A browser launching a command interpreter deserves context. It can be an approved protocol handler or a sign that a downloaded file or web-delivered workflow crossed into local execution.
Technique & Investigation of the Day · Threat Hunting Lab 01
By Amit Vijayan · Technical review: September 21, 2026
Why it matters
This hunt focuses on browser-to-shell process chains. Its goal is a defensible explanation of observed behavior, supported by evidence and tested against legitimate alternatives.
Hunt hypothesis: A browser directly launched a shell or script host outside an approved business workflow.
Telemetry and preparation
The KQL example uses Microsoft Defender XDR advanced hunting and the DeviceProcessEvents table. It is not a Sentinel SecurityEvent query. Confirm licensing, sensor coverage, retention and the table’s actual populated fields before searching. Preserve UTC timestamps, device and account identifiers, raw records and collection scope.
For Splunk, the example expects Sysmon Event 1 in your own index and extracted Windows XML fields. Replace YOUR_SYSMON_INDEX and map Computer, EventCode and the fields shown in the query to your deployment. Missing fields must be corrected before interpreting results.
Read-only starting points: These queries have been reviewed against documented schemas but have not been executed in your environment. Test and adapt them only in authorized environments, starting with a small time range. They retrieve or summarize logs; they do not remediate endpoints. Review sensitive command lines and account data under your evidence-handling rules.
Step-by-step investigation
- Confirm the parent-child relationship in raw telemetry; record both process start times, user and full command lines. A process name alone does not establish ancestry.
- Determine whether a browser extension, native messaging host, protocol handler or downloaded installer explains the transition. Ask the endpoint owner about the exact time, not merely whether they use that browser.
- Review the child’s descendants, files and network activity within a bounded window. Preserve the originating URL from approved browser or proxy evidence when available.
- Scope matching command lines and file hashes across comparable endpoints. Record that this direct-parent search misses intermediaries such as explorer.exe.
Sample query: Microsoft Defender XDR KQL
DeviceProcessEvents
| where Timestamp > ago(24h)
| where InitiatingProcessFileName in~ ("chrome.exe", "msedge.exe", "firefox.exe")
| where FileName in~ ("cmd.exe", "powershell.exe", "pwsh.exe", "wscript.exe", "cscript.exe")
| project Timestamp, DeviceId, DeviceName, AccountDomain, AccountName, FileName, FolderPath, ProcessCommandLine, ProcessId, ProcessCreationTime, InitiatingProcessFileName, InitiatingProcessCommandLine, InitiatingProcessId, InitiatingProcessCreationTime, SHA1
| order by Timestamp desc
| take 200Sample query: Splunk SPL
index=YOUR_SYSMON_INDEX EventCode=1 earliest=-24h latest=now
| where match(lower(ParentImage), "(chrome|msedge|firefox)[.]exe$") AND match(lower(Image), "(cmd|powershell|pwsh|wscript|cscript)[.]exe$")
| table _time Computer User Image CommandLine ProcessGuid ParentImage ParentCommandLine ParentProcessGuid Hashes
| sort 0 - _time
| head 200The display is capped at the latest 200 rows. That cap is for triage, not a completeness guarantee; remove or paginate it under local search limits when scoping a case. Defender and Splunk examples pursue the same hypothesis but need not return identical counts because their sources and collection rules differ.
Two worked reasoning examples
These are fictional teaching scenarios, not reports of a real incident.
Example A: a legitimate explanation to verify
A signed enterprise application registered as a protocol handler may launch an approved helper. Validate its registration, installation source and matching user action before creating a narrow exception.
Example B: evidence that raises concern
A browser launches a shell that writes an unapproved executable and contacts a newly observed destination. That combination warrants escalation; the direct-parent match alone does not.
Tuning and coverage limits
Baseline by browser, endpoint role and approved handler. Avoid excluding all browser-launched PowerShell or an entire user profile directory.
Blind spot: This detects only listed interpreters with an immediate browser parent. Indirect chains and renamed executables are outside its coverage.
Before promoting the hunt into an alert, inspect a sample of matching and known-good events, measure daily volume and record what the search misses. Keep exceptions narrow, owned and reviewable. No results means no matching collected evidence—not proof that the behavior did not occur.
ATT&CK context
T1059 — Command and Scripting Interpreter. Assign mappings to supported behavior in the case record; do not use an ATT&CK label as a severity score.
Escalation, containment and case notes
Escalate when the unexplained behavior is corroborated by unauthorized access, suspicious follow-on execution, persistence or affected sensitive assets. Preserve relevant evidence and identify the asset owner before changing the system. If ongoing harm is supported, use the organization’s incident-response process for isolation or access restriction, considering service impact and evidence preservation. Do not automatically delete files, remove entries or terminate processes because this hunt matched.
Open the investigator’s completion checklist
- Record the hypothesis, time zone, query version, actual search interval and retention limits.
- Save raw event references and stable process/device identifiers; avoid joining on PID alone.
- Document both the strongest suspicious evidence and the best legitimate explanation.
- State affected scope, confidence, unresolved gaps, action owner and next review time.
Key takeaways
- Was the local execution expected? Answer that question with corroboration.
- This detects only listed interpreters with an immediate browser parent. Indirect chains and renamed executables are outside its coverage.
- Use the paired searches as investigation starting points, then tune against your own environment.
Continue the investigation
Review Threat Hunting Part 2: PowerShell Investigations with KQL and Splunk SPL for process-correlation foundations, or explore the HackInvasion knowledge base.
Primary references
Schema and technique references checked September 21, 2026. Product schemas and collection settings can change.
This sample preserves the article’s original text and publication date, restyled for Amit’s personal website. Older material may describe historical tools or techniques.
Read the original article on Blogger