Query Details

SQL Server Engine Process Spawned Suspicious Shell Or LOL Bin

Query

// MSSQL xp_cmdshell / SQL Server Command Execution Detection
let LookBack = 7d;
let SqlEngine = dynamic(["sqlservr.exe", "sqlagent.exe", "sqlagent90.exe"]);
let ShellAndLolbins = dynamic([
"cmd.exe", "powershell.exe", "pwsh.exe", "mshta.exe", "wscript.exe",
"cscript.exe", "rundll32.exe", "regsvr32.exe", "bitsadmin.exe",
"certutil.exe", "curl.exe", "nc.exe", "ncat.exe", "wget.exe",
"python.exe", "python3.exe", "net.exe", "net1.exe", "reg.exe"
]);
let KnownGood = dynamic([
"wmic logicaldisk",                      // Disk monitoring
"haimportdatabasename",				    // AlwaysOn / HA rename
"get-foldersize.ps1"				    // Maintenance script
]);
DeviceProcessEvents
| where Timestamp > ago(LookBack)
// Match if parent or grandparent process is the SQL engine or SQL agent
| where InitiatingProcessFileName in~ (SqlEngine) or InitiatingProcessParentFileName in~ (SqlEngine)
| where FileName in~ (ShellAndLolbins)
| extend Cmd = tolower(ProcessCommandLine)
| extend IsPwsh = FileName in~ ("powershell.exe", "pwsh.exe")
// Encoded PowerShell: flag -e/-ec/-enc with a long Base64 string to avoid hitting -ExecutionPolicy
| extend SigEncoded  = IsPwsh and Cmd matches regex @"\s-e[a-z]*\s+[a-z0-9+/]{40,}"
| extend SigRevShell = Cmd has_any ("tcpclient", "getstream") or Cmd contains "net.sockets"
| extend SigNetcat   = Cmd contains "nc.exe" or Cmd contains "ncat.exe" or Cmd contains "-e cmd" or Cmd contains "-e powershell"
| extend SigRemoteHta = Cmd contains "mshta" and Cmd has_any ("http://", "https://")
| extend SigDownload = Cmd has_any ("downloadstring", "downloadfile", "bitsadmin", "certutil", "wget") or Cmd contains "invoke-webrequest" or Cmd contains "start-bitstransfer"
| extend SigIex      = (Cmd contains "iex(" or Cmd contains "invoke-expression") and (Cmd contains "http" or Cmd contains "downloadstring")
| extend HighCount = toint(SigEncoded) + toint(SigRevShell) + toint(SigNetcat) + toint(SigRemoteHta) + toint(SigDownload) + toint(SigIex)
// Low-confidence indicators (requires at least 2 matches to trigger)
| extend SigHidden = Cmd contains "-w hidden" or Cmd contains "-windowstyle hidden"
| extend SigRecon  = Cmd has_any ("whoami", "ipconfig", "hostname", "systeminfo") or Cmd contains "net user" or Cmd contains "net localgroup"
| extend LowCount = toint(SigHidden) + toint(SigRecon)
// Filter to keep only actual attack signatures
| where HighCount >= 1 or LowCount >= 2
| extend Indicators = set_difference(pack_array(
    iff(SigEncoded,   "EncodedPowerShell", ""),
    iff(SigRevShell,  "PowerShellReverseShell", ""),
    iff(SigNetcat,    "NetcatShell", ""),
    iff(SigRemoteHta, "RemoteHTA", ""),
    iff(SigDownload,  "RemoteToolDownload", ""),
    iff(SigIex,       "DownloadCradle", ""),
    iff(SigHidden,    "HiddenWindow", ""),
    iff(SigRecon,     "HostRecon", "")
), dynamic([""]))
| extend Verdict = iff(HighCount >= 1,
    "High: SQL engine spawned an attack tool",
    "Suspicious: multiple low-severity indicators, investigation required")
| project
Timestamp,
DeviceName,
SqlServiceAccount  = InitiatingProcessAccountName,
GrandparentProcess = InitiatingProcessParentFileName,
ParentProcess      = InitiatingProcessFileName,
LaunchedProcess    = FileName,
ProcessCommandLine,
Indicators,
Verdict,
DeviceId,
ReportId
| order by Timestamp desc

About this query

Explanation

This query is designed to detect potentially malicious activities involving SQL Server processes. Here's a simplified breakdown:

  1. Purpose: The query identifies when SQL Server processes (sqlservr.exe or sqlagent.exe) start command-line shells or tools that could be used for malicious purposes, such as executing commands or downloading files.

  2. Detection Mechanism:

    • It looks back over the past 7 days for any suspicious activities.
    • It checks if the SQL Server processes or their parent processes have launched known command-line shells or tools (like cmd.exe, powershell.exe, mshta.exe, etc.).
    • It evaluates the command-line arguments for signs of malicious behavior, such as:
      • Encoded PowerShell commands.
      • Reverse shell commands.
      • Use of tools like Netcat for network connections.
      • Remote file downloads or execution of remote scripts.
      • Host reconnaissance commands (e.g., whoami, ipconfig).
  3. Scoring System:

    • High-confidence indicators (like encoded PowerShell or reverse shells) are flagged immediately.
    • Low-confidence indicators (like hidden windows or reconnaissance commands) require at least two matches to be flagged.
  4. Output:

    • The query outputs details of the suspicious activity, including the timestamp, device name, SQL service account, processes involved, command line used, detected indicators, and a verdict.
    • The verdict categorizes the activity as either "High" (indicating a likely attack) or "Suspicious" (indicating potential malicious activity that needs further investigation).
  5. Use Case: This query is useful for security teams to monitor and investigate potential security incidents involving SQL Server processes executing unauthorized or suspicious commands.