Microsoft Sentinelv1.0
Detecting Lumma Stealer Commands
Detecting Lumma Stealer commands focuses on identifying malicious PowerShell or mshta executions, particularly those tricking users into pasting Base64-encoded strings via the Windows "Run" dialogue box (often associated with fake CAPTCHA campaigns).
By ThreatBeaconX Research Team · Updated Aug 31, 2026 · 37 views
detecting-lumma-stealer-commands.kql
DeviceFileEvents| extend CommandWords = split(InitiatingProcessCommandLine, " ") // Split the command into words| extend Word1 = CommandWords[0], // First wordWord2 = CommandWords[1], // Second wordWord3 = CommandWords[2], // Third wordWord4 = CommandWords[3], // Fourth wordWord5 = CommandWords[4]| extend LongestWord = case(strlen(Word1) >= strlen(Word2) and strlen(Word1) >= strlen(Word3) and strlen(Word1) >= strlen(Word4) and strlen(Word1) >= strlen(Word5), Word1,strlen(Word2) >= strlen(Word1) and strlen(Word2) >= strlen(Word3) and strlen(Word2) >= strlen(Word4) and strlen(Word2) >= strlen(Word5), Word2,strlen(Word3) >= strlen(Word1) and strlen(Word3) >= strlen(Word2) and strlen(Word3) >= strlen(Word4) and strlen(Word3) >= strlen(Word5), Word3,strlen(Word4) >= strlen(Word1) and strlen(Word4) >= strlen(Word2) and strlen(Word4) >= strlen(Word3) and strlen(Word4) >= strlen(Word5), Word4,Word5 // Default case if Column5 is the longest)| extend tostring(LongestWord)| extend DecodedBytes = base64_decode_tostring(LongestWord)| extend DecodedString = tostring(DecodedBytes)| where DecodedString contains "mshta" or InitiatingProcessCommandLine contains "mshta"| distinct DeviceName,InitiatingProcessCommandLine,LongestWord,DecodedString