Windows: Detect suspicious PowerShell/Lsass tool execution launched by ManageEngine (ServiceDesk)

Alerts on suspicious child PowerShell/LSASS/tool activity launched by ManageEngine ServiceDesk (Java parent) on Windows.

FreeReviewedSigma · Critical · v5
Product
windows
Category
process_creation
Author
Nasreddine Bencherchali (Nextron Systems), MSTIC (idea) (SigmaHQ), DRL 1.1
Published
2023-04-20
Updated
2026-07-31
title: "Windows: Detect suspicious PowerShell/Lsass tool execution launched by ManageEngine (ServiceDesk)"
id: d1281233-fd51-41db-a2d1-be2450bc70eb
status: test
description: This rule identifies Windows process executions where a ManageEngine-related parent process (containing "manageengine" and "ServiceDesk" and a Java parent path component) spawns suspicious child activity. It focuses on PowerShell usage with high-risk command patterns, as well as LSASS-related access and common “living off the land” tools for downloads, command execution, credential harvesting, and defensive tampering. The detection relies on process creation telemetry, including ParentImage, Image, and CommandLine, to correlate the parent application context with suspicious child command content.
references:
  - https://www.microsoft.com/en-us/security/blog/2023/04/18/nation-state-threat-actor-mint-sandstorm-refines-tradecraft-to-attack-high-value-targets/
  - https://github.com/SigmaHQ/sigma/blob/master/rules-emerging-threats/2023/TA/Mint-Sandstorm/proc_creation_win_apt_mint_sandstorm_manage_engine_susp_child_process.yml
author: Nasreddine Bencherchali (Nextron Systems), MSTIC (idea), Huntrule Team
date: 2023-04-20
modified: 2025-10-19
tags:
  - attack.execution
  - detection.emerging-threats
logsource:
  category: process_creation
  product: windows
detection:
  selection_parent_path:
    ParentImage|contains:
      - manageengine
      - ServiceDesk
  selection_parent_image:
    ParentImage|contains: \java
  selection_special_child_powershell_img:
    Image|endswith:
      - \powershell.exe
      - \powershell_ise.exe
  selection_special_child_powershell_cli:
    - CommandLine|contains:
        - " echo "
        - -dumpmode
        - -ssh
        - .dmp
        - add-MpPreference
        - adscredentials
        - bitsadmin
        - certutil
        - csvhost.exe
        - DownloadFile
        - DownloadString
        - dsquery
        - ekern.exe
        - FromBase64String
        - "iex "
        - iex(
        - Invoke-Expression
        - Invoke-WebRequest
        - localgroup administrators
        - o365accountconfiguration
        - samaccountname=
        - set-MpPreference
        - svhost.exe
        - System.IO.Compression
        - System.IO.MemoryStream
        - usoprivate
        - usoshared
        - whoami
    - CommandLine|re: "[-/–][Ee^]{1,2}[ncodema^]*\\s[A-Za-z0-9+/=]{15,}"
    - CommandLine|re: net\s+user
    - CommandLine|re: net\s+group
    - CommandLine|re: query\ssession
  selection_special_child_lsass_1:
    CommandLine|contains: lsass
  selection_special_child_lsass_2:
    CommandLine|contains:
      - procdump
      - tasklist
      - findstr
  selection_child_wget:
    Image|endswith: \wget.exe
    CommandLine|contains: http
  selection_child_curl:
    Image|endswith: \curl.exe
    CommandLine|contains: http
  selection_child_script:
    CommandLine|contains:
      - E:jscript
      - e:vbscript
  selection_child_localgroup:
    CommandLine|contains|all:
      - localgroup Administrators
      - /add
  selection_child_net:
    CommandLine|contains: net
    CommandLine|contains|all:
      - user
      - /add
  selection_child_reg:
    - CommandLine|contains|all:
        - reg add
        - DisableAntiSpyware
        - \Microsoft\Windows Defender
    - CommandLine|contains|all:
        - reg add
        - DisableRestrictedAdmin
        - CurrentControlSet\Control\Lsa
  selection_child_wmic_1:
    CommandLine|contains|all:
      - wmic
      - process call create
  selection_child_wmic_2:
    CommandLine|contains|all:
      - wmic
      - delete
      - shadowcopy
  selection_child_vssadmin:
    CommandLine|contains|all:
      - vssadmin
      - delete
      - shadows
  selection_child_wbadmin:
    CommandLine|contains|all:
      - wbadmin
      - delete
      - catalog
  filter_main:
    CommandLine|contains|all:
      - download.microsoft.com
      - manageengine.com
      - msiexec
  condition: all of selection_parent_* and (all of selection_special_child_powershell_* or all of selection_special_child_lsass_* or 1 of selection_child_*) and not filter_main
falsepositives:
  - Unlikely
level: critical
license: DRL-1.1
related:
  - id: 58d8341a-5849-44cd-8ac8-8b020413a31b
    type: derived