Renamed ProcDump Execution

 Original Source: [Sigma source]
Title: Renamed ProcDump Execution
Status: test
Description:Detects the execution of a renamed ProcDump executable. This often done by attackers or malware in order to evade defensive mechanisms.
References:
  -https://learn.microsoft.com/en-us/sysinternals/downloads/procdump
Author: Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems)
Date: 2019-11-18
modified:2026-06-29
Tags:
  • -'attack.stealth'
  • -'attack.t1036.003'
Logsource:
  • product: windows
  • category: process_creation
Detection:
  selection_ofn:
    OriginalFileName: 'procdump'
  selection_cli_dump_flag:
    CommandLine|contains|windash:
      -' -ma '
      -' -mp '

  selection_cli_eula_flag:
    CommandLine|contains|windash: ' /accepteula'
  filter_main_known_names:
    Image|endswith:
      -'\procdump.exe'
      -'\procdump64.exe'
      -'\procdump64a.exe'

  condition:(selection_ofn or all of selection_cli_*) and not 1 of filter_main_*
Falsepositives:
  -Procdump illegally bundled with legitimate software.
  -Administrators who rename binaries (should be investigated).
Level: high