{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/edr-abuse/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Falcon"],"_cs_severities":["medium"],"_cs_tags":["living-off-the-land","powershell","edr-abuse"],"_cs_type":"advisory","_cs_vendors":["CrowdStrike"],"content_html":"\u003cp\u003eThis threat involves the abuse of the CrowdStrike Falcon Real Time Response (RTR) feature by adversaries who have compromised a legitimate CrowdStrike management console. By utilizing the 'runscript' capability, actors can push and execute arbitrary PowerShell scripts on remote, managed Windows endpoints. This technique effectively weaponizes a trusted security tool to perform post-compromise activities, such as reconnaissance, lateral movement, or malware deployment, while masquerading as legitimate administrative maintenance. Defenders should be aware that this activity originates from 'dllhost.exe' with specific command-line parameters associated with the RTR service, making it a critical visibility gap for organizations relying on EDR telemetry without specific monitoring for management-console-initiated execution.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker gains unauthorized credentials or session access to a target organization's CrowdStrike Falcon management console.\u003c/li\u003e\n\u003cli\u003eAttacker initiates an RTR session to a chosen managed Windows endpoint.\u003c/li\u003e\n\u003cli\u003eAttacker uploads or selects a malicious PowerShell script for execution via the 'runscript' command.\u003c/li\u003e\n\u003cli\u003eThe CrowdStrike agent triggers the execution, resulting in 'dllhost.exe' spawning 'powershell.exe'.\u003c/li\u003e\n\u003cli\u003eThe spawned process executes with specific command-line arguments, including '-EncodedCommand' and '-Version 5.1'.\u003c/li\u003e\n\u003cli\u003eMalicious code executes in the context of the CrowdStrike agent or the designated service account.\u003c/li\u003e\n\u003cli\u003eAttacker achieves objectives such as data exfiltration, payload deployment, or further privilege escalation.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful abuse of the RTR feature allows an attacker to operate with the same privileges as the security agent, potentially leading to full host compromise, sensitive data exfiltration, or the disabling of other security controls. This technique is particularly dangerous as it originates from trusted security infrastructure, potentially bypassing standard EDR behavioral blocking.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize monitoring for the execution patterns of the CrowdStrike RTR agent to detect unauthorized script execution.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eDeploy the provided Sigma rule to detect PowerShell execution originating from the RTR-specific parent process ('dllhost.exe').\u003c/li\u003e\n\u003cli\u003eAudit and restrict administrative access to the CrowdStrike management console, enforcing multi-factor authentication for all sessions.\u003c/li\u003e\n\u003cli\u003eReview and baseline legitimate administrative RTR scripts; filter alerts to exclude known-good maintenance activity initiated by authorized security personnel.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-29T10:11:44Z","date_published":"2026-09-29T10:11:44Z","id":"https://feed.craftedsignal.io/briefs/2026-09-crowdstrike-rtr-abuse/","summary":"Attackers with unauthorized access to a CrowdStrike management console can leverage the 'runscript' functionality to execute arbitrary PowerShell commands on remote Windows hosts.","title":"Abuse of CrowdStrike Real Time Response for Remote Command Execution","url":"https://feed.craftedsignal.io/briefs/2026-09-crowdstrike-rtr-abuse/"}],"language":"en","title":"CraftedSignal Threat Feed - Edr-Abuse","version":"https://jsonfeed.org/version/1.1"}