Windows: Detect suspicious PowerShell/Lsass tool execution launched by ManageEngine (ServiceDesk)
Alerts on suspicious child PowerShell/LSASS/tool activity launched by ManageEngine ServiceDesk (Java parent) on Windows.
- Product
- windows
- Category
- process_creation
- Author
- Nasreddine Bencherchali (Nextron Systems), MSTIC (idea) (SigmaHQ), DRL 1.1
- Published
- 2023-04-20
- Updated
- 2026-07-31
What it detects
This rule identifies Windows process executions where a ManageEngine-related parent process (containing "manageengine" and "ServiceDesk" and a Java parent path component) spawns suspicious child activity. It focuses on PowerShell usage with high-risk command patterns, as well as LSASS-related access and common “living off the land” tools for downloads, command execution, credential harvesting, and defensive tampering. The detection relies on process creation telemetry, including ParentImage, Image, and CommandLine, to correlate the parent application context with suspicious child command content.
Reporting behind it
- microsoft.comhttps://www.microsoft.com/en-us/security/blog/2023/04/18/nation-state-threat-actor-mint-sandstorm-refines-tradecraft-to-attack-high-value-targets/
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules-emerging-threats/2023/TA/Mint-Sandstorm/proc_creation_win_apt_mint_sandstorm_manage_engine_susp_child_process.yml
Changelog
v5- v5Candidate ingested via manual entry.2026-07-31
- v4Candidate ingested via manual entry.2026-07-31
- v3Candidate ingested via manual entry.2026-07-31
- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: "Windows: Detect suspicious PowerShell/Lsass tool execution launched by ManageEngine (ServiceDesk)"
id: d1281233-fd51-41db-a2d1-be2450bc70eb
status: test
description: This rule identifies Windows process executions where a ManageEngine-related parent process (containing "manageengine" and "ServiceDesk" and a Java parent path component) spawns suspicious child activity. It focuses on PowerShell usage with high-risk command patterns, as well as LSASS-related access and common “living off the land” tools for downloads, command execution, credential harvesting, and defensive tampering. The detection relies on process creation telemetry, including ParentImage, Image, and CommandLine, to correlate the parent application context with suspicious child command content.
references:
- https://www.microsoft.com/en-us/security/blog/2023/04/18/nation-state-threat-actor-mint-sandstorm-refines-tradecraft-to-attack-high-value-targets/
- https://github.com/SigmaHQ/sigma/blob/master/rules-emerging-threats/2023/TA/Mint-Sandstorm/proc_creation_win_apt_mint_sandstorm_manage_engine_susp_child_process.yml
author: Nasreddine Bencherchali (Nextron Systems), MSTIC (idea), Huntrule Team
date: 2023-04-20
modified: 2025-10-19
tags:
- attack.execution
- detection.emerging-threats
logsource:
category: process_creation
product: windows
detection:
selection_parent_path:
ParentImage|contains:
- manageengine
- ServiceDesk
selection_parent_image:
ParentImage|contains: \java
selection_special_child_powershell_img:
Image|endswith:
- \powershell.exe
- \powershell_ise.exe
selection_special_child_powershell_cli:
- CommandLine|contains:
- " echo "
- -dumpmode
- -ssh
- .dmp
- add-MpPreference
- adscredentials
- bitsadmin
- certutil
- csvhost.exe
- DownloadFile
- DownloadString
- dsquery
- ekern.exe
- FromBase64String
- "iex "
- iex(
- Invoke-Expression
- Invoke-WebRequest
- localgroup administrators
- o365accountconfiguration
- samaccountname=
- set-MpPreference
- svhost.exe
- System.IO.Compression
- System.IO.MemoryStream
- usoprivate
- usoshared
- whoami
- CommandLine|re: "[-/–][Ee^]{1,2}[ncodema^]*\\s[A-Za-z0-9+/=]{15,}"
- CommandLine|re: net\s+user
- CommandLine|re: net\s+group
- CommandLine|re: query\ssession
selection_special_child_lsass_1:
CommandLine|contains: lsass
selection_special_child_lsass_2:
CommandLine|contains:
- procdump
- tasklist
- findstr
selection_child_wget:
Image|endswith: \wget.exe
CommandLine|contains: http
selection_child_curl:
Image|endswith: \curl.exe
CommandLine|contains: http
selection_child_script:
CommandLine|contains:
- E:jscript
- e:vbscript
selection_child_localgroup:
CommandLine|contains|all:
- localgroup Administrators
- /add
selection_child_net:
CommandLine|contains: net
CommandLine|contains|all:
- user
- /add
selection_child_reg:
- CommandLine|contains|all:
- reg add
- DisableAntiSpyware
- \Microsoft\Windows Defender
- CommandLine|contains|all:
- reg add
- DisableRestrictedAdmin
- CurrentControlSet\Control\Lsa
selection_child_wmic_1:
CommandLine|contains|all:
- wmic
- process call create
selection_child_wmic_2:
CommandLine|contains|all:
- wmic
- delete
- shadowcopy
selection_child_vssadmin:
CommandLine|contains|all:
- vssadmin
- delete
- shadows
selection_child_wbadmin:
CommandLine|contains|all:
- wbadmin
- delete
- catalog
filter_main:
CommandLine|contains|all:
- download.microsoft.com
- manageengine.com
- msiexec
condition: all of selection_parent_* and (all of selection_special_child_powershell_* or all of selection_special_child_lsass_* or 1 of selection_child_*) and not filter_main
falsepositives:
- Unlikely
level: critical
license: DRL-1.1
related:
- id: 58d8341a-5849-44cd-8ac8-8b020413a31b
type: derived