Windows: ManageEngine ServiceDesk Java Parent Spawns Suspicious PowerShell or Credential/LSASS Actions
Alerts on suspicious child PowerShell/LSASS/tool activity launched by ManageEngine ServiceDesk (Java parent) on Windows.
FreeUnreviewedSigmacriticalv1
windows-manageengine-servicedesk-java-parent-spawns-suspicious-powershell-or-cre-58d8341a
title: "Windows: ManageEngine ServiceDesk Java Parent Spawns Suspicious PowerShell or Credential/LSASS Actions"
id: d1281233-fd51-41db-a2d1-be2450bc70eb
status: test
description: This rule flags Windows process creation where a ManageEngine-related parent process path containing 'manageengine' or 'ServiceDesk' (with a parent image containing '\java') spawns child activity associated with PowerShell, LSASS-related command lines, or other tool/script behaviors. It matters because these command patterns commonly indicate staging, credential access, defense evasion, and system discovery actions that can accompany targeted intrusions. The detection relies on process creation telemetry, including parent image path, child executable name, and command-line content, plus exclusions for installers and downloads from manageengine and download.microsoft.com domains.
references:
- https://www.microsoft.com/en-us/security/blog/2023/04/18/nation-state-threat-actor-mint-sandstorm-refines-tradecraft-to-attack-high-value-targets/
- https://github.com/SigmaHQ/sigma/blob/master/rules-emerging-threats/2023/TA/Mint-Sandstorm/proc_creation_win_apt_mint_sandstorm_manage_engine_susp_child_process.yml
author: Nasreddine Bencherchali (Nextron Systems), MSTIC (idea), Huntrule Team
date: 2023-04-20
modified: 2025-10-19
tags:
- attack.execution
- detection.emerging-threats
logsource:
category: process_creation
product: windows
detection:
selection_parent_path:
ParentImage|contains:
- manageengine
- ServiceDesk
selection_parent_image:
ParentImage|contains: \java
selection_special_child_powershell_img:
Image|endswith:
- \powershell.exe
- \powershell_ise.exe
selection_special_child_powershell_cli:
- CommandLine|contains:
- " echo "
- -dumpmode
- -ssh
- .dmp
- add-MpPreference
- adscredentials
- bitsadmin
- certutil
- csvhost.exe
- DownloadFile
- DownloadString
- dsquery
- ekern.exe
- FromBase64String
- "iex "
- iex(
- Invoke-Expression
- Invoke-WebRequest
- localgroup administrators
- o365accountconfiguration
- samaccountname=
- set-MpPreference
- svhost.exe
- System.IO.Compression
- System.IO.MemoryStream
- usoprivate
- usoshared
- whoami
- CommandLine|re: "[-/–][Ee^]{1,2}[ncodema^]*\\s[A-Za-z0-9+/=]{15,}"
- CommandLine|re: net\s+user
- CommandLine|re: net\s+group
- CommandLine|re: query\ssession
selection_special_child_lsass_1:
CommandLine|contains: lsass
selection_special_child_lsass_2:
CommandLine|contains:
- procdump
- tasklist
- findstr
selection_child_wget:
Image|endswith: \wget.exe
CommandLine|contains: http
selection_child_curl:
Image|endswith: \curl.exe
CommandLine|contains: http
selection_child_script:
CommandLine|contains:
- E:jscript
- e:vbscript
selection_child_localgroup:
CommandLine|contains|all:
- localgroup Administrators
- /add
selection_child_net:
CommandLine|contains: net
CommandLine|contains|all:
- user
- /add
selection_child_reg:
- CommandLine|contains|all:
- reg add
- DisableAntiSpyware
- \Microsoft\Windows Defender
- CommandLine|contains|all:
- reg add
- DisableRestrictedAdmin
- CurrentControlSet\Control\Lsa
selection_child_wmic_1:
CommandLine|contains|all:
- wmic
- process call create
selection_child_wmic_2:
CommandLine|contains|all:
- wmic
- delete
- shadowcopy
selection_child_vssadmin:
CommandLine|contains|all:
- vssadmin
- delete
- shadows
selection_child_wbadmin:
CommandLine|contains|all:
- wbadmin
- delete
- catalog
filter_main:
CommandLine|contains|all:
- download.microsoft.com
- manageengine.com
- msiexec
condition: all of selection_parent_* and (all of selection_special_child_powershell_* or all of selection_special_child_lsass_* or 1 of selection_child_*) and not filter_main
falsepositives:
- Unlikely
level: critical
license: DRL-1.1
related:
- id: 58d8341a-5849-44cd-8ac8-8b020413a31b
type: derived
What it detects
This rule flags Windows process creation where a ManageEngine-related parent process path containing 'manageengine' or 'ServiceDesk' (with a parent image containing '\java') spawns child activity associated with PowerShell, LSASS-related command lines, or other tool/script behaviors. It matters because these command patterns commonly indicate staging, credential access, defense evasion, and system discovery actions that can accompany targeted intrusions. The detection relies on process creation telemetry, including parent image path, child executable name, and command-line content, plus exclusions for installers and downloads from manageengine and download.microsoft.com domains.
Known false positives
- Unlikely
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.