SQL Server Engine Process Spawned Suspicious Shell Or LOL Bin
Query
// MSSQL xp_cmdshell / SQL Server Command Execution Detection
let LookBack = 7d;
let SqlEngine = dynamic(["sqlservr.exe", "sqlagent.exe", "sqlagent90.exe"]);
let ShellAndLolbins = dynamic([
"cmd.exe", "powershell.exe", "pwsh.exe", "mshta.exe", "wscript.exe",
"cscript.exe", "rundll32.exe", "regsvr32.exe", "bitsadmin.exe",
"certutil.exe", "curl.exe", "nc.exe", "ncat.exe", "wget.exe",
"python.exe", "python3.exe", "net.exe", "net1.exe", "reg.exe"
]);
let KnownGood = dynamic([
"wmic logicaldisk", // Disk monitoring
"haimportdatabasename", // AlwaysOn / HA rename
"get-foldersize.ps1" // Maintenance script
]);
DeviceProcessEvents
| where Timestamp > ago(LookBack)
// Match if parent or grandparent process is the SQL engine or SQL agent
| where InitiatingProcessFileName in~ (SqlEngine) or InitiatingProcessParentFileName in~ (SqlEngine)
| where FileName in~ (ShellAndLolbins)
| extend Cmd = tolower(ProcessCommandLine)
| extend IsPwsh = FileName in~ ("powershell.exe", "pwsh.exe")
// Encoded PowerShell: flag -e/-ec/-enc with a long Base64 string to avoid hitting -ExecutionPolicy
| extend SigEncoded = IsPwsh and Cmd matches regex @"\s-e[a-z]*\s+[a-z0-9+/]{40,}"
| extend SigRevShell = Cmd has_any ("tcpclient", "getstream") or Cmd contains "net.sockets"
| extend SigNetcat = Cmd contains "nc.exe" or Cmd contains "ncat.exe" or Cmd contains "-e cmd" or Cmd contains "-e powershell"
| extend SigRemoteHta = Cmd contains "mshta" and Cmd has_any ("http://", "https://")
| extend SigDownload = Cmd has_any ("downloadstring", "downloadfile", "bitsadmin", "certutil", "wget") or Cmd contains "invoke-webrequest" or Cmd contains "start-bitstransfer"
| extend SigIex = (Cmd contains "iex(" or Cmd contains "invoke-expression") and (Cmd contains "http" or Cmd contains "downloadstring")
| extend HighCount = toint(SigEncoded) + toint(SigRevShell) + toint(SigNetcat) + toint(SigRemoteHta) + toint(SigDownload) + toint(SigIex)
// Low-confidence indicators (requires at least 2 matches to trigger)
| extend SigHidden = Cmd contains "-w hidden" or Cmd contains "-windowstyle hidden"
| extend SigRecon = Cmd has_any ("whoami", "ipconfig", "hostname", "systeminfo") or Cmd contains "net user" or Cmd contains "net localgroup"
| extend LowCount = toint(SigHidden) + toint(SigRecon)
// Filter to keep only actual attack signatures
| where HighCount >= 1 or LowCount >= 2
| extend Indicators = set_difference(pack_array(
iff(SigEncoded, "EncodedPowerShell", ""),
iff(SigRevShell, "PowerShellReverseShell", ""),
iff(SigNetcat, "NetcatShell", ""),
iff(SigRemoteHta, "RemoteHTA", ""),
iff(SigDownload, "RemoteToolDownload", ""),
iff(SigIex, "DownloadCradle", ""),
iff(SigHidden, "HiddenWindow", ""),
iff(SigRecon, "HostRecon", "")
), dynamic([""]))
| extend Verdict = iff(HighCount >= 1,
"High: SQL engine spawned an attack tool",
"Suspicious: multiple low-severity indicators, investigation required")
| project
Timestamp,
DeviceName,
SqlServiceAccount = InitiatingProcessAccountName,
GrandparentProcess = InitiatingProcessParentFileName,
ParentProcess = InitiatingProcessFileName,
LaunchedProcess = FileName,
ProcessCommandLine,
Indicators,
Verdict,
DeviceId,
ReportId
| order by Timestamp descAbout this query
Explanation
This query is designed to detect potentially malicious activities involving SQL Server processes. Here's a simplified breakdown:
-
Purpose: The query identifies when SQL Server processes (
sqlservr.exeorsqlagent.exe) start command-line shells or tools that could be used for malicious purposes, such as executing commands or downloading files. -
Detection Mechanism:
- It looks back over the past 7 days for any suspicious activities.
- It checks if the SQL Server processes or their parent processes have launched known command-line shells or tools (like
cmd.exe,powershell.exe,mshta.exe, etc.). - It evaluates the command-line arguments for signs of malicious behavior, such as:
- Encoded PowerShell commands.
- Reverse shell commands.
- Use of tools like Netcat for network connections.
- Remote file downloads or execution of remote scripts.
- Host reconnaissance commands (e.g.,
whoami,ipconfig).
-
Scoring System:
- High-confidence indicators (like encoded PowerShell or reverse shells) are flagged immediately.
- Low-confidence indicators (like hidden windows or reconnaissance commands) require at least two matches to be flagged.
-
Output:
- The query outputs details of the suspicious activity, including the timestamp, device name, SQL service account, processes involved, command line used, detected indicators, and a verdict.
- The verdict categorizes the activity as either "High" (indicating a likely attack) or "Suspicious" (indicating potential malicious activity that needs further investigation).
-
Use Case: This query is useful for security teams to monitor and investigate potential security incidents involving SQL Server processes executing unauthorized or suspicious commands.