Suspicious svchost Masquerading Executed Outside System Directory

PremiumReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
HuntRule
Published
2026-07-29
Updated
2026-08-28

ATT&CK techniques

Priv Esc → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects a process named svchost.exe running from any location other than the System32 or SysWOW64 directories, matching the GopherWhisper JabGopher component that spawns a fake svchost.exe host for LaxGopher injection. The legitimate service host only executes from System, so a copy elsewhere reveals masquerading and process injection.

Related detections9 linkedT1055 — drag to rearrange
Windows Defender windefend Event 1119 flags RedSun TieringEngineService.exe EICAR test file
Windows svchost.exe Uncommon Command-Line Parameter Process Creation
Suspicious AppLaunch.exe Spawned As Injection Target (via process_creation)
Suspicious BugSleep Marker File in Public Directory
Malicious Fake Fortinet Patch Infostealer Execution (via process_creation)
Suspicious Masquerading Python Interpreter csshost Executing Script
Suspicious CRAT Injection Named Pipe ChromeUpdatePipe (via pipe_created)
AsyncRAT Injector libPK.dll Written to Public Folder (via file_event)
FortiClient Binary Executed from LocalAppData Compliance Directory (via process_creation)
Suspicious svchost Masquerading Executed Outside System Directory
Pivot detection · T1055 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.