Conhost Spawned By Uncommon Parent Process

 Original Source: [Sigma source]
Title: Conhost Spawned By Uncommon Parent Process
Status: test
Description:Detects when the Console Window Host (conhost.exe) process is spawned by an uncommon parent process, which could be indicative of potential code injection activity.
References:
  -https://www.elastic.co/guide/en/security/current/conhost-spawned-by-suspicious-parent-process.html
Author: Tim Rauch, Elastic (idea)
Date: 2022-09-28
modified:2025-03-06
Tags:
  • -'attack.execution'
  • -'attack.t1059'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection:
    Image|endswith: '\conhost.exe'
    ParentImage|endswith:
      -'\explorer.exe'
      -'\lsass.exe'
      -'\regsvr32.exe'
      -'\rundll32.exe'
      -'\services.exe'
      -'\smss.exe'
      -'\spoolsv.exe'
      -'\svchost.exe'
      -'\userinit.exe'
      -'\wininit.exe'
      -'\winlogon.exe'

  filter_main_svchost:
    ParentCommandLine|contains:
      -'-k apphost -s AppHostSvc'
      -'-k imgsvc'
      -'-k localService -p -s RemoteRegistry'
      -'-k LocalSystemNetworkRestricted -p -s NgcSvc'
      -'-k NetSvcs -p -s NcaSvc'
      -'-k netsvcs -p -s NetSetupSvc'
      -'-k netsvcs -p -s wlidsvc'
      -'-k NetworkService -p -s DoSvc'
      -'-k wsappx -p -s AppXSvc'
      -'-k wsappx -p -s ClipSVC'
      -'-k wusvcs -p -s WaaSMedicSvc'

  filter_optional_dropbox:
    ParentCommandLine|contains:
      -'C:\Program Files (x86)\Dropbox\Client\'
      -'C:\Program Files\Dropbox\Client\'

  condition:selection and not 1 of filter_main_* and not 1 of filter_optional_*
Falsepositives:
  -Unknown
Level: medium