Windows MMC20 Lateral Movement via MMC.exe -Embedding spawned by svchost.exe

Alerts when svchost.exe launches mmc.exe with “-Embedding”, indicating potential MMC20 COM-based lateral movement.

FreeReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
@2xxeformyshirt (Security Risk Advisors) - rule; Teymur Kheirkhabarov (idea) (SigmaHQ), DRL 1.1
Published
2020-03-04
Updated
2026-07-30

ATT&CK techniques

Lateral Movement
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule flags process creation where svchost.exe spawns MMC.exe using a command line containing “-Embedding”. This behavior is consistent with MMC20.Application COM usage to execute or load components through a trusted Windows host, which can support lateral movement. The detection relies on process creation telemetry, matching parent image path, child image path, and the presence of “-Embedding” in the child command line.

Related detections9 linkedT1021.003 — drag to rearrange
Malicious Impacket DCOMexec Process Abuse via MMC (via process_creation)
Malicious Impacket DCOMexec Privilege Abuse via MMC (via security)
DCOM Lateral Movement - Via MMC20 (via powershell)
Suspicious DLL Payload Dropped Under Non-Standard Assembly Directory (via file_event)
Windows SpeechRuntime.exe Child Process Creation
Windows: Detect Suspicious DLL Loads by BaaUpdate.exe from Publicly Writable Paths
Windows: Detect baaupdate.exe Spawning Scripting, Admin, or LOLBin Child Processes
Windows Process Creation: Excel DCOM Child Processes Linked to ActivateMicrosoftApp
RPC Firewall detects remote DCOM/WMI-related RPC operations via specified interface UUIDs
Windows MMC20 Lateral Movement via MMC.exe -Embedding spawned by svchost.exe
Pivot detection · T1021.003 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.