Skip to content

Commit 0881a66

Browse files
update: add new ref
1 parent ac75c74 commit 0881a66

File tree

1 file changed

+1
-0
lines changed

1 file changed

+1
-0
lines changed

rules/windows/process_creation/proc_creation_win_lolbin_sftp_indirect_cmd_execution.yml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -5,6 +5,7 @@ description: |
55
Detects potential abuse of SFTP.exe to execute commands indirectly via ProxyCommand parameter.
66
Threat actors can leverage this legitimate Windows binary to bypass security controls and execute arbitrary commands while evading detection.
77
references:
8+
- https://lolbas-project.github.io/lolbas/Binaries/Sftp/
89
- https://news.sophos.com/en-us/2025/05/09/lumma-stealer-coming-and-going/
910
author: Swachchhanda Shrawan Poudel (Nextron Systems)
1011
date: 2025-05-13

0 commit comments

Comments
 (0)