Suspicious notepad Spawned by mshta for Process Injection

PremiumReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
HuntRule
Published
2026-07-01
Updated
2026-08-28

ATT&CK techniques

Priv Esc → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects mshta spawning notepad which in the WithSecure Windows lab was created suspended as an injection host for a Covenant Grunt implant. The script host mshta launching notepad has no legitimate purpose and strongly suggests it is being used as a hollow target for process injection.

Related detections2 linkedT1055.003 — drag to rearrange
Windows Remote Thread Creation Targeting Uncommon System Image Processes
Windows Maldoc Process Injection via winword.exe CallTrace from LittleCorporal
Suspicious notepad Spawned by mshta for Process Injection
Pivot detection · T1055.003 · 2 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.