
Summary
Detects suspicious commands written into Windows Explorer’s address bar history (TypedPaths) which adversaries exploit by prompting a user to paste a command into a File Explorer or file-upload dialog. The command string is stored in registry TypedPaths values (registry.data.strings) under common explorer paths. The rule flags registry events where the stored string resembles execution commands (powershell, pwsh, cmd, mshta, msiexec, rundll32) or other living-off-the-land binaries (curl, wget, certutil, certreq, bitsadmin, wscript, cscript, conhost, forfiles, etc.). It then requires a matching child process of the writer (explorer.exe for File Explorer or a browser process hosting the dialog) and inspects that child’s commands and artifacts for payloads or secondary actions (files written to user-writable paths, downloads, installations, or network destinations). Further contextual checks review user/host activity to determine if the paste-and-run action aligns with a planned exercise or legitimate workflow. The rule maps to MITRE techniques that cover command/S scripting interpreter usage (PowerShell, Windows Command Shell), System Binary Proxy Execution (Mshta, Msiexec, Rundll32), and related execution/initial access paths, with a defense-evading angle when living-off-the-land binaries are used within a TypedPaths chain. Investigation guidance emphasizes correlating the TypedPaths string with the writing process, validating the child process and its descendants, and confirming any payloads or exfil destinations. False positives include benign security training, signed installers run via address bar, or misinterpreted file paths; these require consistent registry string fragments and matching process contexts across alerts. Remediation emphasizes containment, process termination of suspicious descendants, removal of payloads, and post-incident hardening (telemetry retention, paste/execution controls, and case documentation). The rule is designed to work with Elastic Defend and supports integrations with Defender XDR, SentinelOne Cloud Funnel, CrowdStrike, and Sysmon Registry events, among others.
Categories
- Endpoint
- Windows
Data Sources
- Windows Registry
- Process
ATT&CK Techniques
- T1059
- T1059.001
- T1059.003
- T1204
- T1204.002
- T1204.004
- T1218
- T1218.005
- T1218.007
- T1218.011
- T1566
- T1566.001
- T1566.002
- T1105
Created: 2026-09-28