Windows hh.exe Execution Triggered by .chm Command Line

Flags hh.exe being executed with a command line referencing a .chm file on Windows.

FreeReviewedSigma · Low · v2
Product
windows
Category
process_creation
Author
E.M. Anhaus (originally from Atomic Blue Detections, Dan Beavin), oscd.community (SigmaHQ), DRL 1.1
Published
2019-10-24
Updated
2026-07-31
title: Windows hh.exe Execution Triggered by .chm Command Line
id: f3ad8d85-d858-478a-85b9-6f3c1d997e1b
status: test
description: This rule identifies Windows process executions where the binary appears to be hh.exe and the command line contains .chm. Attackers may use Microsoft HTML Help (hh.exe) to open crafted help files and execute subsequent actions. The detection relies on process creation telemetry including OriginalFileName, the executable image path/ending, and the full command line string.
references:
  - https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1218.001/T1218.001.md
  - https://eqllib.readthedocs.io/en/latest/analytics/b25aa548-7937-11e9-8f5c-d46d6d62a49e.html
  - https://www.zscaler.com/blogs/security-research/unintentional-leak-glimpse-attack-vectors-apt37
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_hh_chm_execution.yml
author: E.M. Anhaus (originally from Atomic Blue Detections, Dan Beavin), oscd.community, Huntrule Team
date: 2019-10-24
modified: 2023-12-11
tags:
  - attack.stealth
  - attack.t1218.001
logsource:
  category: process_creation
  product: windows
detection:
  selection_img:
    - OriginalFileName: HH.exe
    - Image|endswith: \hh.exe
  selection_cli:
    CommandLine|contains: .chm
  condition: all of selection_*
falsepositives:
  - False positives are expected with legitimate ".CHM"
level: low
regression_tests_path: regression_data/rules/windows/process_creation/proc_creation_win_hh_chm_execution/info.yml
license: DRL-1.1
related:
  - id: 68c8acb4-1b60-4890-8e82-3ddf7a6dba84
    type: derived