This detection identifies the presence of the KiwiCmd.exe utility from the Chinese Hacktool set, which adversaries often deploy to extract credentials and establish persistence within compromised Azure workloads. Proactively hunting for this file in Azure Sentinel is critical because its low-severity classification may cause it to be overlooked during routine monitoring, allowing threat actors to maintain a stealthy foothold before escalating their activities.
rule x64_KiwiCmd {
meta:
description = "Chinese Hacktool Set - file KiwiCmd.exe"
author = "Florian Roth"
reference = "http://tools.zjqhr.com/"
date = "2015-06-13"
hash = "569ca4ff1a5ea537aefac4a04a2c588c566c6d86"
strings:
$s1 = "Process Ok, Memory Ok, resuming process :)" fullword wide
$s2 = "Kiwi Cmd no-gpo" fullword wide
$s3 = "KiwiAndCMD" fullword wide
condition:
uint16(0) == 0x5a4d and filesize < 400KB and 2 of them
}
This YARA rule can be deployed in the following contexts:
This rule contains 3 string patterns in its detection logic.
Here are 4 specific false positive scenarios for the Chinese Hacktool Set - file KiwiCmd.exe detection rule in an enterprise environment:
Lateral Movement via Microsoft SCCM/ConfigMgr Deployment
KiwiCmd.exe executable is extracted and executed as part of the standard package execution flow by the SCCM client service (ccmexec).ccmexec.exe (Microsoft Configuration Manager) or CcmExec.exe, specifically when the file path contains \CCMCache\ or \SoftwareDistribution\.Scheduled Maintenance by Third-Party Asset Management Tools
KiwiCmd.exe to perform scheduled inventory scans, patch compliance checks, or remote command execution on endpoints. These tasks often run during off-hours via the Windows Task Scheduler, triggering the detection when the tool queries system configuration data.SolarWinds.Agent.exe, MEAgentService.exe) or filter based on the scheduled task name containing keywords like “Inventory,” “Patch,” or “AssetScan.”Remote Support Sessions via Kiwi Syslog/Command Tools