Conhost Suspicious Command Execution

PremiumReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
HuntRule
Published
2026-07-01
Updated
2026-08-28

ATT&CK techniques

Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. C2

  13. Exfiltration

  14. Impact

What it detects

Detects use of conhost in "headless" mode. By running conhost.exe in "headless" mode, it means that no visible window will pop up on the victim's machine.

Related detections9 linkedT1564.003 — drag to rearrange
Suspicious conhost Headless Execution for Hidden Window
Windows cmd.exe Executing start Utility with Hidden Window Flags (/b or /min)
PowerShell Launch With --headless From Conhost.exe on Windows
Windows: Headless Chromium Browser Execution via --headless
Windows Chromium-Based Browsers Launched with Headless Debugging and User Profile Directory
Windows PUA AdvancedRun.exe Execution
Windows Process Creation: Headless Chromium Download via dump-dom
PowerShell Hidden WindowStyle Indicator in Script Block Text (Windows)
Windows Process Creation: Detect Covenant PowerShell Launcher Command Lines
Conhost Suspicious Command Execution
Pivot detection · T1564.003 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.