Java keytool Spawns System Shells or Scripting Utilities on Windows
Alerts when Java keytool.exe spawns command and script execution binaries like cmd.exe or PowerShell on Windows.
FreeReviewedSigma · High · v2
- Product
- windows
- Category
- process_creation
- Author
- Andreas Hunkeler (@Karneades) (SigmaHQ), DRL 1.1
- Published
- 2021-12-22
- Updated
- 2026-07-31
What it detects
This rule flags Windows process creation events where the parent process is keytool.exe and the spawned child process is a shell, scripting, or common execution utility. Such activity is suspicious because legitimate keytool usage typically does not launch command interpreters or system administration binaries. Detection relies on process creation telemetry that includes parent and child process image paths to match the keytool parent and the specific child executable names.
Reporting behind it
- redcanary.comhttps://redcanary.com/blog/intelligence-insights-december-2021
- synacktiv.comhttps://www.synacktiv.com/en/publications/how-to-exploit-cve-2021-40539-on-manageengine-adselfservice-plus.html
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_java_keytool_susp_child_process.yml
Changelog
v2- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
windows-keytool-exe-spawns-suspicious-command-line-shell-processes-90fb5e62
title: Java keytool Spawns System Shells or Scripting Utilities on Windows
id: 02a4122a-95ae-4149-aacf-b9c332a2a5d5
status: test
description: This rule flags Windows process creation events where the parent process is keytool.exe and the spawned child process is a shell, scripting, or common execution utility. Such activity is suspicious because legitimate keytool usage typically does not launch command interpreters or system administration binaries. Detection relies on process creation telemetry that includes parent and child process image paths to match the keytool parent and the specific child executable names.
references:
- https://redcanary.com/blog/intelligence-insights-december-2021
- https://www.synacktiv.com/en/publications/how-to-exploit-cve-2021-40539-on-manageengine-adselfservice-plus.html
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_java_keytool_susp_child_process.yml
author: Andreas Hunkeler (@Karneades), Huntrule Team
date: 2021-12-22
modified: 2023-01-21
tags:
- attack.initial-access
- attack.persistence
- attack.privilege-escalation
logsource:
category: process_creation
product: windows
detection:
selection:
ParentImage|endswith: \keytool.exe
Image|endswith:
- \cmd.exe
- \sh.exe
- \bash.exe
- \powershell.exe
- \pwsh.exe
- \schtasks.exe
- \certutil.exe
- \whoami.exe
- \bitsadmin.exe
- \wscript.exe
- \cscript.exe
- \scrcons.exe
- \regsvr32.exe
- \hh.exe
- \wmic.exe
- \mshta.exe
- \rundll32.exe
- \forfiles.exe
- \scriptrunner.exe
- \mftrace.exe
- \AppVLP.exe
- \systeminfo.exe
- \reg.exe
- \query.exe
condition: selection
falsepositives:
- Unknown
level: high
license: DRL-1.1
related:
- id: 90fb5e62-ca1f-4e22-b42e-cc521874c938
type: derived