Windows: ManageEngine ServiceDesk Java Parent Spawns Suspicious PowerShell or Credential/LSASS Actions

Alerts on suspicious child PowerShell/LSASS/tool activity launched by ManageEngine ServiceDesk (Java parent) on Windows.

FreeUnreviewedSigmacriticalv1
title: "Windows: ManageEngine ServiceDesk Java Parent Spawns Suspicious PowerShell or Credential/LSASS Actions"
id: d1281233-fd51-41db-a2d1-be2450bc70eb
status: test
description: This rule flags Windows process creation where a ManageEngine-related parent process path containing 'manageengine' or 'ServiceDesk' (with a parent image containing '\java') spawns child activity associated with PowerShell, LSASS-related command lines, or other tool/script behaviors. It matters because these command patterns commonly indicate staging, credential access, defense evasion, and system discovery actions that can accompany targeted intrusions. The detection relies on process creation telemetry, including parent image path, child executable name, and command-line content, plus exclusions for installers and downloads from manageengine and download.microsoft.com domains.
references:
  - https://www.microsoft.com/en-us/security/blog/2023/04/18/nation-state-threat-actor-mint-sandstorm-refines-tradecraft-to-attack-high-value-targets/
  - https://github.com/SigmaHQ/sigma/blob/master/rules-emerging-threats/2023/TA/Mint-Sandstorm/proc_creation_win_apt_mint_sandstorm_manage_engine_susp_child_process.yml
author: Nasreddine Bencherchali (Nextron Systems), MSTIC (idea), Huntrule Team
date: 2023-04-20
modified: 2025-10-19
tags:
  - attack.execution
  - detection.emerging-threats
logsource:
  category: process_creation
  product: windows
detection:
  selection_parent_path:
    ParentImage|contains:
      - manageengine
      - ServiceDesk
  selection_parent_image:
    ParentImage|contains: \java
  selection_special_child_powershell_img:
    Image|endswith:
      - \powershell.exe
      - \powershell_ise.exe
  selection_special_child_powershell_cli:
    - CommandLine|contains:
        - " echo "
        - -dumpmode
        - -ssh
        - .dmp
        - add-MpPreference
        - adscredentials
        - bitsadmin
        - certutil
        - csvhost.exe
        - DownloadFile
        - DownloadString
        - dsquery
        - ekern.exe
        - FromBase64String
        - "iex "
        - iex(
        - Invoke-Expression
        - Invoke-WebRequest
        - localgroup administrators
        - o365accountconfiguration
        - samaccountname=
        - set-MpPreference
        - svhost.exe
        - System.IO.Compression
        - System.IO.MemoryStream
        - usoprivate
        - usoshared
        - whoami
    - CommandLine|re: "[-/–][Ee^]{1,2}[ncodema^]*\\s[A-Za-z0-9+/=]{15,}"
    - CommandLine|re: net\s+user
    - CommandLine|re: net\s+group
    - CommandLine|re: query\ssession
  selection_special_child_lsass_1:
    CommandLine|contains: lsass
  selection_special_child_lsass_2:
    CommandLine|contains:
      - procdump
      - tasklist
      - findstr
  selection_child_wget:
    Image|endswith: \wget.exe
    CommandLine|contains: http
  selection_child_curl:
    Image|endswith: \curl.exe
    CommandLine|contains: http
  selection_child_script:
    CommandLine|contains:
      - E:jscript
      - e:vbscript
  selection_child_localgroup:
    CommandLine|contains|all:
      - localgroup Administrators
      - /add
  selection_child_net:
    CommandLine|contains: net
    CommandLine|contains|all:
      - user
      - /add
  selection_child_reg:
    - CommandLine|contains|all:
        - reg add
        - DisableAntiSpyware
        - \Microsoft\Windows Defender
    - CommandLine|contains|all:
        - reg add
        - DisableRestrictedAdmin
        - CurrentControlSet\Control\Lsa
  selection_child_wmic_1:
    CommandLine|contains|all:
      - wmic
      - process call create
  selection_child_wmic_2:
    CommandLine|contains|all:
      - wmic
      - delete
      - shadowcopy
  selection_child_vssadmin:
    CommandLine|contains|all:
      - vssadmin
      - delete
      - shadows
  selection_child_wbadmin:
    CommandLine|contains|all:
      - wbadmin
      - delete
      - catalog
  filter_main:
    CommandLine|contains|all:
      - download.microsoft.com
      - manageengine.com
      - msiexec
  condition: all of selection_parent_* and (all of selection_special_child_powershell_* or all of selection_special_child_lsass_* or 1 of selection_child_*) and not filter_main
falsepositives:
  - Unlikely
level: critical
license: DRL-1.1
related:
  - id: 58d8341a-5849-44cd-8ac8-8b020413a31b
    type: derived

What it detects

This rule flags Windows process creation where a ManageEngine-related parent process path containing 'manageengine' or 'ServiceDesk' (with a parent image containing '\java') spawns child activity associated with PowerShell, LSASS-related command lines, or other tool/script behaviors. It matters because these command patterns commonly indicate staging, credential access, defense evasion, and system discovery actions that can accompany targeted intrusions. The detection relies on process creation telemetry, including parent image path, child executable name, and command-line content, plus exclusions for installers and downloads from manageengine and download.microsoft.com domains.

Known false positives

  • Unlikely

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.