Files
orca/docs/reference/windows-edr-posture.md
T
bfc6a262a7 fix(windows): read command lines from the kernel, not each process's PEB (#17886)
* fix(windows): read command lines from the kernel, not each process's PEB

MDE incident D scored Orca for suspicious memory activity: the vendored
`@vscode/windows-process-tree` recovered every process's command line by
opening it with `PROCESS_QUERY_INFORMATION | PROCESS_VM_READ` and chaining
three `ReadProcessMemory` calls through the PEB and
`RTL_USER_PROCESS_PARAMETERS`. On a 750ms/2s cadence over the whole table that
is the credential-dumping primitive, whatever the intent.

Windows 8.1 added `NtQueryInformationProcess`'s `ProcessCommandLineInformation`
class (60), which returns the same string as a kernel-built `UNICODE_STRING`
under `PROCESS_QUERY_LIMITED_INFORMATION` alone. Electron's floor is Windows
10, so every supported OS has it. The PEB reader stays behind a process-wide
latch that only `STATUS_INVALID_INFO_CLASS`/`NOT_SUPPORTED`/`NOT_IMPLEMENTED`
can set; a pid that merely denied a handle does not re-arm it, because
`PROCESS_QUERY_INFORMATION` implicitly grants the limited right and so cannot
be obtained where the weaker open already failed.

The same hunk drops `PROCESS_VM_READ` from `GetProcessMemoryUsage` and
`GetCpuUsage`, which acquired it and never read an address space.

Measured on Windows 11 (514 processes), counted in-process by swapping the
addon's import table entries for counting stubs, per CommandLine scan:
`ReadProcessMemory` 1128 -> 0, desired access 0x0410 -> 0x1000, p50 12.7ms ->
9.3ms. Command lines were byte-identical on every process both readers
recovered (376/376, 379/379 across runs), including a 24,068-character argv
with quotes, non-ASCII and trailing whitespace, and a WOW64 target. Three
processes that refused the old rights granted the new one; none went the other
way.

* chore(deps): refresh the windows-process-tree patch hash in the lockfile

* fix(windows): drop the PEB fallback and detect the unpatched prebuilt

Review of #17886 found three ways the reader could still perform, or silently
resume, the primitive it exists to remove.

The class-missing latch was a permanent, process-wide, one-way downgrade back
to the PEB read, and any single target returning STATUS_INVALID_INFO_CLASS /
NOT_SUPPORTED / NOT_IMPLEMENTED could trip it. On an EDR-hooked ntdll -- the
entire premise of this change -- a hook that does not recognise class 60 would
have restored PROCESS_VM_READ plus three ReadProcessMemory per pid per scan for
the life of the process, unobservably, on precisely the machines this was
written for. The fallback is deleted rather than guarded: GetProcessCommandLine
now returns false and leaves the command line empty, which callers already
handle, so the addon imports no ReadProcessMemory at all.

That absence is what makes the property checkable on the artifact. The
published 0.8.0 tarball ships a loadable prebuilt built from unpatched source;
it is node-addon-api, so a bare require() accepts it, allowBuilds is false and
CI installs with --ignore-scripts, and a rebuild that soft-exits on a Windows
file lock leaves it in place. Source-text guards could never see it.
windowsProcessTreeAddonReadsProcessMemory() checks the compiled binary instead,
and is wired into the install check, the rebuild, and the relay build.

The repair itself never worked: `git apply` run inside a work tree prefixes
patch paths with the cwd-relative prefix, skips what does not match, and exits
0, so the branch always fell through to its own post-check throw. The package
dir is always under the project root, while the fixture that covered it was in
%TEMP%, outside any repo. Blinding git with GIT_DIR fixes it, and the test now
runs inside a real work tree.

Also from review: bounds-check the returned UNICODE_STRING against the
allocation (not the size the second query clobbers) and cap the probe so a
bogus length cannot bad_alloc a whole scan; test NT_SUCCESS explicitly; value-
initialize ProcessInfo, which left `memory` as stack garbage -- measured, 82
processes reported the same bogus working set; and correct a comment in
windows-process-table.ts that still described the command line as a PEB read.

Re-measured on Windows 11 (543 processes): ReadProcessMemory 1128 -> 0, with
the symbol absent from the import table so the IAT hook finds no slot to
count; desired access 0x0410 -> 0x1000 on all 543 opens; p50 13.5 -> 12.3ms;
405/405 command lines byte-identical including a 24,087-character quoted
non-ASCII argv and a WOW64 target; 3 processes recovered only by the new path,
0 only by the old.

* chore(deps): refresh the windows-process-tree patch hash in the lockfile

* test(scripts): stage a script's local imports into the native-runtime fixture

ensure-native-runtime.mjs gained an import of windows-process-tree-gyp-rebuild.mjs,
but the fixture copied only the script itself, so every case in the suite died
with ERR_MODULE_NOT_FOUND before reaching its own assertions. copyScriptWithLocalModules
already walks a script's co-located imports for exactly this reason -- its own doc
comment names this failure -- so use it rather than listing files by hand.

The two Windows cases still fail here, on a missing node-pty ConPTY runtime that
also fails on main; this only stops a resolution error from standing in front of
whatever they were meant to catch.

* fix(windows): route a locked stale addon to the Windows file-lock message

`pnpm install` with Orca running aborted with a raw EPERM stack. The stale-binary
guard -- which deletes an addon that still imports ReadProcessMemory so a skipped
rebuild cannot use it -- ran outside the try whose catch classifies Windows file
locks, and whose message is literally "Close running Orca/Electron/dev processes
for this worktree": exactly this situation.

Measured rather than assumed: rmSync against a loaded (memory-mapped) addon throws
EPERM, and `force: true` does not help, since it only swallows ENOENT. Cold copies
of the same file delete fine. So the delete threw a page before the handler that
knows what it means.

Moving the guard inside the try is the whole fix; the classifier already matches
the EPERM text. The new case runs the real script against a temp project whose
stale addon is held open by a live child process, and fails against the old
placement with the raw `syscall: 'rm'` stack the report described.

* feat(windows): warn once when command-line recovery is refused host-wide

Removing the PEB fallback removed a total-defeat vector, but it left a cliff: if
NtQueryInformationProcess(ProcessCommandLineInformation) is refused -- a hooked
ntdll that does not know class 60 -- every command line comes back empty and
agent identity matching silently degrades to image names. The addon still loads
and still enumerates, so every health check the app has stays green. A cliff
nobody can see is the failure mode this area keeps producing.

The querying process is the unambiguous probe. A process can always open itself
with PROCESS_QUERY_LIMITED_INFORMATION, so its own command line coming back empty
means the query is refused for every process -- not that some target denied a
handle, which is normal for roughly a quarter of the table. Keying on our own row
rather than a fraction means no threshold to tune and no false positive on a
hardened box where most processes deny.

One warning per session, gated on the CommandLine flag actually being requested so
a future identity-only reader cannot trip it. The suite's own SELF fixture gains a
command line for the same reason: a self row without one is the alarm, not a
detail.

* fix(windows): check the relay's staged addon at load, and answer tri-state

Two gaps in the ReadProcessMemory check, both about what it does not see.

It only ever looked at node_modules/@vscode/windows-process-tree. A relay host
has no node_modules of ours: it loads ./windows-process-tree.node staged beside
the bundle. The relay build asserts the symbol on the artifact it produces, but a
bundle and the addon beside it redeploy independently, so a host that has not
taken a new bundle keeps whatever binary is already there -- and the published
prebuilt is node-addon-api, so it binds cleanly and then walks every process's
address space. loadWindowsProcessTree now checks that file too and refuses it,
falling back to the CIM scan: slower, but not the thing an EDR quarantines a host
for. The predicate is duplicated rather than imported, because the config-script
copy is install-time tooling that drags in node-gyp and child_process, and this
module is bundled into the app and the relay.

And it returned false for a binary that is not there. All three callers happened
to be safe, but the name read as a safety predicate, so a future caller would take
a missing binary as verified. inspectWindowsProcessTreeAddon() now answers
clean/unpatched/missing over an explicit binary path -- which is also what lets
the relay's staged addon be checked at all -- and each caller states which state
it acts on.

Both are covered by cases that fail against the old code: without the load-time
check the unpatched staged addon is bound and the CIM fallback never runs, and
with 'missing' folded back into 'clean' the absence case fails outright.

* test(windows): load the addon in beforeAll, not at collection time

loadAddon() ran while the file was being collected, so on a Windows checkout with
no built addon the require threw before any case existed and took the seven
patch-text cases down with it -- cases that read only the patch file and need no
binary at all. Verified both ways against a deliberately unresolvable addon path:
at collection time vitest reports "no tests" for the file; from beforeAll the
seven text cases pass and only the three addon cases go.

* fix(deps): normalize the windows-process-tree patch to LF and let pnpm own its hash

`pnpm install --frozen-lockfile` failed on this branch on every platform with
ERR_PNPM_LOCKFILE_CONFIG_MISMATCH, which breaks CI and the release build.

Two coupled defects. The patch file was committed with CRLF -- 174 CR bytes,
against zero on main -- and `.gitattributes` pins `/config/patches/*.patch -text`
precisely so checkout cannot convert it, so those bytes reached every runner. And
pnpm hashes a patch **LF-normalized**, so the raw sha256 of a CRLF file is a value
pnpm never computes:

  raw sha256      322965470c05f63d8527f7d8e892ee26ee444136b66b57fd64c362a9f2ff05d1
  LF-normalized   f8ea245391c94da5770045aeea01fa6de466c2199c6ef46b5b769b398aa9823e

The lockfile carried the raw one, at all three sites. It is the only one of the
seven patches where the two digests differ, which is why the other six passed.

Normalized the patch to LF and took pnpm's own value from
`pnpm install --no-frozen-lockfile`; nothing here is hand-computed. With the file
LF-only the two interpretations coincide, so the lockfile, the contract test's
no-CR assertion and its hash assertion all agree at one number -- and
`config/scripts/windows-process-tree-patch-contract.test.mjs`, which was red on
this branch for the same reason, is green again. The lockfile diff is exactly the
three hash lines.

The regression check is the installer, not a digest. Two separate reviews
"verified" the shipped hash by recomputing sha256(patchBytes) and matching the
lockfile; both were wrong, because both repeated the same wrong assumption about
which bytes pnpm hashes. A check that reproduces the original mistake is not
independent. So the new case runs `pnpm install --frozen-lockfile --lockfile-only
--ignore-scripts` against a copy of the manifest, lockfile and patches, and
asserts exit 0 -- verified by deletion: restoring the shipped hash fails it with
the exact ERR_PNPM_LOCKFILE_CONFIG_MISMATCH from the branch's package (windows)
job.

Also corrected the `.gitattributes` comment claiming pnpm hashes patches
byte-for-byte. The `-text` setting is right -- `git apply` needs the exact bytes --
but that sentence is the claim that produced the wrong hash twice.

* ci(windows): run the process-tree patch suites in CI

Both suites only self-skip off Windows, so the binary-level check that the
addon carries no ReadProcessMemory passed vacuously in every lane.

* fix(windows): force core.autocrlf=input for the patch repair

My LF normalization of the windows-process-tree patch broke the `git apply`
repair path introduced in this PR. The two are coupled and I checked only one.

Those 174 CR bytes were not editor noise. They sat on exactly the pre-image
lines and nowhere else -- 107/107 in src/process.cc, 67/67 in
src/process_commandline.cc, 0 on every added or context line -- because
@vscode/windows-process-tree@0.8.0 ships those two sources as CRLF. Normalizing
the patch made its pre-image stop matching the file it is applied against.

Measured, reconstructing the true CRLF pre-image from the pre-normalization
blob and applying the current LF patch:

  core.autocrlf   plain   -c core.autocrlf=input
  true            exit 0  exit 0
  input           exit 0  exit 0
  false           exit 1  exit 0

`false` is Git's own built-in default and what "checkout as-is" selects in the
Git for Windows installer -- on this box the `true` that hides it comes from the
installer's system gitconfig, not from anything in the repo. There the repair
throws, ensureWindowsProcessTreeCommandLinePatch reports "still reads the PEB,
and repairing it ... failed", isWindowsNativeLockError does not match that text,
and `pnpm install` dies with no path forward.

Forcing the mode rather than `--ignore-whitespace`: both fix every cell and both
leave the applied file fully LF, but `input` relaxes line endings only, so a hunk
whose real content drifted is still rejected. The repair rewrites a
security-relevant source file; it should stay strict about everything except the
thing that is legitimately ambiguous.

Not reverting the patch to CRLF: windows-process-tree-patch-contract.test.mjs
(pre-existing on main) forbids CR bytes in it, and pnpm computes the same hash
either way. LF plus the forced mode is the end state.

The suite could not have caught this. The fixture built its pre-image from the
patch itself and joined with '\n', so fixture and patch agreed by construction on
any encoding -- once again a test that passes without its fix. It now emits the
CRLF the real package ships, and the case runs under both autocrlf modes pinned
through a temp HOME gitconfig, because the repair blinds git to the repo and so
reads global config. Verified by deletion in both directions: with the flag
removed the autocrlf=false case fails with the exact "still reads the PEB" dead
end while autocrlf=true still passes, and with the fixture back on LF all eight
cases pass with no fix present at all.

Also corrected the .gitattributes comment I added last commit. It said `git
apply` needs the bytes the patch was written against, which is now false -- the
pinned bytes are LF and the bytes it was written against are CRLF. That is the
same class of confident-and-wrong claim that produced the bad hash twice.

* fix(windows): assert the rebuilt addon, and install the patch for real in tests

Three follow-ups from review.

**The packaged binary had no check.** The relay build asserts its own artifact
and ensure-native-runtime asserts what it loads, but nothing looked at the addon
copied into the packaged app -- so a rebuild that silently produced the upstream
reader shipped. `rebuild-native-deps.mjs` now asserts `clean` on it after
`rebuild()`. This is also the caller D4's tri-state was missing: every existing
site branches on `=== 'unpatched'`, so `missing` still behaved exactly like
`clean` everywhere, which was the thing making it a state rather than a boolean.
Here both non-clean states fail, and they fail differently: after a rebuild that
reported success, an absent binary is a broken build, not an absence to shrug at.

The fake `rebuild()` had to start producing a binary for that to mean anything,
so it now emits stand-in bytes and takes `addon: 'clean' | 'unpatched' | 'none'`.
Verified by deletion: with the assertion removed both new cases pass.

**The frozen-install case could not see a patch at all.** `--lockfile-only`
resolves and never applies one, so its coverage stops at hash consistency. Added
a case that installs `@vscode/windows-process-tree@0.8.0` for real with the patch
and asserts the materialized `src/process_commandline.cc` carries the marker and
no longer carries `ReadProcessMemory` -- about 1.5s for the pair.

Correcting the brief on that one: it does **not** catch the `git apply` breakage
from the previous commit. Measured -- with `-c core.autocrlf=input` removed it
passes cleanly, because `pnpm install` uses pnpm's own patch applier and never
runs our repair script. What it does catch is a patch pnpm can no longer apply:
corrupting one pre-image line fails both cases. The repair path stays covered by
the CRLF fixture in rebuild-native-deps-node-pty.test.mjs.

Worth recording, since it decides whether the LF normalization was safe at all:
pnpm applies the LF patch to the CRLF tarball sources without complaint, and
materializes them as LF with the marker present and `ReadProcessMemory` absent.
The primary install path was never affected -- only the `git apply` fallback was.

**Dead timeout.** The frozen-install case passed `timeoutMs: 300_000` to the
spawn while vitest capped the case itself at 30s, so on a cold runner vitest
would have killed it first. Both cases now declare the budget they use.

* test(windows): route the frozen-install check through the pnpm invocation owner

The new patched-dependencies check hand-rolled a PATH walk naming 'pnpm.cmd',
which the windows batch shim spawn boundary ratchet rejects: pnpm-cli-invocation
already owns that decision for every other script, and its allowlist only
shrinks.

Reuse resolvePnpmCliInvocation for the command and prefixArgs, and the shared
resolveCliCommand for the presence check, so no shim name is spelled here. Its
`shell` flag is dropped because runProcessSync refuses it and already drives a
shim through the interpreter itself.

---------

Co-authored-by: Orca Worker <orca-worker@localhost>
Co-authored-by: Neil <4138956+nwparker@users.noreply.github.com>
2026-09-05 21:12:47 -07:00

29 KiB

Windows EDR signal surface

Orca's Windows process tree is shaped like the thing behavioural EDR is built to find. An enterprise Windows 11 / Intune tenant opened six Microsoft Defender for Endpoint incidents against Orca 1.4.192 in eight days. All six fired as active incidents and stayed open; three closed only because a human classified them by hand in the portal. Defender never downgraded or closed one on its own.

None were signature hits. Every one was behavioural process-tree scoring, and two escalated to multi-stage incidents carrying ATT&CK tactic mappings (Execution, Collection).

The framing this document keeps throughout, because both halves matter:

Defender is not malfunctioning. It is describing the code accurately. Orca really does copy its own signed image under a different name, really did read every process's memory on a timer, really does run base64-encoded PowerShell with the execution policy bypassed, and really does take screenshots and synthesise input from a runtime-compiled assembly. Each of those is a deliberate engineering choice with issue history behind it. The problem is not that the capabilities are illegitimate — it is that their behavioural signature overlaps with attack techniques, and an EDR scoring behaviour cannot see the difference.

Do not read this as a bug report against Defender, and do not read it as a claim that Orca is malware. It is a map of which of our behaviours are legible to an EDR as attack-technique-shaped, why each one exists, and what engineers and administrators can do about it.

What the tenant actually saw

Four independent evidence clusters, from six incidents:

Cluster Incidents Evidence
Update A, B, C orca-windows-setup.exe → old-uninstaller.exe, Uninstall Orca.exe (electron-builder generates these; they are in no repo file)
Spawn all six Orca.exe → orca-terminal-daemon.exe → powershell.exe / pwsh.exe / cmd.exe / reg.exe → claude.exe, gh.exe, codex.cmd
Process table D "suspicious memory activity" — OpenProcess plus a PEB read against every process on a repeating cadence
Computer use E, F runtime.ps1, computer-sidecar.js, many operation.json, a burst of ~10 short-lived powershell.exe

Incident E is the one to look at hardest: 5 alerts, 37 evidence items, ATT&CK Execution + Collection, and a description reading "Screenshots were taken unexpectedly on this device… Screen capture code was found in a script launched by powershell.exe." Incident F added "suspicious MSIL code", from the Add-Type -TypeDefinition that recompiles inline C# P/Invoke on every operation.

In the update cluster the uninstaller is genuinely NotSigned, while Orca.exe and orca-terminal-daemon.exe report Valid CN=SignPath Foundation.

The behaviours, and why each one exists

The daemon runs from a copy of our own image

src/main/daemon/daemon-host-relocation.ts copies the Electron runtime into %LOCALAPPDATA%\Orca\daemon-host\<version>\ and forks the terminal daemon from there.

It exists because the NSIS installer deletes the old install directory and force- kills every process imaged under it. Without relocation, an auto-update kills the terminal daemon and every live terminal with it. The copy is a run-as-node Orca.exe rather than node.exe so there is no console flash and asar still resolves; config/nsis/orca-installer-hooks.nsh reaps it on a real uninstall (guarded by ${isUpdated} so an update's uninstallOldVersion never fires it).

At the time of these incidents the copy was also renamed to orca-terminal-daemon.exe, the image name every incident here reports, and DAEMON_HOST_EXE_NAME's comment stated the reason without varnish: "so the NSIS updater's taskkill /IM Orca.exe can't match it." The rename has since been removed; the copy now keeps the app exe's own file name, because the updater's kill sweep is path-scoped on every host that has PowerShell and the rename only ever bought the no-PowerShell fallback. See windows-daemon-host-relocation.md.

How an EDR reads it: MITRE T1036, masquerading — and, for what remains, T1036.005. A signed executable copied out of the install directory into %LOCALAPPDATA% under a different name, which then spawns shells, matches the textbook description closely enough that no behavioural engine can be expected to score it low. Dropping the rename removes that literal indicator but not the underlying shape: execution from a non-standard user-writable location is scored on its own. Note also that the strongest form of the T1036 signal was never present here — the shipped binary's OriginalFilename is empty, so there was no embedded name for the old disk name to contradict.

Every process gets a handle, on a timer

src/main/windows/windows-process-table.ts takes a Toolhelp32 snapshot under one flag set, CommandLine | CreationTime, shared by every caller. pid, ppid and name come out of the snapshot itself and open nothing. CommandLine is what opens a handle: the addon calls GetProcessCommandLine per process, which opens PROCESS_QUERY_LIMITED_INFORMATION — the same right Task Manager takes — and asks the kernel for the string. Upstream it opened PROCESS_QUERY_INFORMATION | PROCESS_VM_READ and walked the PEB with three ReadProcessMemory calls (src/process_commandline.cc:32,41-47 in the vendored @vscode/windows-process-tree 0.8.0 source that config/patches/ patches).

Memory is retired as of this change, and that is a real reduction: it made GetProcessMemoryUsage open a second PROCESS_QUERY_INFORMATION | PROCESS_VM_READ handle per process for a GetProcessMemoryInfo call whose result no caller read (src/process.cc:47-63). Dropping it halves the handles opened per snapshot. On its own it removed no memory read — both handles carried PROCESS_VM_READ at the time — so it composes with the patch below rather than substituting for it.

It exists because seven independent readers used to fork powershell.exe for a Get-CimInstance Win32_Process scan. That cost, measured: a PowerShell Transcription policy recorded ~289 GB across 1.4 million files because a scan ran every ~2 seconds (#15209); a Group Policy or AV block turned a query into "unavailable", which callers read as "no evidence", which is how a PTY tree survived its own teardown (#9045, #10475); and the scan cost ~700 ms per pane, so panes multiplied it (#15036). The native snapshot answers the same question in 15.9 ms against 706 ms for CIM — p50, measured on Windows 11 at 1050 processes. See windows-process-enumeration.md.

Asking for fewer fields is cheaper, and the module now asks for the smallest set that still answers every caller. There is no per-flag-set cache split: one TTL-cached snapshot serves everyone, deliberately, because a split would restore the per-pane fan-out the cache exists to remove — a 32-wide teardown has to collapse into one scan. So the cheap identity-only read is not something any caller can select; every read pays for CommandLine. An earlier revision of this file described a two-cache design with 6.3 ms / 12.3 ms p50 figures at 492 processes. That design is not in the tree and those numbers describe no code path here; the figures that do apply are the module's own, in windows-process-enumeration.md.

How an EDR read it: a cross-process handle plus a remote memory read against every process on the box, repeating on a cadence, is the read half of the telemetry that credential dumping and process injection produce. MDE surfaced it as "suspicious memory activity".

The memory read is gone. A fourth hunk in config/patches/@vscode__windows-process-tree@0.8.0.patch has GetProcessCommandLine call NtQueryInformationProcess with ProcessCommandLineInformation (class 60, Windows 8.1+; Electron's floor is Windows 10), which returns a UNICODE_STRING the kernel builds and needs only PROCESS_QUERY_LIMITED_INFORMATION. Measured on ~540 processes, per detailed scan: ReadProcessMemory 1128 → 0, desired access 0x0410 → 0x1000, with byte-identical command lines on every process both readers recovered. There is no PEB fallback to reinstate it — a hooked ntdll answering STATUS_INVALID_INFO_CLASS for one target would have flipped a process-wide, one-way switch back to PROCESS_VM_READ on exactly the machines this exists for.

Because the property is the absence of an import, it is checkable on the artifact rather than the source: inspectWindowsProcessTreeAddon() answers clean / unpatched / missing, and the rebuild, ensure-native-runtime.mjs, the relay build and loadWindowsProcessTree() all key on it. That check is load- bearing because the published tarball ships a loadable prebuilt built from unpatched source, so "it required cleanly" is not evidence.

What to declare to administrators is now one PROCESS_QUERY_LIMITED_INFORMATION handle per process on a detailed snapshot and no remote memory access at all. What this does not narrow is which processes are asked — a detailed scan still queries every pid, including lsass.exe. Restricting the command-line pass to Orca's own subtree needs job-object membership as its source of truth (a ppid-derived allowlist would miss the detached, reparented descendants of #9045 and #10475), and remains unclaimed work.

Encoded, policy-bypassing PowerShell

Three sites are named in the incident analysis:

  • src/relay/windows-port-scan.ts ran -NoProfile -NonInteractive -ExecutionPolicy Bypass -EncodedCommand over a Get-NetTCPConnection -State Listen script to find dev-server ports. Enumerating listening ports is MITRE T1049, network service discovery, and doing it through an encoded policy-bypassed shell is the aggravating factor rather than the finding itself. The ordinary scan now starts no PowerShell at all — netstat.exe -ano, with the owning process name projected off the shared native table — and that payload survives only as the last-resort fallback, as -Command with no policy override.
  • src/main/daemon/shell-ready.ts uses -EncodedCommand for the OSC 133 bootstrap.
  • src/main/agent-hooks/windows-powershell-hook-launcher.ts wraps managed hooks.

No site spells the pair any more. src/main/ssh/ssh-remote-powershell.ts, src/shared/setup-agent-sequencing.ts, src/shared/windows-cmd-runner-delayed-launch.ts and src/shared/windows-interactive-login-spawn.ts each dropped -ExecutionPolicy Bypass as a measured no-op: the policy gates script files, never -EncodedCommand. Where the bypass was load-bearing it moved in-payload as a process-scope Set-ExecutionPolicy (setup-agent-sequencing.ts), which is the pattern to copy rather than restoring the switch — the switch loses to a GPO scope anyway, so it never covered the locked-down case.

What remains is -EncodedCommand without the bypass: the PTY bootstraps (src/main/daemon/shell-ready.ts, src/main/providers/local-pty-shell-ready.ts, src/main/providers/windows-shell-args.ts), the hook wrappers (src/main/agent-hooks/windows-powershell-hook-launcher.ts and its callers src/main/agent-hooks/runtime-home-hook-command.ts, src/main/agent-hooks/installer-utils.ts, and src/main/claude/hook-settings.ts — that last one only as a fallback since #18875, see below), src/main/runtime/windows-default-route-interfaces.ts, src/main/runtime/orchestration/setup-completion-signal.ts, src/shared/hermes-startup-query.ts, and the four ex-bypass sites above. src/main/runtime/windows-mobile-firewall.ts encodes a script and launches it elevated through Start-Process -Verb RunAs, which is a stronger shape than any of those; only that hop is encoded, because -ArgumentList re-splits an unquoted parameter string on whitespace.

One site still spells -ExecutionPolicy Bypass with no encoding, the weaker signal: src/main/cli/wsl-cli-scripts.ts (-File, and it is a real script file, so the switch is not a no-op there). src/main/system-fonts.ts dropped it for plain -Command; src/shared/secure-path-windows-acl.ts no longer runs PowerShell at all, having moved to icacls.exe; and computer use now asks for -ExecutionPolicy RemoteSigned in src/main/computer/windows-powershell-execution-policy.ts, falling back to Bypass only after a policy-blocked start.

Regenerate with rg -- '-EncodedCommand|-ExecutionPolicy' src/ rather than trusting the lists above, and note that a raw grep under-reports: the hook sites reach -EncodedCommand through wrapWindowsPowerShellEncodedCommand and never spell the flag themselves.

Encoding is not gratuitous: it shields paths and switches from cmd.exe and MSYS rewriting (#6078, #14815), which is a real class of corruption. But -EncodedCommand is a first-class Defender alert title ("Suspicious PowerShell command line"), and base64 raises the score rather than lowering it, because it denies the analyser the payload it would otherwise clear.

The hook launcher is prior art worth knowing about. #16003 measured, on a reporting Kaspersky host, that -WindowStyle Hidden paired with -EncodedCommand was denied at CreateProcess with exit 126 regardless of payload — exit 0 was denied too. The fix was to stop spelling the flags: WINDOWS_POWERSHELL_HOOK_SWITCHES is now just -NoProfile, and separately, in #16576, the execution policy bypass moved in-payload as a process-scope Set-ExecutionPolicy — a real command-line signal reduction, though #16003's measured denial keyed on -WindowStyle Hidden + -EncodedCommand, not on the bypass. It is also honest that the underlying behaviour did not change.

Copy the pattern, but copy its caveat too. windows-powershell-hook-launcher.ts records that dropping -WindowStyle Hidden was a real tradeoff whose suppression "was never measured" and "remains unverified on a real box". Reducing spelled flags is the right instinct; treat any specific claim about what a removed flag was doing as unproven until someone measures it.

cmd.exe /c carrying caret-escaped free text

buildWindowsCmdShimCommandLine in src/shared/child-process/windows-command-line.ts builds /d /v:off /s /c "…" for the .cmd and .bat targets Windows can only start through cmd.exe (codex.cmd being the one that matters). Because cmd expands %VAR% even inside a quoted token, each % is broken with "^%".

The escaping is not decorative. Measured on Windows 11 against a real .cmd shim, ["a b", 'c"d', "e%F%g", "h&i", "j^k"] came back as ["a b", 'c"d', "e^%F^%g", "h"] — the & truncated the argument and ran the remainder as a command.

How an EDR reads it: caret escaping is the canonical obfuscation marker in cmd.exe command lines, and the free text being escaped here is an agent prompt, so the line is long, high-entropy, and attacker-shaped. It is the exact input an obfuscated-command-line detector is tuned on.

The spawn tree itself

Orca.exe → the relocated daemon host (orca-terminal-daemon.exe in the builds these incidents cover, Orca.exe since) → a shell → an agent CLI is what a terminal multiplexer for coding agents is. reg.exe appears from src/main/win32-utils.ts, src/main/agent-hooks/managed-hook-owner-identity.ts and src/relay/pty-shell-utils.ts (reading the OpenSSH DefaultShell).

Nothing here is avoidable in principle. What is controllable is depth and breadth: every interpreter hop between Orca and the thing the user asked for adds a scored edge, which is why the shipped doctrine of #15520 and #15595 is to shorten the interpreter chain rather than to hide a window.

#18875 is a worked example of that doctrine. The Claude Code lifecycle hook was registered as powershell.exe -NoProfile -EncodedCommand <...> whose entire decoded payload was a Test-Path and a call to ~/.orca/agent-hooks/claude-hook.cmd. It now registers the script path itself (<path> || echo {}), so bash -> powershell -> cmd -> curl became bash -> cmd -> curl and one powershell.exe -EncodedCommand per hook event — a first-class Defender alert title — leaves the tree. The reporting box fired ~6 900 of them in five days, 70% from Claude sessions that were not running under Orca at all and whose hook exits at its first ORCA_PANE_KEY guard.

What is measured is latency and the hop count, nothing else: median 471 ms -> 213 ms per event idle, and 656 ms -> 296 ms (p95 696 ms -> 337 ms) under 10-way concurrency, invoked as Claude Code invokes it. No EDR verdict on either tree was measured, so claim the removed -EncodedCommand spelling and the shorter chain, not a score. cmd.exe remains in the tree, spelled by MSYS's own .cmd spawn rather than by us — the doc's one "unavoidable for .cmd/.bat" case, carrying an absolute path and two literal tokens, with no caret escaping, no encoding and no free text. The encoded launcher is still the shape for profile paths the shells cannot carry bare (a space, %, ^, &, non-ASCII, a UNC profile) and for hosts where Git Bash is not resolvable, because PowerShell 5.1 rejects || (measured: parse error, exit 1).

That last clause is the standing assumption of this change, and it is worth stating plainly because it is not measured. || parses in Git Bash, cmd.exe and pwsh, but not in Windows PowerShell 5.1, so the direct shape is correct for any host that is one of the first three. Claude Code itself is a Git Bash host on native Windows. What no one here has verified is which host a compat consumer uses: cursor-agent and Devin import ~/.claude/settings.json and run command through their own launcher (the managed .cmd carries a DEVIN_PROJECT_DIR skip for exactly that). If one of them spawns hook strings through Windows PowerShell 5.1, its imported Claude events become a parse error with empty stdout, which is the fail-closed case #14818 exists to prevent. The encoded launcher had no such assumption — it was a powershell.exe invocation and therefore parsed anywhere. Before widening the direct shape to another agent, measure that consumer's host.

Computer use: screen capture, synthetic input, runtime-compiled MSIL

native/computer-use-windows/runtime.ps1 is a large PowerShell script. src/main/computer/desktop-script-provider-bridge.ts launches it as powershell.exe -NoLogo -NoProfile -NonInteractive -ExecutionPolicy RemoteSigned -File runtime.ps1 <operation.json>, retrying once at Bypass only if the start comes back policy-blocked — once per operation, with desktop-script-provider-client.ts writing a fresh operation.json into a new temp directory each time. On every launch the script runs Add-Type -TypeDefinition over inline C# that P/Invokes SendInput and the window APIs, then captures the screen through Graphics.CopyFromScreen.

That is four separate high-signal behaviours stacked in one process:

Behaviour How it is scored
Graphics.CopyFromScreen MITRE T1113, screen capture — Collection tactic
SendInput synthetic keyboard/mouse input synthesis against other applications
Add-Type -TypeDefinition on every operation MSIL compiled at runtime; incident F's "suspicious MSIL code"
One powershell.exe per operation a burst of short-lived interpreters under one parent

The bottom two rows are the two the incident text named directly, and they are also the two a persistent runtime host would remove: a long-lived helper compiles its P/Invoke stubs once and answers operations over a channel, so neither the MSIL recompilation nor the interpreter burst repeats. A change doing that is in flight and unmerged at the time of writing; check the code rather than this paragraph for what the shipped build does. Screen capture and SendInput are inherent to the feature and no refactor removes them.

Signing is not the gate

The most useful calibration in the whole incident set came from the reporter's own machine: Antigravity IDE's main executable is NotSigned and was not flagged, while Orca's is signed and was flagged six times. Their conclusion: "signing is not the gate here — behaviour is."

The mechanism is that Defender reputation is signer plus prevalence, and prevalence is keyed on file hash. A widely installed unsigned binary clears on install count alone. Orca's signature is a free OV certificate from SignPath Foundation (config/electron-builder.config.cjs sets win.signtoolOptions.publisherName; config/scripts/verify-windows-inner-signature.mjs pins CN=SignPath Foundation, O=SignPath Foundation, L=Lewes, S=Delaware, C=US), shared across many OSS projects, with no independent SmartScreen or MAPS reputation of its own. Every release ships new hashes, so whatever prevalence a build accumulates resets on the next update. Dev channels ship unsigned by design, because SignPath's approval waits cannot fit a dev cadence (config/scripts/verify-dev-channel-packaging.mjs).

Signing the uninstaller is worth doing — an unsigned old-uninstaller.exe running under a signed installer is a gratuitous contribution to the update cluster — but do not expect it to change the behavioural verdict. The three non-update clusters contain no unsigned binary at all.

What we do not know

Two limits the incident analysis recorded, kept here rather than smoothed over:

  • No data on Hermes. Nothing in this document describes how Hermes behaves under the same tenant policy — though src/shared/hermes-startup-query.ts does spell -EncodedCommand, so the gap is telemetry, not surface.
  • Antigravity not being flagged is absence of evidence, not proof. It is one reporter's recollection from one machine, not a measurement. It is strong enough to falsify "the problem is that we are not signed well enough"; it is not strong enough to support a positive claim about how Defender scores that product.

Add to those: this is one tenant with one policy configuration. Whether the same build scores the same way elsewhere is unmeasured.

Guidance for engineers

Fixes for several of the shapes above are in flight in separate changes; nothing in this section should be read as a statement that a given site has already changed. Check the code before relying on it.

The checklist. On Windows, do not reach for:

Don't Instead
-ExecutionPolicy Bypass on the command line Set the policy in-payload at process scope, as windows-powershell-hook-launcher.ts does, or do not run a .ps1 at all
-EncodedCommand A temp .ps1 with an argument, or no PowerShell hop: prefer a native API or an existing Node path
cmd.exe /c carrying escaped free text Spawn the real target directly. cmd.exe is only unavoidable for .cmd/.bat; keep free text out of the line where you can
Forking powershell.exe to read system state The native reader — windows-process-enumeration.md is the standing rule for the process table
A process per operation in a loop One long-lived helper with a request channel. A burst of short-lived interpreters under one parent is itself the signal
Add-Type -TypeDefinition at runtime A precompiled, signed assembly, or a native helper
Copying our own image under a different name Copy it verbatim — windows-daemon-host-relocation.md (done for the daemon host)
Deriving a script runner from a UI preference windows-setup-shell.md — the script declares its own interpreter

Two framing rules that outlast the table:

  • Shorten the interpreter chain. Each hop between Orca and the user's actual target is a scored edge and a place for AV to deny a CreateProcess. This is the shipped doctrine of #15520 and #15595.
  • Do not spell a flag you can avoid spelling. #16003 measured a denial that was independent of the payload and keyed purely on the switch combination on the command line. What is on the line is itself the detection surface.

Guidance for administrators deploying Orca

Path exclusions alone will not silence these

This is the single most important operational point, and it is the one most commonly got wrong. The six incidents are MDE EDR behavioural alerts. Defender Antivirus path exclusions suppress scan detections; they do not suppress EDR behavioural alerts the same way. Adding %LOCALAPPDATA%\Programs\orca\ to the AV exclusion list and expecting the incidents to stop will not work.

What actually stops incidents being created

An MDE alert suppression rule scoped to the process tree. Build it in Microsoft 365 Defender (Settings → Endpoints → Alert suppression), conditioned on:

  • Alert titles — A suspicious file was observed and Suspicious PowerShell command line, plus any further titles your tenant actually produced. Take the titles from your own incidents rather than from this list.
  • File paths — Orca.exe and orca-terminal-daemon.exe under %LOCALAPPDATA%\Programs\orca\ and %LOCALAPPDATA%\Orca\daemon-host\.

Scope it as narrowly as your tenant will tolerate, and review it when Orca updates: the daemon-host path carries a <version> segment, so a rule pinned to one version will silently stop matching. Two traps in that path in particular. Materialization stages into a <version>.staging-<hex> sibling before renaming it into place, so an exact-version rule misses the tree mid-update — which is precisely when the update-cluster incidents fire. And the root falls back to the Electron userData path when LOCALAPPDATA is unset, so %LOCALAPPDATA%\Orca\daemon-host\ is the normal location rather than a guaranteed one. Prefer a prefix match on …\Orca\daemon-host\ over a rule pinned to one full path.

Add AV path exclusions for those two directories as well — they cut scan cost on a tree that is rewritten on every update — but understand the division of labour. The exclusions reduce scanning; the suppression rule is what stops incidents being created.

Check your ASR rules

Check whether the tenant has the Attack Surface Reduction rule "Block executable files from running unless they meet a prevalence, age, or trusted list criterion" enabled. If it is, that alone explains a freshly signed Orca build being hit immediately after every update: each release ships new hashes, so every build starts at zero prevalence and zero age no matter how it is signed. Either allowlist the Orca install paths for that rule or expect a hit on each update.

Expect the alerts to recur after each update

Prevalence is keyed on file hash. An update replaces the hashes, the reputation starts over, and a suppression rule is the only thing carrying across.

Computer use: decide before you deploy

Read this section before enabling computer use on a monitored endpoint, not after.

On a monitored endpoint, an alert reading "Screenshots were taken unexpectedly on this device" is not the kind of finding a SOC dismisses on sight.

Incident E is the shape to expect: 5 alerts, 37 evidence items, a multi-stage incident mapped to ATT&CK Execution + Collection, and a description naming screen capture found in a script launched by powershell.exe. Incident F adds runtime-compiled MSIL to the same tree.

Every part of that is an accurate description of what the feature does. Orca's computer use takes screenshots, synthesises keyboard and mouse input into other applications, and compiles the P/Invoke stubs it needs at runtime. An organisation that monitors for Collection-tactic activity — and any organisation running MDE with default incident creation does — will see it, and will see it as Collection.

So decide deliberately, in advance:

  • Allowlist it, with a suppression rule covering the computer-use tree (powershell.exe with -File …\runtime.ps1) as well as the base Orca paths, and tell your SOC what it is before the first incident rather than during it.
  • Or leave it disabled on monitored endpoints.

What does not work is deploying it un-triaged and handling the incidents reactively. By the time a Collection-tactic incident is open, an analyst is already reading a description of screenshots being taken without the user's knowledge, and the burden of proof has moved to you.