Windows: Malicious Child Process Execution via vsjitdebugger.exe Just-In-Time Debugger
Flags unusual executables launched by vsjitdebugger.exe on Windows, excluding common Visual Studio helper/debugger children.
FreeUnreviewedSigmamediumv1
windows-malicious-child-process-execution-via-vsjitdebugger-exe-just-in-time-deb-15c7904e
title: "Windows: Malicious Child Process Execution via vsjitdebugger.exe Just-In-Time Debugger"
id: 28bf9b48-73aa-4b25-ad2c-d2310795eb49
status: test
description: This rule identifies process creation where the parent process is Microsoft Visual Studio Just-In-Time Debugger (vsjitdebugger.exe), but excludes likely benign helper/debugger scenarios. Attackers can abuse this functionality to launch and run arbitrary executables under the context of a trusted, developer-installed component. It relies on process creation telemetry capturing both the parent image path and the spawned child image path on Windows.
references:
- https://twitter.com/pabraeken/status/990758590020452353
- https://lolbas-project.github.io/lolbas/OtherMSBinaries/Vsjitdebugger/
- https://learn.microsoft.com/en-us/visualstudio/debugger/debug-using-the-just-in-time-debugger?view=vs-2019
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_susp_use_of_vsjitdebugger_bin.yml
author: Agro (@agro_sev), Ensar Şamil (@sblmsrsn), oscd.community, Huntrule Team
date: 2020-10-14
modified: 2022-10-09
tags:
- attack.stealth
- attack.t1218
logsource:
category: process_creation
product: windows
detection:
selection:
ParentImage|endswith: \vsjitdebugger.exe
reduction1:
Image|endswith: \vsimmersiveactivatehelper*.exe
reduction2:
Image|endswith: \devenv.exe
condition: selection and not (reduction1 or reduction2)
falsepositives:
- The process spawned by vsjitdebugger.exe is uncommon.
level: medium
license: DRL-1.1
related:
- id: 15c7904e-6ad1-4a45-9b46-5fb25df37fd2
type: derived
What it detects
This rule identifies process creation where the parent process is Microsoft Visual Studio Just-In-Time Debugger (vsjitdebugger.exe), but excludes likely benign helper/debugger scenarios. Attackers can abuse this functionality to launch and run arbitrary executables under the context of a trusted, developer-installed component. It relies on process creation telemetry capturing both the parent image path and the spawned child image path on Windows.
Known false positives
- The process spawned by vsjitdebugger.exe is uncommon.
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.