Suspicious Remote Thread Created in notepad Process

PremiumReviewedSigma · Medium · v1
Product
windows
Category
create_remote_thread
Author
HuntRule
Published
2026-05-31
Updated
2026-08-28

ATT&CK techniques

Priv Esc → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects a remote thread being created inside a notepad process which is the CreateRemoteThread injection step described in the WithSecure Windows lab where shellcode was written into a suspended notepad and executed. Notepad is rarely a legitimate target of cross process thread creation so this pattern is a reliable process injection indicator.

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.