<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Falcon - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/falcon/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 29 Sep 2026 10:11:44 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/falcon/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Abuse of CrowdStrike Real Time Response for Remote Command Execution</title><link>https://feed.craftedsignal.io/briefs/2026-09-crowdstrike-rtr-abuse/</link><pubDate>Tue, 29 Sep 2026 10:11:44 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-crowdstrike-rtr-abuse/</guid><description>Attackers with unauthorized access to a CrowdStrike management console can leverage the 'runscript' functionality to execute arbitrary PowerShell commands on remote Windows hosts.</description><content:encoded><![CDATA[<p>This threat involves the abuse of the CrowdStrike Falcon Real Time Response (RTR) feature by adversaries who have compromised a legitimate CrowdStrike management console. By utilizing the 'runscript' capability, actors can push and execute arbitrary PowerShell scripts on remote, managed Windows endpoints. This technique effectively weaponizes a trusted security tool to perform post-compromise activities, such as reconnaissance, lateral movement, or malware deployment, while masquerading as legitimate administrative maintenance. Defenders should be aware that this activity originates from 'dllhost.exe' with specific command-line parameters associated with the RTR service, making it a critical visibility gap for organizations relying on EDR telemetry without specific monitoring for management-console-initiated execution.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker gains unauthorized credentials or session access to a target organization's CrowdStrike Falcon management console.</li>
<li>Attacker initiates an RTR session to a chosen managed Windows endpoint.</li>
<li>Attacker uploads or selects a malicious PowerShell script for execution via the 'runscript' command.</li>
<li>The CrowdStrike agent triggers the execution, resulting in 'dllhost.exe' spawning 'powershell.exe'.</li>
<li>The spawned process executes with specific command-line arguments, including '-EncodedCommand' and '-Version 5.1'.</li>
<li>Malicious code executes in the context of the CrowdStrike agent or the designated service account.</li>
<li>Attacker achieves objectives such as data exfiltration, payload deployment, or further privilege escalation.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful abuse of the RTR feature allows an attacker to operate with the same privileges as the security agent, potentially leading to full host compromise, sensitive data exfiltration, or the disabling of other security controls. This technique is particularly dangerous as it originates from trusted security infrastructure, potentially bypassing standard EDR behavioral blocking.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize monitoring for the execution patterns of the CrowdStrike RTR agent to detect unauthorized script execution.</p>
<ul>
<li>Deploy the provided Sigma rule to detect PowerShell execution originating from the RTR-specific parent process ('dllhost.exe').</li>
<li>Audit and restrict administrative access to the CrowdStrike management console, enforcing multi-factor authentication for all sessions.</li>
<li>Review and baseline legitimate administrative RTR scripts; filter alerts to exclude known-good maintenance activity initiated by authorized security personnel.</li>
</ul>
]]></content:encoded><category domain="severity">medium</category><category domain="type">advisory</category><category>living-off-the-land</category><category>powershell</category><category>edr-abuse</category></item></channel></rss>