Remote Thread Creation In Uncommon Target Image

 Original Source: [Sigma source]
Title: Remote Thread Creation In Uncommon Target Image
Status: test
Description:Detects uncommon target processes for remote thread creation
References:
  -https://web.archive.org/web/20220319032520/https://blog.redbluepurple.io/offensive-research/bypassing-injection-detection
Author: Florian Roth (Nextron Systems)
Date: 2022-03-16
modified:2025-07-04
Tags:
  • -'attack.privilege-escalation'
  • -'attack.stealth'
  • -'attack.t1055.003'
Logsource:
  • product: windows
  • category: create_remote_thread
Detection:
  selection:
    TargetImage|endswith:
      -'\calc.exe'
      -'\calculator.exe'
      -'\mspaint.exe'
      -'\notepad.exe'
      -'\ping.exe'
      -'\sethc.exe'
      -'\spoolsv.exe'
      -'\wordpad.exe'
      -'\write.exe'

  filter_main_csrss:
    SourceImage: 'C:\Windows\System32\csrss.exe'
  filter_main_notepad:
    SourceImage:
      -'C:\Windows\System32\explorer.exe'
      -'C:\Windows\System32\OpenWith.exe'

    TargetImage: 'C:\Windows\System32\notepad.exe'
  filter_main_sethc:
    SourceImage: 'C:\Windows\System32\AtBroker.exe'
    TargetImage: 'C:\Windows\System32\Sethc.exe'
  filter_optional_aurora_1:
    StartFunction: 'EtwpNotificationThread'
  filter_optional_aurora_2:
    SourceImage|contains: 'unknown process'
  filter_optional_vmtoolsd:
    SourceImage: 'C:\Program Files\VMware\VMware Tools\vmtoolsd.exe'
    StartFunction: 'GetCommandLineW'
    TargetImage:
      -'C:\Windows\System32\notepad.exe'
      -'C:\Windows\System32\spoolsv.exe'

  filter_optional_xerox_pjems:
    SourceImage: 'C:\Program Files\Xerox\XeroxPrintExperience\CommonFiles\XeroxPrintJobEventManagerService.exe'
    StartFunction: 'LoadLibraryW'
    TargetImage: 'C:\Windows\System32\spoolsv.exe'
  condition:selection and not 1 of filter_main_* and not 1 of filter_optional_*
Falsepositives:
  -Unknown
Level: medium