Windows Remote Thread Creation via Ttdinject.exe Proxy

Alerts on Windows create-remote-thread events initiated by Ttdinject.exe used as a proxy.

FreeReviewedSigma · High · v2
Product
windows
Category
create_remote_thread
Author
frack113 (SigmaHQ), DRL 1.1
Published
2022-05-16
Updated
2026-07-31

ATT&CK techniques

Execution → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Persistence

  5. Priv Esc

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule flags remote thread creation events where the source image ends with '\\ttdinject.exe'. Using Ttdinject.exe as a proxy for remote thread injection can enable stealthy code execution in another process. It relies on Windows telemetry that records remote thread creation with the originating executable name.

Related detections9 linkedT1127 — drag to rearrange
Suspicious Code Compilation via Aspnet_compiler LOLBIN (via process_creation)
ArcSOC.exe Creates Suspicious Script/Executable Files on Windows
Suspicious Child Process of aspnet_compiler.exe on Windows
Suspicious aspnet_compiler.exe Execution from User or Temp Paths on Windows
Windows: Detect kavremover-related LOLBIN command-line usage
Windows node.exe Execution with -e/--eval and suspicious child process usage
Windows: Process creation involving VSIISExeLauncher.exe with -p and -a arguments
Windows Process Creation: Mftrace.exe Child Process Execution
Windows Process Creation: Remote.exe Execution
Windows Remote Thread Creation via Ttdinject.exe Proxy
Pivot detection · T1127 · 9 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.