2026 Critical Enterprise Intrusion Chain Detection: Windows Terminal Abused to Spawn Infostealer Delivery Commands
Detects instances where the Windows Terminal application (or related processes like OpenConsole) spawns suspicious command-line utilities such as PowerShell, CMD, curl, or certutil with indicators of potential download activity or command-line obfuscation. This pattern is often indicative of interactive adversary activity attempting to stage tools or execute payloads.
Cortex XDR

