Windows: Child Process Spawned with SYSTEM Integrity by LOCAL/NETWORK SERVICE Parent

Alert on Windows executions where a SYSTEM-integrity child is spawned by a LOCAL SERVICE or NETWORK SERVICE parent, excluding a specific rundll32 pattern.

FreeReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
Teymur Kheirkhabarov, Roberto Rodriguez (@Cyb3rWard0g), Open Threat Research (OTR) (SigmaHQ), DRL 1.1
Published
2019-10-26
Updated
2026-07-30

ATT&CK techniques

Priv Esc → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule flags Windows process creation events where a child process runs with SYSTEM integrity while the parent process is associated with LOCAL SERVICE or NETWORK SERVICE accounts. Such behavior can indicate attempts to escalate privileges by leveraging service-context processes to spawn or execute SYSTEM-level code. The detection relies on process creation telemetry including parent user and child user/ integrity level fields, and it excludes cases involving rundll32.exe with a DavSetCookie command-line fragment.

Related detections3 linkedT1134.002 — drag to rearrange
Windows PUA AdvancedRun.exe Execution
Windows: AdvancedRun executed with RunAs IDs under high-privilege service accounts
Windows getsystem via Meterpreter/Cobalt Strike when services.exe starts a likely privilege escalation command
Windows: Child Process Spawned with SYSTEM Integrity by LOCAL/NETWORK SERVICE Parent
Pivot detection · T1134.002 · 3 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.