Suspicious Command Shell Spawned by lmadmin License Manager via process_creation

PremiumReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
HuntRule
Published
2026-10-10
Updated
2026-10-10

ATT&CK techniques

Priv Esc → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects the lmadmin.exe license manager spawning a command shell or PowerShell, indicating post-exploitation of the Schneider Electric vulnerability including SeImpersonate Potato style privilege escalation. The license service has no legitimate need to launch interactive shells. A shell child under lmadmin points to exploitation and follow-on execution.

Related detections9 linkedT1068 — drag to rearrange
Suspicious Potato Privilege Escalation Tool Execution via process_creation
Suspicious W32TIME Named Pipe Activity Linked to RPC Privilege Escalation (via pipe_created)
Suspicious Named Pipe TyphoonPWN Local Privilege Escalation Marker (via pipe_created)
Suspicious Dell DBUtilDrv2 Vulnerable Driver Load via driver_load
Malicious Potato Privilege Escalation Tooling Execution
Suspicious RdpBus Registry Symbolic Link Creation for Privilege Escalation
Malicious Vulnerable Driver Mapping via KDU
Malicious Vulnerable Driver Load via TfSysMon.sys BYOVD (via driver_load)
Malicious Vulnerable Driver Load by GentleKiller BYOVD EDR Killer
Suspicious Command Shell Spawned by lmadmin License Manager via process_creation
Pivot detection · T1068 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.