APT37 cmd.exe substring expansion obfuscation via env variable a9390f0
Detects the use of Windows command shell variable substring expansion to obfuscate commands. Adversaries use this technique to build malicious command lines dynamically, making them less visible to standard keyword-based detection mechanisms by storing parts of strings in environment variables and reassembling them using substring notation (e.g., %var:~start,length%).
Sigma

