Suspicious Child Process Creation from BgInfo.EXE on Windows

Alerts when BgInfo.exe spawns suspicious calc/cmd/cscript/mshta/powershell/wscript or runs from common AppData/Temp paths.

FreeReviewedSigma · High · v2
Product
windows
Category
process_creation
Author
Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2023-08-16
Updated
2026-07-31

ATT&CK techniques

Execution → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Persistence

  5. Priv Esc

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule flags Windows process creation events where BgInfo.exe or BgInfo64.exe spawns specific child processes such as command interpreters and scripting tools. This behavior can indicate abuse of BgInfo for proxy execution to launch additional binaries or scripts. The detection relies on process creation telemetry that includes parent image and child image paths/names.

Related detections9 linkedT1202 — drag to rearrange
Windows: Uncommon Child Processes Spawned by Bginfo.exe
Windows ConHost Spawning Suspicious Script and Command-Line Child Processes
Windows: Suspicious Child Process Spawned by VsCode code.exe
Windows WSL Process Spawning Uncommon Child Executables
Windows: Alert on Unusual Child Process of Setres.EXE Spawning 'choice' Executables
Windows Process Creation: Detect Sysinternals Tool Name Impersonation by Executable
Windows ZipExec-Style Suspicious PowerShell/Command Execution with Password-Protected ZIP
Windows: Cmdl32.EXE Arbitrary File Download Indicator via /vpn and /lan Flags
Windows Process Creation: WSL (wsl.exe) Used for Arbitrary Command Execution
Suspicious Child Process Creation from BgInfo.EXE on Windows
Pivot detection · T1202 · 9 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.