Windows Process Creation: Commvault qlogin using _+_PublicSharingUser_ and GUID Password

Alert on qlogin.exe commands that authenticate as _+_PublicSharingUser_ using a GUID-formatted password.

FreeReviewedSigma · Medium · v5
Product
windows
Category
process_creation
Author
Swachchhanda Shrawan Poudel (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2025-10-20
Updated
2026-07-31

ATT&CK techniques

Initial Access → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Execution

  4. Cred Access

  5. Discovery

  6. Lateral Movement

  7. Collection

  8. C2

  9. Exfiltration

  10. Impact

What it detects

This rule flags qlogin.exe command lines that include both the internal _+_PublicSharingUser_ and a password value matching a GUID pattern. Such behavior can indicate an exploit attempt where an attacker uses a GUID-like credential to authenticate. It relies on Windows process creation telemetry with access to the full command line.

Related detections4 linkedT1078.001 — drag to rearrange
Possible Check Point Management Application Token Authentication as Administrator (via checkpoint)
macOS Root Account Enable Attempt via dsenableroot
macOS: Guest account enabled via sysadminctl
Windows: Administrator Account Remote Logon via Negotiate (4624 LogonType 10)
Windows Process Creation: Commvault qlogin using _+_PublicSharingUser_ and GUID Password
Pivot detection · T1078.001 · 4 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.