Windows: MMC spawning command-line executables

Flags cases where mmc.exe starts command-line tools like cmd, PowerShell, script hosts, or BITSADMIN.

FreeReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
Karneades, Swisscom CSIRT (SigmaHQ), DRL 1.1
Published
2019-08-05
Updated
2026-07-30

ATT&CK techniques

Lateral Movement
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule identifies process creation events where MMC (mmc.exe) spawns child executables used for command execution and administration, including cmd.exe, PowerShell (powershell.exe/pwsh.exe), script hosts, and common utilities. Attackers may use MMC as an execution proxy to blend into legitimate management activity while launching command tooling. It relies on process creation telemetry, matching the parent image ending with mmc.exe and the child image ending with specific command-line program names or containing BITSADMIN.

Related detections9 linkedT1021.003 — drag to rearrange
Malicious Impacket DCOMexec Process Abuse via MMC (via process_creation)
Malicious Impacket DCOMexec Privilege Abuse via MMC (via security)
DCOM Lateral Movement - Via MMC20 (via powershell)
Suspicious DLL Payload Dropped Under Non-Standard Assembly Directory (via file_event)
Windows SpeechRuntime.exe Child Process Creation
Windows: Detect Suspicious DLL Loads by BaaUpdate.exe from Publicly Writable Paths
Windows: Detect baaupdate.exe Spawning Scripting, Admin, or LOLBin Child Processes
Windows Process Creation: Excel DCOM Child Processes Linked to ActivateMicrosoftApp
RPC Firewall detects remote DCOM/WMI-related RPC operations via specified interface UUIDs
Windows: MMC spawning command-line executables
Pivot detection · T1021.003 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.