From ff107c3fe12964ca1568e219e54a465030c4010d Mon Sep 17 00:00:00 2001 From: Swachchhanda Shrawan Poudel <87493836+swachchhanda000@users.noreply.github.com> Date: Tue, 28 Apr 2026 02:11:12 +0545 Subject: [PATCH] Merge PR #5414 from @swachchhanda000 - Add `Indirect Command Execution via SFTP ProxyCommand` new: Indirect Command Execution via SFTP ProxyCommand --------- Co-authored-by: Nasreddine Bencherchali --- .../762bb580-79b4-40f4-8b9e-9349ce1710f4.evtx | Bin 0 -> 69632 bytes .../762bb580-79b4-40f4-8b9e-9349ce1710f4.json | 66 ++++++++++++++++++ .../info.yml | 13 ++++ ...ation_win_sftp_proxy_command_execution.yml | 26 +++++++ 4 files changed, 105 insertions(+) create mode 100644 regression_data/rules/windows/process_creation/proc_creation_win_lolbin_sftp_indirect_cmd_execution/762bb580-79b4-40f4-8b9e-9349ce1710f4.evtx create mode 100644 regression_data/rules/windows/process_creation/proc_creation_win_lolbin_sftp_indirect_cmd_execution/762bb580-79b4-40f4-8b9e-9349ce1710f4.json create mode 100644 regression_data/rules/windows/process_creation/proc_creation_win_lolbin_sftp_indirect_cmd_execution/info.yml create mode 100644 rules/windows/process_creation/proc_creation_win_sftp_proxy_command_execution.yml diff --git a/regression_data/rules/windows/process_creation/proc_creation_win_lolbin_sftp_indirect_cmd_execution/762bb580-79b4-40f4-8b9e-9349ce1710f4.evtx b/regression_data/rules/windows/process_creation/proc_creation_win_lolbin_sftp_indirect_cmd_execution/762bb580-79b4-40f4-8b9e-9349ce1710f4.evtx new file mode 100644 index 0000000000000000000000000000000000000000..e9224168d49bf65d86bd7990ed25b18a87679133 GIT binary patch literal 69632 zcmeI0TWp+1701u_?ZxZ0ch_!Xu1(marPL{QY;V@tZR(a(;ibO9!#S1Db6-Y>^JQaZ|aS^IOyub@mK^35a%>O_0eO|8{ zJ1Kqrf2-M@Z|2OIGrx1@%-EC5i}l9xf^C1osNphxLra+T1lvX4@q6vxZ{G2al}LdI zh=2%)fCz|y2#A0Ph=2%)fCz}dRS8TkFOHvSK4|e@_dESwrY8JTAk%Ah>-T?kRlQde z;5NE;&6xcoW%ifk)*iDFw2$H65O4Q+BfVopB)jO4!;wX^LB zv@LG4=OcLkSM*Pk_idYFCDO&Q&qno=kgY@Ki`(>2=31XWceEsLj{iZ^YWlxw2M@xh z1>5w0#eQe6ktF{QqLAK-wT`5ueH5}!N$g`@Kx-$)l+G^ z$1Xzix|45K5XMM>YMw&)O%TViw36SboEq zKy>+}rNex}(#fF94xk~9^!Idj*e4^g21qs07v{SxnZ%ykhnG0S=U++L6a?w3WhZ15 z3hf5G+z`d-5%|+$ox}z9g_ua#G1eK#)$7p? z&%U0u8Z@rMa7N2IR_gWUJFJjqQlQ(*Kkqe8?KN>tI}FM(TsAgVFh`t3e)PjmEZ~AO z{JfjUyZ1QlfH#e{WPj5c#q1me*YJs~$XF)L)JoSrTFrp)nTTx+Am3@3M9|~HiOHDH z=MbXfkeo#zHJ#mbT8{fISPSHWP-2BL6X!F$v0ubjQ_;LrXz{?n=S8;vi&`Mb9}{*c>u zM8W;xqmr4zC-2XkSg*uK2J2mONAC|l`q<0=z4y62ufbuIf)9U%|j{aaY{@pF<4!Ck1 z#Nurm=3o(J2O?SLdat=_TTsV|HOz%p;F$hs%==sV-?|azEzBh>L;3xYJiQ-TpF&9S z;8}wGVGd!mqb+sN<|^A0ZJ0~#GG+quJl+`DXE*&7=F+?H@rTbmm@=`1xsF|AnWeb- zxKl4eHsfWFMC&As%F6FzxN~qv>`Os;;{`SArGS*2(NoHJTM9+Aa$FTlPyv$f9N zFvolfD{qWO_O(W)k&t*5;-zQ}HuieSE7~{>$(XQ@ocIW6@wm?OC`U87w@(cYb6s?U$7FBlbjTV%3r_Qr=on0psSB#mh%L@FPQ(mGQ< zQ#&qbuKnidmokr_d>!Q`6dnOQF8mP@*g<4Tw()%w{TxrZ0e9^jLE8YXoh5t^Th)rF zAHh|&gx}jBF@pJdDJ|K)8^00czw_h9w@Dnj{)4O7IAmtFoe(o^7n%|@%tTqfiJp6~ zh8e^GFT!V`d%@iXs;HGwINLBR;cblj%*z)c%{^A!Hq!tkV@*Z$4nV3HW!VeZk?kHC z!>wQr@jnllL#P!|XuZFL$LAYuYh9?l^>c`-Wk|=?9>CbaXze~qxhHsoE^g+bHPmmx z+A84Nk6GS&G8VDA30x@G(A$2-&fowW26d9Jq4(2n&(7dPn#3-y+iB=NjNS^$FzTnU z?p0VwO*`FGW?&0%w+-w=dh%P}eQs%L4~{%M@o#|oaY!sd<|J$@+Za4@7`0=FiBZ^6 z!R$w{@(NljsPSzSWf-N3?-5v7N2#LJAXl>wJCE1UQ-5qAtDjzOx7kJnnq zTh+DHF)Jm?&@_tg5=M=njTY1}`(eDXg?cM!=lmlmbvJ6#=^Ju((ZVuhNAa0}JtwfX zX{@v6EE~g^66C0hbJrnTg?6r}gx_(@U&0LD+97D5PbSdHHd;xV-<*EFae5C~X6zSZ z*S;@&JjQX={&p>%