg.exe", risk_message="a process with commandline C:\\Windows\\System32\\reg.exe query \"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\" /v CACHEDLOGONSCOUNT tries to retrieve cache domain credential logon count in ar-win-dc.attackrange.local", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="9.0", savedsearch_description="The following analytic identifies a process command line related to the discovery of cache domain credential logon count in the registry. This Technique was being abused by several post exploitation tool like Winpeas where it query CachedLogonsCount registry value in Winlogon registry. This value can be good information about the login caching setting on the Windows OS target host. A value of 0 means login caching is disable and values > 50 caches only 50 login attempts. By default all versions of Windows 10 save cached logins except Windows Server 2008.", user="Administrator" 1686747938, search_name="ESCU - Windows Cached Domain Credentials Reg Query - Rule", analyticstories="Prestige Ransomware", analyticstories="Windows Post-Exploitation", annotations="{\"analytic_story\":[\"Windows Post-Exploitation\",\"Prestige Ransomware\"],\"cis20\":[\"CIS 10\"],\"confidence\":30,\"impact\":30,\"kill_chain_phases\":[\"Exploitation\"],\"mitre_attack\":[\"T1003.005\",\"T1003\"],\"nist\":[\"DE.AE\"]}", annotations._all="T1003", annotations._all="Windows Post-Exploitation", annotations._all="CIS 10", annotations._all="T1003.005", annotations._all="Exploitation", annotations._all="DE.AE", annotations._all="Prestige Ransomware", annotations._frameworks="analytic_story", annotations._frameworks="cis20", annotations._frameworks="kill_chain_phases", annotations._frameworks="mitre_attack", annotations._frameworks="nist", annotations.analytic_story="Windows Post-Exploitation", annotations.analytic_story="Prestige Ransomware", annotations.cis20="CIS 10", annotations.kill_chain_phases="Exploitation", annotations.mitre_attack="T1003.005", annotations.mitre_attack="T1003", annotations.nist="DE.AE", count="1", dest="ar-win-dc.attackrange.local", firstTime="2023-06-14T13:04:01", info_max_time="1686747900.000000000", info_min_time="1686747300.000000000", info_search_time="1686747931.978808000", lastTime="2023-06-14T13:04:01", original_file_name="reg.exe", parent_process="\"cmd.exe\" /s /k pushd \"C:\\Temp\"", parent_process_guid="{953948C6-BA8E-6489-C200-00000000F902}", parent_process_name="cmd.exe", process="reg query \"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\" /v CACHEDLOGONSCOUNT", process_guid="{953948C6-BAC1-6489-E601-00000000F902}", process_id="4112", process_name="reg.exe", risk_message="a process with commandline reg query \"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\" /v CACHEDLOGONSCOUNT tries to retrieve cache domain credential logon count in ar-win-dc.attackrange.local", risk_object="ar-win-dc.attackrange.local", risk_object_type="system", risk_score="9.0", savedsearch_description="The following analytic identifies a process command line related to the discovery of cache domain credential logon count in the registry. This Technique was being abused by several post exploitation tool like Winpeas where it query CachedLogonsCount registry value in Winlogon registry. This value can be good information about the login caching setting on the Windows OS target host. A value of 0 means login caching is disable and values > 50 caches only 50 login attempts. By default all versions of Windows 10 save cached logins except Windows Server 2008.", user="Administrator"