Proxy Execution via Console Window Host
Identifies abuse of the Console Window Host (conhost.exe) to execute commands via proxy. This behavior is used as a defense evasion technique to blend-in malicious activity with legitimate Windows software.
Elastic rule (View on GitHub)
1[metadata]
2creation_date = "2025/08/21"
3integration = ["endpoint", "windows", "system", "m365_defender", "sentinel_one_cloud_funnel", "crowdstrike"]
4maturity = "production"
5updated_date = "2026/09/18"
6
7[rule]
8author = ["Elastic"]
9description = """
10Identifies abuse of the Console Window Host (conhost.exe) to execute commands via proxy. This behavior is used as a defense
11evasion technique to blend-in malicious activity with legitimate Windows software.
12"""
13from = "now-9m"
14index = [
15 "endgame-*",
16 "logs-crowdstrike.fdr*",
17 "logs-endpoint.events.process-*",
18 "logs-m365_defender.event-*",
19 "logs-sentinel_one_cloud_funnel.*",
20 "logs-system.security*",
21 "logs-windows.forwarded*",
22 "logs-windows.sysmon_operational-*",
23 "winlogbeat-*",
24]
25language = "eql"
26license = "Elastic License v2"
27name = "Proxy Execution via Console Window Host"
28references = ["https://lolbas-project.github.io/lolbas/Binaries/Conhost/"]
29risk_score = 73
30rule_id = "fcd16fe8-eb29-42b3-8aee-6c9ad777a2f6"
31severity = "high"
32tags = [
33 "Domain: Endpoint",
34 "OS: Windows",
35 "Use Case: Threat Detection",
36 "Tactic: Defense Evasion",
37 "Data Source: Elastic Endgame",
38 "Data Source: Elastic Defend",
39 "Data Source: Windows Security Event Logs",
40 "Data Source: Microsoft Defender XDR",
41 "Data Source: Sysmon",
42 "Data Source: SentinelOne",
43 "Data Source: Crowdstrike",
44 "Resources: Investigation Guide",
45 "Noise: Medium",
46 "Performance: Normal",
47 "Rule Type: Event Correlation (EQL)",
48 "Platform: Windows",
49]
50timestamp_override = "event.ingested"
51type = "eql"
52
53query = '''
54process where host.os.type == "windows" and event.type == "start" and
55 process.name : "conhost.exe" and process.args : "--headless" and
56 process.command_line : (
57 "*powershell*", "*cmd *", "*cmd.exe *", "*script*", "*mshta*", "*curl *", "*curl.exe *", "*^*^*^*",
58 "*.bat*", "*.cmd*", "*schtasks*", "*@SSL*", "*http*", "* \\\\*", "*.vbs*", "*.js*", "*mhsta*"
59 ) and
60 not (
61 /* Winget-AutoUpdate via ServiceUI */
62 ?process.parent.executable : "?:\\Program Files\\winget-autoupdate*\\serviceui.exe" or
63 /* Winget-AutoUpdate notification via Task Scheduler */
64 (
65 ?process.parent.executable : "?:\\Windows\\System32\\svchost.exe" and ?process.parent.args : "-s" and
66 ?process.parent.args : "Schedule" and process.command_line : "*WAU-Notify.ps1*"
67 ) or
68 /* Windows OpenSSH console host — SSH-specific detection handled by 8cd49fbc-a35a-4418-8688-133cc3a1e548 */
69 ?process.parent.executable : (
70 "?:\\Windows\\System32\\OpenSSH\\sshd.exe",
71 "?:\\Windows\\System32\\OpenSSH\\sshd-session.exe",
72 "?:\\Program Files\\OpenSSH*\\sshd.exe",
73 "?:\\Program Files\\OpenSSH*\\sshd-session.exe"
74 )
75 )
76'''
77
78note = """## Triage and analysis
79
80### Investigating Proxy Execution via Console Window Host
81
82#### Possible investigation steps
83
84- What command did the headless conhost instance proxy?
85 - Why: `--headless` can hide the child window behind conhost, so command intent and child-process evidence outweigh conhost identity alone.
86 - Focus: `process.command_line` for `--headless` and the proxied family: shell, script host, retrieval, UNC, caret-escaped, batch, or scheduled-task action.
87 - Implication: escalate when headless conhost proxies script execution, remote retrieval, scheduled-task changes, or lateral-path commands; lower suspicion only when command, launcher, user, and host match remote-admin console management, deployment automation, or installer/update helper use and later process evidence does not contradict it.
88- Is this the native conhost binary or a masqueraded copy?
89 - Focus: `process.executable`, `process.pe.original_file_name`, `process.hash.sha256`, `process.code_signature.subject_name`, and `process.code_signature.trusted`; compare the path with `C:\\Windows\\System32\\conhost.exe`.
90 - Implication: escalate when conhost is renamed, unsigned, user-writable, host-new by hash, or signed by an unexpected publisher; native signed identity lowers masquerade concern but not suspicious `--headless` proxy execution.
91- Which launcher produced headless conhost?
92 - Focus: `process.parent.executable`, `process.parent.command_line`, and `process.parent.entity_id`.
93 - Implication: escalate when the launcher is Office, a browser, a script host, a temp or user-writable binary, another LOLBin, or a remote-management tool outside its console-management pattern; lower suspicion when the same parent is a stable console, deployment, or update path for the same `user.id` and `host.id`.
94- Do the user and session context fit the same admin or deployment use?
95 - Focus: `user.id`, `host.id`, `process.Ext.session_info.logon_type`, and `process.Ext.authentication_id`.
96 - Implication: escalate when session type, account, or authentication ID is unusual for that `host.id` and user cohort or ties to unrelated suspicious processes; lower suspicion when user, host cohort, session type, command, and lineage match the same remote-admin, deployment, or update use.
97- Did headless conhost spawn the command family named in the alert?
98 - Focus: child process starts on `host.id` where `process.parent.entity_id` matches alert `process.entity_id`; read `process.name`, `process.executable`, and `process.command_line`. $investigate_0
99 - Hint: if `process.entity_id` is absent, query the same `host.id` with alert `process.pid` in a tight alert-time window; treat matches as weaker because PID reuse is possible.
100 - Implication: escalate when conhost spawns shell, script-host, downloader, scheduled-task, or payload-like children; keep scope local only when no child execution appears and earlier evidence fits the same named admin, deployment, or update use.
101- If local evidence is suspicious or unresolved, is this isolated or broader proxy execution?
102 - Focus: process-start history for the same `host.id` and, if needed, `user.id`; compare `process.command_line`, `process.parent.executable`, and child-process patterns.
103 - $investigate_1
104 - $investigate_2
105 - Hint: review related alerts for the same `host.id` and `user.id`, especially script execution, downloader, scheduled-task, credential-tool, or other proxy-execution activity.
106 - $investigate_3
107 - $investigate_4
108 - Implication: escalate scope when the same host or user shows repeated headless conhost proxy execution, suspicious launchers, or related script, downloader, scheduled-task, or credential-tool processes; lack of history does not clear suspicious command, lineage, session, or child-process evidence.
109
110- Escalate on unauthorized headless proxy execution plus suspicious identity, launcher, session, child-process, or repeat-alert corroboration; close only when command, identity, lineage, session, and child-process evidence bind to one named benign use case below; preserve evidence and escalate when evidence is mixed or incomplete.
111
112### False positive analysis
113
114- Remote-administration, console-management, deployment automation, installer, or update agents can launch headless conhost when a named tool uses console helpers. Confirm that native `process.executable`, stable `process.parent.executable`, `process.parent.code_signature.subject_name`, `process.parent.code_signature.trusted`, parent and child `process.command_line`, `user.id`, `host.id`, `process.Ext.session_info.logon_type`, and child-process pattern all align with that tool or product path. Tool inventories, change records, or owner confirmation can corroborate telemetry-backed use, but should not replace missing or contradictory process evidence. If command, parent, session, or child evidence diverges, or the first cohort event includes retrieval, UNC, script-host, or scheduled-task behavior outside that path, treat it as unresolved or suspicious.
115- Before creating an exception, verify that native `process.executable`, parent identity, exact `process.command_line`, `user.id`, `host.id`, and session type recur across prior alerts from this rule. Build the exception from that confirmed workflow pattern; avoid exceptions on `process.name`, the conhost filename, or `--headless` alone.
116
117### Response and remediation
118
119- If confirmed benign, reverse temporary containment and record the command intent, native conhost identity, parent lineage, `user.id`, `host.id`, session type, and child-process evidence that justified closure. Create an exception only when that same admin, deployment, or update pattern recurs consistently across prior alerts.
120- If suspicious but unconfirmed, preserve the alert, process tree export, command lines, hash and signer details, `process.entity_id`, `process.parent.entity_id`, `process.Ext.authentication_id`, child-process events, and any scripts or task definitions named in the command line before containment. Apply reversible containment first, such as heightened monitoring or temporary restrictions on the affected `user.id`, `host.id`, or parent tool, and avoid process termination until scope is clearer.
121- If confirmed malicious, contain the host or affected account when command intent, launcher lineage, session context, or child-process evidence establishes unauthorized proxy execution. Record the process identifiers, command lines, signer and hash evidence, user and host anchors, and child-process chain before terminating processes, deleting scripts, disabling scheduled tasks, or isolating accounts.
122- Eradicate only the scripts, task definitions, copied tools, or persistence mechanisms identified during the investigation, then remediate the launcher, automation path, or access path that allowed headless conhost to proxy the command.
123- Rotate credentials only when the user and session evidence or adjacent case evidence confirms account misuse, remote abuse, or privileged account compromise; otherwise keep identity action proportional to the confirmed process evidence.
124- After containment, scope other hosts and users for the same `process.command_line`, `process.parent.executable`, `process.hash.sha256`, parent signer, or child-process pattern. Retain the process telemetry and response notes needed to distinguish repeat benign console automation from repeat proxy execution.
125"""
126
127setup = """## Setup
128
129This rule is designed for data generated by [Elastic Defend](https://www.elastic.co/security/endpoint-security), which provides native endpoint detection and response, along with event enrichments designed to work with our detection rules.
130
131Setup instructions: https://ela.st/install-elastic-defend
132
133### Additional data sources
134
135This rule also supports the following third-party data sources. For setup instructions, refer to the links below:
136
137- [CrowdStrike](https://ela.st/crowdstrike-integration)
138- [Microsoft Defender XDR](https://ela.st/m365-defender)
139- [SentinelOne Cloud Funnel](https://ela.st/sentinel-one-cloud-funnel)
140- [Sysmon Event ID 1 - Process Creation](https://ela.st/sysmon-event-1-setup)
141- [Windows Process Creation Logs](https://ela.st/audit-process-creation)
142"""
143
144[rule.investigation_fields]
145field_names = [
146 "@timestamp",
147 "host.name",
148 "host.id",
149 "user.name",
150 "user.id",
151 "process.entity_id",
152 "process.pid",
153 "process.executable",
154 "process.pe.original_file_name",
155 "process.command_line",
156 "process.Ext.authentication_id",
157 "process.Ext.session_info.logon_type",
158 "process.parent.executable",
159 "process.parent.command_line",
160 "process.code_signature.trusted",
161]
162
163[transform]
164
165[[transform.investigate]]
166label = "Child process starts from the same conhost instance"
167description = ""
168providers = [
169 [
170 { excluded = false, field = "event.category", queryType = "phrase", value = "process", valueType = "string" },
171 { excluded = false, field = "host.id", queryType = "phrase", value = "{{host.id}}", valueType = "string" },
172 { excluded = false, field = "process.parent.entity_id", queryType = "phrase", value = "{{process.entity_id}}", valueType = "string" }
173 ]
174]
175relativeFrom = "now-1h"
176relativeTo = "now"
177
178[[transform.investigate]]
179label = "Process history on the same host"
180description = ""
181providers = [
182 [
183 { excluded = false, field = "event.category", queryType = "phrase", value = "process", valueType = "string" },
184 { excluded = false, field = "host.id", queryType = "phrase", value = "{{host.id}}", valueType = "string" }
185 ]
186]
187relativeFrom = "now-48h/h"
188relativeTo = "now"
189
190[[transform.investigate]]
191label = "Process history for the same user"
192description = ""
193providers = [
194 [
195 { excluded = false, field = "event.category", queryType = "phrase", value = "process", valueType = "string" },
196 { excluded = false, field = "user.id", queryType = "phrase", value = "{{user.id}}", valueType = "string" }
197 ]
198]
199relativeFrom = "now-48h/h"
200relativeTo = "now"
201
202[[transform.investigate]]
203label = "Alerts associated with the host"
204description = ""
205providers = [
206 [
207 { excluded = false, field = "event.kind", queryType = "phrase", value = "signal", valueType = "string" },
208 { excluded = false, field = "host.id", queryType = "phrase", value = "{{host.id}}", valueType = "string" }
209 ]
210]
211relativeFrom = "now-48h/h"
212relativeTo = "now"
213
214[[transform.investigate]]
215label = "Alerts associated with the user"
216description = ""
217providers = [
218 [
219 { excluded = false, field = "event.kind", queryType = "phrase", value = "signal", valueType = "string" },
220 { excluded = false, field = "user.id", queryType = "phrase", value = "{{user.id}}", valueType = "string" }
221 ]
222]
223relativeFrom = "now-48h/h"
224relativeTo = "now"
225
226[[rule.threat]]
227framework = "MITRE ATT&CK"
228
229[[rule.threat.technique]]
230id = "T1202"
231name = "Indirect Command Execution"
232reference = "https://attack.mitre.org/techniques/T1202/"
233
234[rule.threat.tactic]
235id = "TA0005"
236name = "Defense Evasion"
237reference = "https://attack.mitre.org/tactics/TA0005/"
238
239[[rule.threat]]
240framework = "MITRE ATT&CK"
241
242[[rule.threat.technique]]
243id = "T1059"
244name = "Command and Scripting Interpreter"
245reference = "https://attack.mitre.org/techniques/T1059/"
246
247[[rule.threat.technique.subtechnique]]
248id = "T1059.001"
249name = "PowerShell"
250reference = "https://attack.mitre.org/techniques/T1059/001/"
251
252[[rule.threat.technique.subtechnique]]
253id = "T1059.003"
254name = "Windows Command Shell"
255reference = "https://attack.mitre.org/techniques/T1059/003/"
256
257[rule.threat.tactic]
258id = "TA0002"
259name = "Execution"
260reference = "https://attack.mitre.org/tactics/TA0002/"
Triage and analysis
Investigating Proxy Execution via Console Window Host
Possible investigation steps
-
What command did the headless conhost instance proxy?
- Why:
--headlesscan hide the child window behind conhost, so command intent and child-process evidence outweigh conhost identity alone. - Focus:
process.command_linefor--headlessand the proxied family: shell, script host, retrieval, UNC, caret-escaped, batch, or scheduled-task action. - Implication: escalate when headless conhost proxies script execution, remote retrieval, scheduled-task changes, or lateral-path commands; lower suspicion only when command, launcher, user, and host match remote-admin console management, deployment automation, or installer/update helper use and later process evidence does not contradict it.
- Why:
-
Is this the native conhost binary or a masqueraded copy?
- Focus:
process.executable,process.pe.original_file_name,process.hash.sha256,process.code_signature.subject_name, andprocess.code_signature.trusted; compare the path withC:\Windows\System32\conhost.exe. - Implication: escalate when conhost is renamed, unsigned, user-writable, host-new by hash, or signed by an unexpected publisher; native signed identity lowers masquerade concern but not suspicious
--headlessproxy execution.
- Focus:
-
Which launcher produced headless conhost?
- Focus:
process.parent.executable,process.parent.command_line, andprocess.parent.entity_id. - Implication: escalate when the launcher is Office, a browser, a script host, a temp or user-writable binary, another LOLBin, or a remote-management tool outside its console-management pattern; lower suspicion when the same parent is a stable console, deployment, or update path for the same
user.idandhost.id.
- Focus:
-
Do the user and session context fit the same admin or deployment use?
- Focus:
user.id,host.id,process.Ext.session_info.logon_type, andprocess.Ext.authentication_id. - Implication: escalate when session type, account, or authentication ID is unusual for that
host.idand user cohort or ties to unrelated suspicious processes; lower suspicion when user, host cohort, session type, command, and lineage match the same remote-admin, deployment, or update use.
- Focus:
-
Did headless conhost spawn the command family named in the alert?
- Focus: child process starts on
host.idwhereprocess.parent.entity_idmatches alertprocess.entity_id; readprocess.name,process.executable, andprocess.command_line. $investigate_0 - Hint: if
process.entity_idis absent, query the samehost.idwith alertprocess.pidin a tight alert-time window; treat matches as weaker because PID reuse is possible. - Implication: escalate when conhost spawns shell, script-host, downloader, scheduled-task, or payload-like children; keep scope local only when no child execution appears and earlier evidence fits the same named admin, deployment, or update use.
- Focus: child process starts on
-
If local evidence is suspicious or unresolved, is this isolated or broader proxy execution?
- Focus: process-start history for the same
host.idand, if needed,user.id; compareprocess.command_line,process.parent.executable, and child-process patterns.- $investigate_1
- $investigate_2
- Hint: review related alerts for the same
host.idanduser.id, especially script execution, downloader, scheduled-task, credential-tool, or other proxy-execution activity.- $investigate_3
- $investigate_4
- Implication: escalate scope when the same host or user shows repeated headless conhost proxy execution, suspicious launchers, or related script, downloader, scheduled-task, or credential-tool processes; lack of history does not clear suspicious command, lineage, session, or child-process evidence.
- Focus: process-start history for the same
-
Escalate on unauthorized headless proxy execution plus suspicious identity, launcher, session, child-process, or repeat-alert corroboration; close only when command, identity, lineage, session, and child-process evidence bind to one named benign use case below; preserve evidence and escalate when evidence is mixed or incomplete.
False positive analysis
- Remote-administration, console-management, deployment automation, installer, or update agents can launch headless conhost when a named tool uses console helpers. Confirm that native
process.executable, stableprocess.parent.executable,process.parent.code_signature.subject_name,process.parent.code_signature.trusted, parent and childprocess.command_line,user.id,host.id,process.Ext.session_info.logon_type, and child-process pattern all align with that tool or product path. Tool inventories, change records, or owner confirmation can corroborate telemetry-backed use, but should not replace missing or contradictory process evidence. If command, parent, session, or child evidence diverges, or the first cohort event includes retrieval, UNC, script-host, or scheduled-task behavior outside that path, treat it as unresolved or suspicious. - Before creating an exception, verify that native
process.executable, parent identity, exactprocess.command_line,user.id,host.id, and session type recur across prior alerts from this rule. Build the exception from that confirmed workflow pattern; avoid exceptions onprocess.name, the conhost filename, or--headlessalone.
Response and remediation
- If confirmed benign, reverse temporary containment and record the command intent, native conhost identity, parent lineage,
user.id,host.id, session type, and child-process evidence that justified closure. Create an exception only when that same admin, deployment, or update pattern recurs consistently across prior alerts. - If suspicious but unconfirmed, preserve the alert, process tree export, command lines, hash and signer details,
process.entity_id,process.parent.entity_id,process.Ext.authentication_id, child-process events, and any scripts or task definitions named in the command line before containment. Apply reversible containment first, such as heightened monitoring or temporary restrictions on the affecteduser.id,host.id, or parent tool, and avoid process termination until scope is clearer. - If confirmed malicious, contain the host or affected account when command intent, launcher lineage, session context, or child-process evidence establishes unauthorized proxy execution. Record the process identifiers, command lines, signer and hash evidence, user and host anchors, and child-process chain before terminating processes, deleting scripts, disabling scheduled tasks, or isolating accounts.
- Eradicate only the scripts, task definitions, copied tools, or persistence mechanisms identified during the investigation, then remediate the launcher, automation path, or access path that allowed headless conhost to proxy the command.
- Rotate credentials only when the user and session evidence or adjacent case evidence confirms account misuse, remote abuse, or privileged account compromise; otherwise keep identity action proportional to the confirmed process evidence.
- After containment, scope other hosts and users for the same
process.command_line,process.parent.executable,process.hash.sha256, parent signer, or child-process pattern. Retain the process telemetry and response notes needed to distinguish repeat benign console automation from repeat proxy execution.
References
Related rules
- Adding Hidden File Attribute via Attrib
- Attempt to Install or Run Kali Linux via WSL
- Clearing Windows Console History
- Command Execution via ForFiles
- Command Obfuscation via Unicode Modifier Letters