Potentially Suspicious Child Process Of WinRAR.EXE (via process_creation)
This rule detects potentially anomalous child processes of WinRAR.exe.
SigmamediumWindowsv1
sigma
potentially-suspicious-child-process-of-winrar-exe-via-process-creation
title: Potentially Suspicious Child Process Of WinRAR.EXE (via process_creation)
id: cb028684-5ea7-5a59-89af-1b680edaf6a9
status: stable
description: This rule detects potentially anomalous child processes of WinRAR.exe.
references:
- https://attack.mitre.org/techniques/T1203/
- https://www.group-ib.com/blog/cve-2023-38831-winrar-zero-day/
- https://github.com/knight0x07/WinRAR-Code-Execution-Vulnerability-CVE-2023-38831/blob/26ab6c40b6d2c09bb4fc60feaa4a3a90cfd20c23/Part-1-Overview.md
author: Huntrule Team
date: 2026-07-03
tags:
- attack.execution
- attack.t1203
logsource:
category: process_creation
product: windows
detection:
selection_parent:
ParentImage|endswith: '\WinRAR.exe'
selection_binaries:
- Image|endswith:
- '\cmd.exe'
- '\cscript.exe'
- '\mshta.exe'
- '\powershell.exe'
- '\pwsh.exe'
- '\regsvr32.exe'
- '\rundll32.exe'
- '\wscript.exe'
- OriginalFileName:
- 'Cmd.Exe'
- 'cscript.exe'
- 'mshta.exe'
- 'PowerShell.EXE'
- 'pwsh.dll'
- 'regsvr32.exe'
- 'RUNDLL32.EXE'
- 'wscript.exe'
condition: all of selection_*
falsepositives:
- Unknown
level: medium
Known false positives
- Unknown
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.