Suspicious conhost Headless Execution for Hidden Window

PremiumReviewedSigma · Medium · v1
Product
windows
Category
process_creation
Author
HuntRule
Published
2026-05-06
Updated
2026-08-28

ATT&CK techniques

Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. C2

  13. Exfiltration

  14. Impact

What it detects

This rule detects conhost launched with the --headless flag which suppresses the console window, a defense evasion technique seen in ACR Stealer intrusion chains. Hiding the console window conceals attacker command execution from the user during infostealer activity.

Related detections9 linkedT1564.003 — drag to rearrange
Conhost Suspicious Command Execution
Windows cmd.exe Executing start Utility with Hidden Window Flags (/b or /min)
PowerShell Launch With --headless From Conhost.exe on Windows
Windows: Headless Chromium Browser Execution via --headless
Windows Chromium-Based Browsers Launched with Headless Debugging and User Profile Directory
Windows PUA AdvancedRun.exe Execution
Windows Process Creation: Headless Chromium Download via dump-dom
PowerShell Hidden WindowStyle Indicator in Script Block Text (Windows)
Windows Process Creation: Detect Covenant PowerShell Launcher Command Lines
Suspicious conhost Headless Execution for Hidden Window
Pivot detection · T1564.003 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.