Suspicious High IntegrityLevel Conhost Legacy Option (via process_creation)
This rule detects ForceV1 asks for information directly from the kernel space. Conhost connects to the console application. High IntegrityLevel means the process is running with elevated privileges, such as an Administrator context.
SigmainformationalWindowsv1
sigma
suspicious-high-integritylevel-conhost-legacy-option-via-process-creation
title: Suspicious High IntegrityLevel Conhost Legacy Option (via process_creation)
id: 84a732f5-1665-5bae-96ea-3944d2e5d053
status: stable
description: This rule detects ForceV1 asks for information directly from the kernel space. Conhost connects to the console application. High IntegrityLevel means the process is running with elevated privileges, such as an Administrator context.
references:
- https://attack.mitre.org/techniques/T1202/
- https://cybercryptosec.medium.com/covid-19-cyber-infection-c615ead7c29
- https://thedfirreport.com/2022/04/04/stolen-images-campaign-ends-in-conti-ransomware/
- https://learn.microsoft.com/en-us/windows/win32/secauthz/mandatory-integrity-control
author: Huntrule Team
date: 2026-01-14
tags:
- attack.stealth
- attack.t1202
logsource:
product: windows
category: process_creation
detection:
selection:
IntegrityLevel:
- 'High'
- 'S-1-16-12288'
CommandLine|contains|all:
- 'conhost.exe'
- '0xffffffff'
- '-ForceV1'
condition: selection
falsepositives:
- Unknown
level: informational
Known false positives
- Unknown
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.