Potential DLL Injection via AccCheckConsole.exe Command-Line Parameters on Windows

Alerts on AccCheckConsole.exe executions whose CLI parameters align with loading custom verification logic via a DLL.

FreeReviewedSigma · Medium · v2
Product
windows
Category
process_creation
Author
Florian Roth (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2022-01-06
Updated
2026-07-31

What it detects

This rule flags execution of AccCheckConsole.exe with command-line arguments that include the window handle switch, a target process identifier, and a window selector. AccCheckConsole supports providing a custom verification routine via a DLL, which could be supplied by an attacker and loaded under the tool’s execution context. The detection relies on Windows process creation telemetry, matching the executable identity and specific command-line fragments.

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.