Windows PingCastle Execution From Suspicious Parent Processes

Alerts on PingCastle (PingCastle.exe) being run with full scan/healthcheck arguments from potentially suspicious parent process locations.

FreeReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
Nasreddine Bencherchali (Nextron Systems), X__Junior (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2024-01-11
Updated
2026-07-30

ATT&CK techniques

Recon
  1. Resource Dev

  2. Initial Access

  3. Execution

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule flags execution of PingCastle on Windows when it is launched by a parent process with suspicious or uncommon command-line characteristics, including script/HTML/shortcut-related extensions and user or temporary directory paths. Attackers may use PingCastle-like discovery tooling during Active Directory reconnaissance, and disguising the launch origin helps evade monitoring. The detection relies on Windows process creation telemetry fields such as Image, OriginalFileName, CommandLine, and ParentCommandLine/ParentCommandLinePath matching.

Related detections4 linkedT1595 — drag to rearrange
Suspicious CTF-Framed Vulnerability Scanner User Agent via Webserver
Suspicious Hello-World Scraper Botnet User-Agent in Web Requests
Proxy HTTP GET traffic using Hello-World/1.0 user-agent (possible scraper botnet)
Windows Process Creation: PingCastle Execution with Full Healthcheck Scanners
Windows PingCastle Execution From Suspicious Parent Processes
Pivot detection · T1595 · 4 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.