Suspicious Command Line Obfuscation
This rule detects suspicious command-line obfuscation techniques by monitoring process creation events (EventID 4688) for specific patterns in the command line. It looks for the use of environment variables like %TEMP% or %SystemRoot%, the `${env:` syntax, and nested `cmd /c "cmd /c"` calls. These patterns are often used by adversaries to hide the true nature of executed commands, evade detection, or bypass security controls. The rule triggers if three or more such events are observed from the same computer and account within a one-hour window.
Microsoft Sentinel (KQL)

