Windows: AdvancedRun executed with RunAs IDs under high-privilege service accounts

Detects AdvancedRun execution where /RunAs is set to specific high-privilege IDs in the process command line.

FreeReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
Florian Roth (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2022-01-20
Updated
2026-07-30

ATT&CK techniques

Priv Esc → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule flags process creation where the command line indicates AdvancedRun usage along with specific /RunAs argument values (8, 4, 10, 11). Attackers and malware commonly use tools that can run under trusted or privileged contexts to increase stealth and effectiveness. The detection relies on Windows process creation telemetry, matching command-line substrings that include the AdvancedRun parameters and the targeted RunAs values.

Related detections3 linkedT1134.002 — drag to rearrange
Windows PUA AdvancedRun.exe Execution
Windows getsystem via Meterpreter/Cobalt Strike when services.exe starts a likely privilege escalation command
Windows: Child Process Spawned with SYSTEM Integrity by LOCAL/NETWORK SERVICE Parent
Windows: AdvancedRun executed with RunAs IDs under high-privilege service accounts
Pivot detection · T1134.002 · 3 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.