Suspicious IIS Worker Process Spawning Whoami Reconnaissance

PremiumReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
HuntRule
Published
2026-09-30
Updated
2026-09-30

ATT&CK techniques

Persistence → Discovery
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects the IIS worker process w3wp.exe spawning whoami.exe, a webshell-driven reconnaissance behavior observed following exploitation of an internet-facing server. A web application context should never legitimately execute identity enumeration commands, so this parent-child relationship strongly indicates a deployed webshell running attacker commands. It typically marks the earliest hands-on-keyboard stage after initial access.

Related detections9 linkedT1505.003 — drag to rearrange
Windows Process Creation: China Chopper Webshell Command Pattern via W3WP
Windows Webserver Parent Process Launching Credential Dumping and Exfiltration Commands
Windows Webshell Recon Command-Line Keywords via Web Server Processes
Malicious Web Server Spawning Command Shell and curl Download via Webshell
Malicious IIS Worker Process Spawning PowerShell via Gladinet CentreStack Exploit
Exchange Worker Process Spawning Command Shell via OWASSRF
Suspicious PowerShell Spawned by SysAid Java Process
Suspicious PHP File Written to FreePBX Custom Firmware Directory (via file_event)
Possible Ivanti EPMM In-Memory Java Webshell Access via mifs 403.jsp
Suspicious IIS Worker Process Spawning Whoami Reconnaissance
Pivot detection · T1505.003 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.