Windows: Detect suspicious PowerShell/Lsass tool execution launched by ManageEngine (ServiceDesk)

Alerts on suspicious child PowerShell/LSASS/tool activity launched by ManageEngine ServiceDesk (Java parent) on Windows.

FreeReviewedSigma · Critical · v5
Product
windows
Category
process_creation
Author
Nasreddine Bencherchali (Nextron Systems), MSTIC (idea) (SigmaHQ), DRL 1.1
Published
2023-04-20
Updated
2026-07-31

What it detects

This rule identifies Windows process executions where a ManageEngine-related parent process (containing "manageengine" and "ServiceDesk" and a Java parent path component) spawns suspicious child activity. It focuses on PowerShell usage with high-risk command patterns, as well as LSASS-related access and common “living off the land” tools for downloads, command execution, credential harvesting, and defensive tampering. The detection relies on process creation telemetry, including ParentImage, Image, and CommandLine, to correlate the parent application context with suspicious child command content.

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.