title: NirCmd Tool Execution id: 4e2ed651-1906-4a59-a78a-18220fca1b22 status: experimental description: Detects the use of NirCmd tool for command execution, which could be the result of legitimate administrative activity author: Florian Roth date: 2022/01/24 references: - https://www.nirsoft.net/utils/nircmd.html - https://www.winhelponline.com/blog/run-program-as-system-localsystem-account-windows/ tags: - attack.execution - attack.t1569.002 - attack.s0029 logsource: category: process_creation product: windows detection: selection: Image|endswith: '\nircmd.exe' selection_params1: CommandLine|contains|all: - ' execmd ' - ' attrib ' selection_params2: CommandLine|contains|all: - ' execmd ' - ' copy ' selection_params3: CommandLine|contains|all: - ' execmd ' - ' del ' - ' /Q ' condition: 1 of selection* fields: - CommandLine - ParentCommandLine falsepositives: - Legitimate use by administrators level: medium