Windows Autoit3.exe Created by Uncommon Process (curl.exe/KeyScramblerLogon.exe/etc.)

Alerts on Windows events where Autoit3.exe is created, with the producing process matching curl.exe or other uncommon executables.

FreeReviewedSigma · Medium · v5
Product
windows
Category
file_event
Author
Micah Babinski (SigmaHQ), DRL 1.1
Published
2023-10-15
Updated
2026-07-31

ATT&CK techniques

Execution → C2
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. Exfiltration

  12. Impact

What it detects

This rule flags file creation where Autoit3.exe is created as a target by unusual parent/tool processes such as curl.exe, KeyScramblerLogon.exe, ExtExport.exe, or wmprph.exe. Creating Autoit3.exe via non-standard utilities is a common tactic to stage execution using a scripting/automation binary and evade normal application startup paths. It relies on Windows file event telemetry that records the creating process image and the created target filename, matching on the relevant executable names and ends-with paths.

Related detections9 linkedT1105 — drag to rearrange
Suspicious Bash Reverse Shell via /dev/tcp
Malicious Remote Payload Piped to Shell via Curl or Wget
Suspicious Remote Script Transfer via Bitsadmin (via process_creation)
Suspicious PowerShell Download Cradle via ClickFix Fake CAPTCHA (via process_creation)
Malicious Curl MSI Download to ProgramData via Process Creation
Suspicious CloudZ RAT Payload Download via curl to ProgramData
Suspicious Velociraptor Agent Deployment via msiexec From Cloud Storage
Suspicious PowerShell Download of lib.zip Archive
Suspicious Python Execution via Renamed Synaptics Binary
Windows Autoit3.exe Created by Uncommon Process (curl.exe/KeyScramblerLogon.exe/etc.)
Pivot detection · T1105 · 9 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.