Network Connection Initiated via Finger.EXE
Description
Detects network connections via finger.exe, which can be abused by threat actors to retrieve remote commands for execution on Windows devices. In one ClickFix malware campaign, adversaries leveraged the finger protocol to fetch commands from a remote server. Since the finger utility is not commonly used in modern Windows environments, its presence already raises suspicion. Investigating such network connections can also help identify potential malicious infrastructure used by threat actors
Query · sigma
selection: Initiated: 'true' Image|endswith: \finger.exe condition: selection
Known false positives
- Unlikely