Java keytool Spawns System Shells or Scripting Utilities on Windows

Alerts when Java keytool.exe spawns command and script execution binaries like cmd.exe or PowerShell on Windows.

FreeReviewedSigma · High · v2
Product
windows
Category
process_creation
Author
Andreas Hunkeler (@Karneades) (SigmaHQ), DRL 1.1
Published
2021-12-22
Updated
2026-07-31
title: Java keytool Spawns System Shells or Scripting Utilities on Windows
id: 02a4122a-95ae-4149-aacf-b9c332a2a5d5
status: test
description: This rule flags Windows process creation events where the parent process is keytool.exe and the spawned child process is a shell, scripting, or common execution utility. Such activity is suspicious because legitimate keytool usage typically does not launch command interpreters or system administration binaries. Detection relies on process creation telemetry that includes parent and child process image paths to match the keytool parent and the specific child executable names.
references:
  - https://redcanary.com/blog/intelligence-insights-december-2021
  - https://www.synacktiv.com/en/publications/how-to-exploit-cve-2021-40539-on-manageengine-adselfservice-plus.html
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_java_keytool_susp_child_process.yml
author: Andreas Hunkeler (@Karneades), Huntrule Team
date: 2021-12-22
modified: 2023-01-21
tags:
  - attack.initial-access
  - attack.persistence
  - attack.privilege-escalation
logsource:
  category: process_creation
  product: windows
detection:
  selection:
    ParentImage|endswith: \keytool.exe
    Image|endswith:
      - \cmd.exe
      - \sh.exe
      - \bash.exe
      - \powershell.exe
      - \pwsh.exe
      - \schtasks.exe
      - \certutil.exe
      - \whoami.exe
      - \bitsadmin.exe
      - \wscript.exe
      - \cscript.exe
      - \scrcons.exe
      - \regsvr32.exe
      - \hh.exe
      - \wmic.exe
      - \mshta.exe
      - \rundll32.exe
      - \forfiles.exe
      - \scriptrunner.exe
      - \mftrace.exe
      - \AppVLP.exe
      - \systeminfo.exe
      - \reg.exe
      - \query.exe
  condition: selection
falsepositives:
  - Unknown
level: high
license: DRL-1.1
related:
  - id: 90fb5e62-ca1f-4e22-b42e-cc521874c938
    type: derived