Uncommon Child Process Of Conhost.EXE

 Original Source: [Sigma source]
Title: Uncommon Child Process Of Conhost.EXE
Status: test
Description:Detects uncommon "conhost" child processes. This could be a sign of "conhost" usage as a LOLBIN or potential process injection activity.
References:
  -http://www.hexacorn.com/blog/2020/05/25/how-to-con-your-host/
Author: omkar72
Date: 2020-10-25
modified:2023-12-11
Tags:
  • -'attack.stealth'
  • -'attack.t1202'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection:
    ParentImage|endswith: '\conhost.exe'
  filter_main_conhost:
    Image|endswith: ':\Windows\System32\conhost.exe'
  filter_main_null:
    Image: 'None'
  filter_main_empty:
    Image: ''
  filter_optional_provider:
    Provider_Name: 'SystemTraceProvider-Process'
  condition:selection and not 1 of filter_main_* and not 1 of filter_optional_*
Falsepositives:
  -Unknown
Level: medium