Malicious PowerShell Spawned by IIS Worker Process via OWASSRF Exchange Exploitation (via process_creation)

PremiumReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
HuntRule
Published
2026-08-01
Updated
2026-08-28

ATT&CK techniques

Initial Access → Execution
  1. Recon

  2. Resource Dev

  3. Persistence

  4. Priv Esc

  5. Defense Evasion

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects the IIS worker process w3wp.exe spawning PowerShell, a post-exploitation pattern seen in the OWASSRF exploitation of Exchange CVE-2022-41080 and CVE-2022-41082 through Outlook Web Access. Attackers use this server-side execution to run reconnaissance and drop tooling after bypassing ProxyNotShell mitigations, so PowerShell descended from an Exchange web process is a strong compromise signal.

Related detections9 linkedT1059.001 — drag to rearrange
Malicious ActiveMQ Exploitation Java Spawning PowerShell Downloader (via process_creation)
Suspicious Cleo Autorun Health Check File Drop (via file_event)
Obfuscated IIS Worker Spawning Encoded PowerShell after SharePoint ToolShell (via process_creation)
Malicious WSUS Service Spawning Command Shell via Remote Code Execution
Suspicious Child Process Spawned From Java Following Web Exploitation
Suspicious IIS Worker Process Spawning Encoded PowerShell via Gladinet Exploitation
MSSQL Server Process Spawning Command Shell via xp_cmdshell
Suspicious IIS Worker Process Spawning Encoded PowerShell via CentreStack Exploitation
Malicious FortiClient Process Spawning PowerShell Downloader (via process_creation)
Malicious PowerShell Spawned by IIS Worker Process via OWASSRF Exchange Exploitation (via process_creation)
Pivot detection · T1059.001 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.