Windows: Uncommon Child Processes Spawned by Bginfo.exe

Flags unusual processes launched by Bginfo.exe/ Bginfo64.exe that may indicate abused proxy execution.

FreeReviewedSigma · Medium · v2
Product
windows
Category
process_creation
Author
Nasreddine Bencherchali (Nextron Systems), Beyu Denis, oscd.community (SigmaHQ), DRL 1.1
Published
2019-10-26
Updated
2026-07-31

ATT&CK techniques

Execution → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Persistence

  5. Priv Esc

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

Identifies process creation events where the parent process is BgInfo.exe or BgInfo64.exe and the spawned child process is considered uncommon. Attackers may use BgInfo as a proxy to execute additional payloads or tooling under a trusted-looking parent. The rule relies on Windows process creation telemetry, specifically the parent image path and the resulting child process creation.

Related detections9 linkedT1202 — drag to rearrange
Suspicious Child Process Creation from BgInfo.EXE on Windows
Windows ConHost Spawning Suspicious Script and Command-Line Child Processes
Windows: Suspicious Child Process Spawned by VsCode code.exe
Windows WSL Process Spawning Uncommon Child Executables
Windows: Alert on Unusual Child Process of Setres.EXE Spawning 'choice' Executables
Windows Process Creation: Detect Sysinternals Tool Name Impersonation by Executable
Windows ZipExec-Style Suspicious PowerShell/Command Execution with Password-Protected ZIP
Windows: Cmdl32.EXE Arbitrary File Download Indicator via /vpn and /lan Flags
Windows Process Creation: WSL (wsl.exe) Used for Arbitrary Command Execution
Windows: Uncommon Child Processes Spawned by Bginfo.exe
Pivot detection · T1202 · 9 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.