Sysinternals PsSuspend Suspicious Execution

 Original Source: [Sigma source]
Title: Sysinternals PsSuspend Suspicious Execution
Status: test
Description:Detects suspicious execution of Sysinternals PsSuspend, where the utility is used to suspend critical processes such as AV or EDR to bypass defenses
References:
  -https://learn.microsoft.com/en-us/sysinternals/downloads/pssuspend
  -https://twitter.com/0gtweet/status/1638069413717975046
Author: Nasreddine Bencherchali (Nextron Systems)
Date: 2023-03-23
modified:2026-06-29
Tags:
  • -'attack.defense-impairment'
  • -'attack.t1685'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_img:
OriginalFileName:'pssuspend.exe'     - Image|endswith:
      - '\pssuspend.exe'
      - '\pssuspend64.exe'
      - '\pssuspend64a.exe'
  selection_cli:
    CommandLine|contains: 'msmpeng.exe'
  condition:all of selection_*
Falsepositives:
  -Unlikely
Level: high