Windows Execution of Microsoft.Workflow.Compiler.exe

Flags Windows process executions of Microsoft.Workflow.Compiler.exe, a binary that may be abused for arbitrary unsigned code execution.

FreeReviewedSigma · Medium · v5
Product
windows
Category
process_creation
Author
Nik Seetharaman, frack113 (SigmaHQ), DRL 1.1
Published
2019-01-16
Updated
2026-07-31

ATT&CK techniques

Execution → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Persistence

  5. Priv Esc

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule identifies process creation where Microsoft.Workflow.Compiler.exe is executed on Windows. Attackers may abuse workflow compilation features to run arbitrary code without requiring properly signed payloads. It relies on process creation telemetry capturing the executable image path ending with Microsoft.Workflow.Compiler.exe and the OriginalFileName field.

Related detections9 linkedT1218 — drag to rearrange
Windows: Suspicious Cdb.EXE Proxy Execution via Debugger Script Parameters
Suspicious More_eggs ie4uinit Copy to AppData Microsoft Folder
Suspicious Microsoft.NodejsTools.PressAnyKey LOLBAS Proxy Execution
Suspicious Renamed Windows Debugger CDB Execution
Suspicious Scripting Interpreter Execution From Downloads Or Temp via Reputation Hijacking
Suspicious MMC Console Spawning Script Interpreter via GrimResource
Suspicious MMC Console Loading MSC File From User Writable Path
Suspicious Cabinet Extraction of Masqueraded vstm Archive via extrac32
Suspicious Code Compilation via Aspnet_compiler LOLBIN (via process_creation)
Windows Execution of Microsoft.Workflow.Compiler.exe
Pivot detection · T1218 · 9 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.