Windows: Alert on Suspicious HH.EXE Process Execution

Alerts on HH.exe execution where the command line references temp, downloads, Outlook, or other writable directories.

FreeReviewedSigma · High · v2
Product
windows
Category
process_creation
Author
Maxim Pavlunin (SigmaHQ), DRL 1.1
Published
2020-04-01
Updated
2026-07-31

ATT&CK techniques

Initial Access → Defense Evasion

What it detects

This rule flags executions of Microsoft HTML Help (HH.exe) when the process image is HH.exe and the command line contains multiple common user-accessible or staging locations. Attackers often leverage HH.exe to blend in with legitimate Windows binaries while loading attacker-controlled content from temporary, downloads, public, or Outlook-related directories. The detection relies on process creation telemetry including the original filename, the executed image path, and the full command line.

Related detections9 linkedT1059.001 — drag to rearrange
Windows Process Creation: Suspicious Children Spawned by HTML Help (hh.exe)
Windows AppLocker Audit-Mode Events Indicate Files Would Have Been Blocked
Windows AppLocker Blocked Application, Script, MSI, or Packaged-App Execution
Windows process creation: CrackMapExec execution via characteristic command-line flags
Windows: Koadic Command Prompt Invocation with /q /c chcp
Windows Process Creation: Suspicious Child Programs Spawned by mshta, PowerShell, wscript, rundll32
Suspicious PowerShell Spawned by cscript in Script Chain
Suspicious Script Host Execution of Decoy-Named JavaScript Dropper (PS1Bot)
Malicious Emmenhtal JavaScript Loader Spawning Encoded PowerShell
Windows: Alert on Suspicious HH.EXE Process Execution
Pivot detection · T1059.001 · 9 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.