Proxy Execution via Console Window Host

Identifies abuse of the Console Window Host (conhost.exe) to execute commands via proxy. This behavior is used as a defense evasion technique to blend-in malicious activity with legitimate Windows software.

Elastic rule (View on GitHub)

  1[metadata]
  2creation_date = "2025/08/21"
  3integration = ["endpoint", "windows", "system", "m365_defender", "sentinel_one_cloud_funnel", "crowdstrike"]
  4maturity = "production"
  5updated_date = "2026/09/18"
  6
  7[rule]
  8author = ["Elastic"]
  9description = """
 10Identifies abuse of the Console Window Host (conhost.exe) to execute commands via proxy. This behavior is used as a defense
 11evasion technique to blend-in malicious activity with legitimate Windows software.
 12"""
 13from = "now-9m"
 14index = [
 15    "endgame-*",
 16    "logs-crowdstrike.fdr*",
 17    "logs-endpoint.events.process-*",
 18    "logs-m365_defender.event-*",
 19    "logs-sentinel_one_cloud_funnel.*",
 20    "logs-system.security*",
 21    "logs-windows.forwarded*",
 22    "logs-windows.sysmon_operational-*",
 23    "winlogbeat-*",
 24]
 25language = "eql"
 26license = "Elastic License v2"
 27name = "Proxy Execution via Console Window Host"
 28references = ["https://lolbas-project.github.io/lolbas/Binaries/Conhost/"]
 29risk_score = 73
 30rule_id = "fcd16fe8-eb29-42b3-8aee-6c9ad777a2f6"
 31severity = "high"
 32tags = [
 33    "Domain: Endpoint",
 34    "OS: Windows",
 35    "Use Case: Threat Detection",
 36    "Tactic: Defense Evasion",
 37    "Data Source: Elastic Endgame",
 38    "Data Source: Elastic Defend",
 39    "Data Source: Windows Security Event Logs",
 40    "Data Source: Microsoft Defender XDR",
 41    "Data Source: Sysmon",
 42    "Data Source: SentinelOne",
 43    "Data Source: Crowdstrike",
 44    "Resources: Investigation Guide",
 45    "Noise: Medium",
 46    "Performance: Normal",
 47    "Rule Type: Event Correlation (EQL)",
 48    "Platform: Windows",
 49]
 50timestamp_override = "event.ingested"
 51type = "eql"
 52
 53query = '''
 54process where host.os.type == "windows" and event.type == "start" and
 55 process.name : "conhost.exe" and process.args : "--headless" and
 56  process.command_line : (
 57    "*powershell*", "*cmd *", "*cmd.exe *", "*script*", "*mshta*", "*curl *", "*curl.exe *", "*^*^*^*",
 58    "*.bat*", "*.cmd*", "*schtasks*", "*@SSL*", "*http*", "* \\\\*", "*.vbs*", "*.js*", "*mhsta*"
 59  ) and
 60  not (
 61    /* Winget-AutoUpdate via ServiceUI */
 62    ?process.parent.executable : "?:\\Program Files\\winget-autoupdate*\\serviceui.exe" or
 63    /* Winget-AutoUpdate notification via Task Scheduler */
 64    (
 65      ?process.parent.executable : "?:\\Windows\\System32\\svchost.exe" and ?process.parent.args : "-s" and
 66      ?process.parent.args : "Schedule" and process.command_line : "*WAU-Notify.ps1*"
 67    ) or
 68    /* Windows OpenSSH console host — SSH-specific detection handled by 8cd49fbc-a35a-4418-8688-133cc3a1e548 */
 69    ?process.parent.executable : (
 70      "?:\\Windows\\System32\\OpenSSH\\sshd.exe",
 71      "?:\\Windows\\System32\\OpenSSH\\sshd-session.exe",
 72      "?:\\Program Files\\OpenSSH*\\sshd.exe",
 73      "?:\\Program Files\\OpenSSH*\\sshd-session.exe"
 74    )
 75  )
 76'''
 77
 78note = """## Triage and analysis
 79
 80### Investigating Proxy Execution via Console Window Host
 81
 82#### Possible investigation steps
 83
 84- What command did the headless conhost instance proxy?
 85  - Why: `--headless` can hide the child window behind conhost, so command intent and child-process evidence outweigh conhost identity alone.
 86  - Focus: `process.command_line` for `--headless` and the proxied family: shell, script host, retrieval, UNC, caret-escaped, batch, or scheduled-task action.
 87  - Implication: escalate when headless conhost proxies script execution, remote retrieval, scheduled-task changes, or lateral-path commands; lower suspicion only when command, launcher, user, and host match remote-admin console management, deployment automation, or installer/update helper use and later process evidence does not contradict it.
 88- Is this the native conhost binary or a masqueraded copy?
 89  - Focus: `process.executable`, `process.pe.original_file_name`, `process.hash.sha256`, `process.code_signature.subject_name`, and `process.code_signature.trusted`; compare the path with `C:\\Windows\\System32\\conhost.exe`.
 90  - Implication: escalate when conhost is renamed, unsigned, user-writable, host-new by hash, or signed by an unexpected publisher; native signed identity lowers masquerade concern but not suspicious `--headless` proxy execution.
 91- Which launcher produced headless conhost?
 92  - Focus: `process.parent.executable`, `process.parent.command_line`, and `process.parent.entity_id`.
 93  - Implication: escalate when the launcher is Office, a browser, a script host, a temp or user-writable binary, another LOLBin, or a remote-management tool outside its console-management pattern; lower suspicion when the same parent is a stable console, deployment, or update path for the same `user.id` and `host.id`.
 94- Do the user and session context fit the same admin or deployment use?
 95  - Focus: `user.id`, `host.id`, `process.Ext.session_info.logon_type`, and `process.Ext.authentication_id`.
 96  - Implication: escalate when session type, account, or authentication ID is unusual for that `host.id` and user cohort or ties to unrelated suspicious processes; lower suspicion when user, host cohort, session type, command, and lineage match the same remote-admin, deployment, or update use.
 97- Did headless conhost spawn the command family named in the alert?
 98  - Focus: child process starts on `host.id` where `process.parent.entity_id` matches alert `process.entity_id`; read `process.name`, `process.executable`, and `process.command_line`. $investigate_0
 99  - Hint: if `process.entity_id` is absent, query the same `host.id` with alert `process.pid` in a tight alert-time window; treat matches as weaker because PID reuse is possible.
100  - Implication: escalate when conhost spawns shell, script-host, downloader, scheduled-task, or payload-like children; keep scope local only when no child execution appears and earlier evidence fits the same named admin, deployment, or update use.
101- If local evidence is suspicious or unresolved, is this isolated or broader proxy execution?
102  - Focus: process-start history for the same `host.id` and, if needed, `user.id`; compare `process.command_line`, `process.parent.executable`, and child-process patterns.
103    - $investigate_1
104    - $investigate_2
105  - Hint: review related alerts for the same `host.id` and `user.id`, especially script execution, downloader, scheduled-task, credential-tool, or other proxy-execution activity.
106    - $investigate_3
107    - $investigate_4
108  - Implication: escalate scope when the same host or user shows repeated headless conhost proxy execution, suspicious launchers, or related script, downloader, scheduled-task, or credential-tool processes; lack of history does not clear suspicious command, lineage, session, or child-process evidence.
109
110- Escalate on unauthorized headless proxy execution plus suspicious identity, launcher, session, child-process, or repeat-alert corroboration; close only when command, identity, lineage, session, and child-process evidence bind to one named benign use case below; preserve evidence and escalate when evidence is mixed or incomplete.
111
112### False positive analysis
113
114- Remote-administration, console-management, deployment automation, installer, or update agents can launch headless conhost when a named tool uses console helpers. Confirm that native `process.executable`, stable `process.parent.executable`, `process.parent.code_signature.subject_name`, `process.parent.code_signature.trusted`, parent and child `process.command_line`, `user.id`, `host.id`, `process.Ext.session_info.logon_type`, and child-process pattern all align with that tool or product path. Tool inventories, change records, or owner confirmation can corroborate telemetry-backed use, but should not replace missing or contradictory process evidence. If command, parent, session, or child evidence diverges, or the first cohort event includes retrieval, UNC, script-host, or scheduled-task behavior outside that path, treat it as unresolved or suspicious.
115- Before creating an exception, verify that native `process.executable`, parent identity, exact `process.command_line`, `user.id`, `host.id`, and session type recur across prior alerts from this rule. Build the exception from that confirmed workflow pattern; avoid exceptions on `process.name`, the conhost filename, or `--headless` alone.
116
117### Response and remediation
118
119- If confirmed benign, reverse temporary containment and record the command intent, native conhost identity, parent lineage, `user.id`, `host.id`, session type, and child-process evidence that justified closure. Create an exception only when that same admin, deployment, or update pattern recurs consistently across prior alerts.
120- If suspicious but unconfirmed, preserve the alert, process tree export, command lines, hash and signer details, `process.entity_id`, `process.parent.entity_id`, `process.Ext.authentication_id`, child-process events, and any scripts or task definitions named in the command line before containment. Apply reversible containment first, such as heightened monitoring or temporary restrictions on the affected `user.id`, `host.id`, or parent tool, and avoid process termination until scope is clearer.
121- If confirmed malicious, contain the host or affected account when command intent, launcher lineage, session context, or child-process evidence establishes unauthorized proxy execution. Record the process identifiers, command lines, signer and hash evidence, user and host anchors, and child-process chain before terminating processes, deleting scripts, disabling scheduled tasks, or isolating accounts.
122- Eradicate only the scripts, task definitions, copied tools, or persistence mechanisms identified during the investigation, then remediate the launcher, automation path, or access path that allowed headless conhost to proxy the command.
123- Rotate credentials only when the user and session evidence or adjacent case evidence confirms account misuse, remote abuse, or privileged account compromise; otherwise keep identity action proportional to the confirmed process evidence.
124- After containment, scope other hosts and users for the same `process.command_line`, `process.parent.executable`, `process.hash.sha256`, parent signer, or child-process pattern. Retain the process telemetry and response notes needed to distinguish repeat benign console automation from repeat proxy execution.
125"""
126
127setup = """## Setup
128
129This rule is designed for data generated by [Elastic Defend](https://www.elastic.co/security/endpoint-security), which provides native endpoint detection and response, along with event enrichments designed to work with our detection rules.
130
131Setup instructions: https://ela.st/install-elastic-defend
132
133### Additional data sources
134
135This rule also supports the following third-party data sources. For setup instructions, refer to the links below:
136
137- [CrowdStrike](https://ela.st/crowdstrike-integration)
138- [Microsoft Defender XDR](https://ela.st/m365-defender)
139- [SentinelOne Cloud Funnel](https://ela.st/sentinel-one-cloud-funnel)
140- [Sysmon Event ID 1 - Process Creation](https://ela.st/sysmon-event-1-setup)
141- [Windows Process Creation Logs](https://ela.st/audit-process-creation)
142"""
143
144[rule.investigation_fields]
145field_names = [
146    "@timestamp",
147    "host.name",
148    "host.id",
149    "user.name",
150    "user.id",
151    "process.entity_id",
152    "process.pid",
153    "process.executable",
154    "process.pe.original_file_name",
155    "process.command_line",
156    "process.Ext.authentication_id",
157    "process.Ext.session_info.logon_type",
158    "process.parent.executable",
159    "process.parent.command_line",
160    "process.code_signature.trusted",
161]
162
163[transform]
164
165[[transform.investigate]]
166label = "Child process starts from the same conhost instance"
167description = ""
168providers = [
169  [
170    { excluded = false, field = "event.category", queryType = "phrase", value = "process", valueType = "string" },
171    { excluded = false, field = "host.id", queryType = "phrase", value = "{{host.id}}", valueType = "string" },
172    { excluded = false, field = "process.parent.entity_id", queryType = "phrase", value = "{{process.entity_id}}", valueType = "string" }
173  ]
174]
175relativeFrom = "now-1h"
176relativeTo = "now"
177
178[[transform.investigate]]
179label = "Process history on the same host"
180description = ""
181providers = [
182  [
183    { excluded = false, field = "event.category", queryType = "phrase", value = "process", valueType = "string" },
184    { excluded = false, field = "host.id", queryType = "phrase", value = "{{host.id}}", valueType = "string" }
185  ]
186]
187relativeFrom = "now-48h/h"
188relativeTo = "now"
189
190[[transform.investigate]]
191label = "Process history for the same user"
192description = ""
193providers = [
194  [
195    { excluded = false, field = "event.category", queryType = "phrase", value = "process", valueType = "string" },
196    { excluded = false, field = "user.id", queryType = "phrase", value = "{{user.id}}", valueType = "string" }
197  ]
198]
199relativeFrom = "now-48h/h"
200relativeTo = "now"
201
202[[transform.investigate]]
203label = "Alerts associated with the host"
204description = ""
205providers = [
206  [
207    { excluded = false, field = "event.kind", queryType = "phrase", value = "signal", valueType = "string" },
208    { excluded = false, field = "host.id", queryType = "phrase", value = "{{host.id}}", valueType = "string" }
209  ]
210]
211relativeFrom = "now-48h/h"
212relativeTo = "now"
213
214[[transform.investigate]]
215label = "Alerts associated with the user"
216description = ""
217providers = [
218  [
219    { excluded = false, field = "event.kind", queryType = "phrase", value = "signal", valueType = "string" },
220    { excluded = false, field = "user.id", queryType = "phrase", value = "{{user.id}}", valueType = "string" }
221  ]
222]
223relativeFrom = "now-48h/h"
224relativeTo = "now"
225
226[[rule.threat]]
227framework = "MITRE ATT&CK"
228
229[[rule.threat.technique]]
230id = "T1202"
231name = "Indirect Command Execution"
232reference = "https://attack.mitre.org/techniques/T1202/"
233
234[rule.threat.tactic]
235id = "TA0005"
236name = "Defense Evasion"
237reference = "https://attack.mitre.org/tactics/TA0005/"
238
239[[rule.threat]]
240framework = "MITRE ATT&CK"
241
242[[rule.threat.technique]]
243id = "T1059"
244name = "Command and Scripting Interpreter"
245reference = "https://attack.mitre.org/techniques/T1059/"
246
247[[rule.threat.technique.subtechnique]]
248id = "T1059.001"
249name = "PowerShell"
250reference = "https://attack.mitre.org/techniques/T1059/001/"
251
252[[rule.threat.technique.subtechnique]]
253id = "T1059.003"
254name = "Windows Command Shell"
255reference = "https://attack.mitre.org/techniques/T1059/003/"
256
257[rule.threat.tactic]
258id = "TA0002"
259name = "Execution"
260reference = "https://attack.mitre.org/tactics/TA0002/"

Triage and analysis

Investigating Proxy Execution via Console Window Host

Possible investigation steps

  • What command did the headless conhost instance proxy?

    • Why: --headless can hide the child window behind conhost, so command intent and child-process evidence outweigh conhost identity alone.
    • Focus: process.command_line for --headless and the proxied family: shell, script host, retrieval, UNC, caret-escaped, batch, or scheduled-task action.
    • Implication: escalate when headless conhost proxies script execution, remote retrieval, scheduled-task changes, or lateral-path commands; lower suspicion only when command, launcher, user, and host match remote-admin console management, deployment automation, or installer/update helper use and later process evidence does not contradict it.
  • Is this the native conhost binary or a masqueraded copy?

    • Focus: process.executable, process.pe.original_file_name, process.hash.sha256, process.code_signature.subject_name, and process.code_signature.trusted; compare the path with C:\Windows\System32\conhost.exe.
    • Implication: escalate when conhost is renamed, unsigned, user-writable, host-new by hash, or signed by an unexpected publisher; native signed identity lowers masquerade concern but not suspicious --headless proxy execution.
  • Which launcher produced headless conhost?

    • Focus: process.parent.executable, process.parent.command_line, and process.parent.entity_id.
    • Implication: escalate when the launcher is Office, a browser, a script host, a temp or user-writable binary, another LOLBin, or a remote-management tool outside its console-management pattern; lower suspicion when the same parent is a stable console, deployment, or update path for the same user.id and host.id.
  • Do the user and session context fit the same admin or deployment use?

    • Focus: user.id, host.id, process.Ext.session_info.logon_type, and process.Ext.authentication_id.
    • Implication: escalate when session type, account, or authentication ID is unusual for that host.id and user cohort or ties to unrelated suspicious processes; lower suspicion when user, host cohort, session type, command, and lineage match the same remote-admin, deployment, or update use.
  • Did headless conhost spawn the command family named in the alert?

    • Focus: child process starts on host.id where process.parent.entity_id matches alert process.entity_id; read process.name, process.executable, and process.command_line. $investigate_0
    • Hint: if process.entity_id is absent, query the same host.id with alert process.pid in a tight alert-time window; treat matches as weaker because PID reuse is possible.
    • Implication: escalate when conhost spawns shell, script-host, downloader, scheduled-task, or payload-like children; keep scope local only when no child execution appears and earlier evidence fits the same named admin, deployment, or update use.
  • If local evidence is suspicious or unresolved, is this isolated or broader proxy execution?

    • Focus: process-start history for the same host.id and, if needed, user.id; compare process.command_line, process.parent.executable, and child-process patterns.
      • $investigate_1
      • $investigate_2
    • Hint: review related alerts for the same host.id and user.id, especially script execution, downloader, scheduled-task, credential-tool, or other proxy-execution activity.
      • $investigate_3
      • $investigate_4
    • Implication: escalate scope when the same host or user shows repeated headless conhost proxy execution, suspicious launchers, or related script, downloader, scheduled-task, or credential-tool processes; lack of history does not clear suspicious command, lineage, session, or child-process evidence.
  • Escalate on unauthorized headless proxy execution plus suspicious identity, launcher, session, child-process, or repeat-alert corroboration; close only when command, identity, lineage, session, and child-process evidence bind to one named benign use case below; preserve evidence and escalate when evidence is mixed or incomplete.

False positive analysis

  • Remote-administration, console-management, deployment automation, installer, or update agents can launch headless conhost when a named tool uses console helpers. Confirm that native process.executable, stable process.parent.executable, process.parent.code_signature.subject_name, process.parent.code_signature.trusted, parent and child process.command_line, user.id, host.id, process.Ext.session_info.logon_type, and child-process pattern all align with that tool or product path. Tool inventories, change records, or owner confirmation can corroborate telemetry-backed use, but should not replace missing or contradictory process evidence. If command, parent, session, or child evidence diverges, or the first cohort event includes retrieval, UNC, script-host, or scheduled-task behavior outside that path, treat it as unresolved or suspicious.
  • Before creating an exception, verify that native process.executable, parent identity, exact process.command_line, user.id, host.id, and session type recur across prior alerts from this rule. Build the exception from that confirmed workflow pattern; avoid exceptions on process.name, the conhost filename, or --headless alone.

Response and remediation

  • If confirmed benign, reverse temporary containment and record the command intent, native conhost identity, parent lineage, user.id, host.id, session type, and child-process evidence that justified closure. Create an exception only when that same admin, deployment, or update pattern recurs consistently across prior alerts.
  • If suspicious but unconfirmed, preserve the alert, process tree export, command lines, hash and signer details, process.entity_id, process.parent.entity_id, process.Ext.authentication_id, child-process events, and any scripts or task definitions named in the command line before containment. Apply reversible containment first, such as heightened monitoring or temporary restrictions on the affected user.id, host.id, or parent tool, and avoid process termination until scope is clearer.
  • If confirmed malicious, contain the host or affected account when command intent, launcher lineage, session context, or child-process evidence establishes unauthorized proxy execution. Record the process identifiers, command lines, signer and hash evidence, user and host anchors, and child-process chain before terminating processes, deleting scripts, disabling scheduled tasks, or isolating accounts.
  • Eradicate only the scripts, task definitions, copied tools, or persistence mechanisms identified during the investigation, then remediate the launcher, automation path, or access path that allowed headless conhost to proxy the command.
  • Rotate credentials only when the user and session evidence or adjacent case evidence confirms account misuse, remote abuse, or privileged account compromise; otherwise keep identity action proportional to the confirmed process evidence.
  • After containment, scope other hosts and users for the same process.command_line, process.parent.executable, process.hash.sha256, parent signer, or child-process pattern. Retain the process telemetry and response notes needed to distinguish repeat benign console automation from repeat proxy execution.

References

Related rules

to-top