Suspicious Child Process Spawning by PowerShell on Windows
Alerts when PowerShell spawns potentially suspicious child binaries (e.g., certutil, mshta, wmic, rundll32), with exclusions for known benign patterns.
- Product
- windows
- Category
- process_creation
- Author
- Florian Roth (Nextron Systems), Tim Shelton (SigmaHQ), DRL 1.1
- Published
- 2022-04-26
- Updated
- 2026-07-31
ATT&CK techniques
ExecutionRecon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule flags Windows process creation events where PowerShell (powershell.exe, pwsh.exe, or powershell_ise.exe) launches a set of potentially suspicious child executables. Attackers commonly chain PowerShell to other living-off-the-land binaries to execute actions, stage payloads, or proxy execution while reducing direct tool visibility. It relies on telemetry that records process creation with parent and image paths plus command lines to support optional exclusions for known script locations and specific certutil/wmic usage patterns.
Reporting behind it
Changelog
v4- v4Candidate ingested via manual entry.2026-07-31
- v3Candidate ingested via manual entry.2026-07-31
- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: Suspicious Child Process Spawning by PowerShell on Windows
id: 8e0cdcdc-8b18-4a0b-9a4e-ccb8297d6319
status: test
description: This rule flags Windows process creation events where PowerShell (powershell.exe, pwsh.exe, or powershell_ise.exe) launches a set of potentially suspicious child executables. Attackers commonly chain PowerShell to other living-off-the-land binaries to execute actions, stage payloads, or proxy execution while reducing direct tool visibility. It relies on telemetry that records process creation with parent and image paths plus command lines to support optional exclusions for known script locations and specific certutil/wmic usage patterns.
references:
- https://twitter.com/ankit_anubhav/status/1518835408502620162
- https://github.com/SigmaHQ/sigma/blob/master/rules-threat-hunting/windows/process_creation/proc_creation_win_powershell_susp_child_processes.yml
author: Florian Roth (Nextron Systems), Tim Shelton, Huntrule Team
date: 2022-04-26
modified: 2024-07-16
tags:
- attack.execution
- attack.t1059.001
- detection.threat-hunting
logsource:
category: process_creation
product: windows
detection:
selection:
ParentImage|endswith:
- \powershell_ise.exe
- \powershell.exe
- \pwsh.exe
Image|endswith:
- \bash.exe
- \bitsadmin.exe
- \certutil.exe
- \cscript.exe
- \forfiles.exe
- \hh.exe
- \mshta.exe
- \regsvr32.exe
- \rundll32.exe
- \schtasks.exe
- \scrcons.exe
- \scriptrunner.exe
- \sh.exe
- \wmic.exe
- \wscript.exe
filter_optional_amazon:
ParentCommandLine|contains: \Program Files\Amazon\WorkspacesConfig\Scripts\
CommandLine|contains: \Program Files\Amazon\WorkspacesConfig\Scripts\
filter_main_certutil_verify_store:
Image|endswith: \certutil.exe
CommandLine|contains: "-verifystore "
filter_main_wmic:
Image|endswith: \wmic.exe
CommandLine|contains:
- qfe list
- "diskdrive "
- "csproduct "
- "computersystem "
- " os "
- ""
condition: selection and not 1 of filter_main_* and not 1 of filter_optional_*
falsepositives:
- False positives are to be expected from PowerShell scripts that might make use of additional binaries such as "mshta", "bitsadmin", etc. Apply additional filters for those scripts.
level: medium
license: DRL-1.1
related:
- id: e4b6d2a7-d8a4-4f19-acbd-943c16d90647
type: derived