This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Windows Processes Suspicious Parent Directory
Original Source:
[Sigma source]
Title:
Windows Processes Suspicious Parent Directory
Status:
test
Description:
Detect suspicious parent processes of well-known Windows processes
References:
-https://web.archive.org/web/20180718061628/https://securitybytes.io/blue-team-fundamentals-part-two-windows-processes-759fe15965e2
-https://www.carbonblack.com/2014/06/10/screenshot-demo-hunt-evil-faster-than-ever-with-carbon-black/
-https://www.13cubed.com/downloads/windows_process_genealogy_v2.pdf
Author:
vburov
Date:
2019-02-23
modified:
2025-03-06
Tags:
-'attack.stealth'
-'attack.t1036.003'
-'attack.t1036.005'
Logsource:
category: process_creation
product: windows
Detection:
selection:
Image|endswith
:
-'\svchost.exe'
-'\taskhost.exe'
-'\lsm.exe'
-'\lsass.exe'
-'\services.exe'
-'\lsaiso.exe'
-'\csrss.exe'
-'\wininit.exe'
-'\winlogon.exe'
filter_sys:
- ParentImage|endswith
:
- '\SavService.exe'
- '\ngen.exe'
- ParentImage|contains
:
- '\System32\'
- '\SysWOW64\'
filter_msmpeng:
ParentImage|contains
:
-'\Windows Defender\'
-'\Microsoft Security Client\'
ParentImage|endswith
:
'\MsMpEng.exe'
filter_null:
ParentImage
:
'None'
- ParentImage
:
- ''
- '-'
condition
:
selection and not 1 of filter_*
Falsepositives:
-Some security products seem to spawn these
Level:
low