Suspicious SimpleHelp Remote Access Client Spawning Discovery Commands (via process_creation)

PremiumReviewedSigma · Medium · v1
Product
windows
Category
process_creation
Author
HuntRule
Published
2026-05-04
Updated
2026-08-28

ATT&CK techniques

Discovery → Lateral Movement
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule detects the SimpleHelp Remote Access client spawning a command shell that runs account and domain enumeration utilities. Following exploitation of SimpleHelp RMM for initial access, operators used the persisted client to run net and nltest reconnaissance.

Related detections9 linkedT1018 — drag to rearrange
Windows Process Creation: China Chopper Webshell Command Pattern via W3WP
Windows Webserver Parent Process Launching Credential Dumping and Exfiltration Commands
Windows Webshell Recon Command-Line Keywords via Web Server Processes
Suspicious Automated SSH Lateral Movement with Batch Mode (via process_creation)
OpenSSH Native Server Feature Installation (via powershell)
OpenSSH Server Listening on Socket (via openssh)
Malicious DNS Hosts File Accessed via Network Share (via security)
Suspicious macOS SSH Loopback Connection for TCC Bypass
Suspicious Active Directory Subnet Enumeration via ADFind Subnets Query (via process_creation)
Suspicious SimpleHelp Remote Access Client Spawning Discovery Commands (via process_creation)
Pivot detection · T1018 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.