Windows Process Access: WerFaultSecure to MsMpEng.exe with dbgcore.dll/dbghelp.dll call trace
Alerts on WerFaultSecure.exe accessing MsMpEng.exe with dbgcore/dbghelp DLLs in the call trace.
FreeUnreviewedSigmahighv1
windows-process-access-werfaultsecure-to-msmpeng-exe-with-dbgcore-dll-dbghelp-dl-387df17d
title: "Windows Process Access: WerFaultSecure to MsMpEng.exe with dbgcore.dll/dbghelp.dll call trace"
id: ec16a6e9-5b3a-41e8-9f48-b593d58dbb08
related:
- id: 8a2f4b1c-3d5e-4f7a-9b2c-1e4f6d8a9c2b
type: similar
- id: 1f0b4cac-9c81-41f4-95d0-8475ff46b3e2
type: similar
- id: 387df17d-3b04-448f-8669-9e7fd5e5fd8c
type: derived
status: experimental
description: This rule flags Windows process access events where WerFaultSecure.exe accesses MsMpEng.exe and the call trace contains dbgcore.dll or dbghelp.dll. Such behavior matters because it can indicate debugging or dump-related activity used to impair or disrupt defensive monitoring. The detection relies on Sysmon ProcessAccess telemetry with call trace data being present for the access event.
references:
- https://blog.axelarator.net/hunting-for-edr-freeze/
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_access/proc_access_win_werfaultsecure_msmpeng_access.yml
author: Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule Team
date: 2025-11-27
tags:
- attack.defense-impairment
- attack.t1685
logsource:
category: process_access
product: windows
definition: |
Requires Sysmon Event ID 10 (ProcessAccess) with CallTrace enabled.
Example sysmon config snippet with grouping, as logging individual ProcessAccess events can generate excessive logs:
<ProcessAccess onmatch="include">
<Rule groupRelation="and">
<TargetImage condition="end with">\MsMpEng.exe</TargetImage>
<SourceImage condition="end with">\WerFaultSecure.exe</SourceImage>
</Rule>
</ProcessAccess>
detection:
selection:
SourceImage|endswith: \WerFaultSecure.exe
TargetImage|endswith: \MsMpEng.exe
CallTrace|contains:
- \dbgcore.dll
- \dbghelp.dll
condition: selection
falsepositives:
- Legitimate Windows Error Reporting operations
level: high
regression_tests_path: regression_data/rules/windows/process_access/proc_access_win_werfaultsecure_msmpeng_access/info.yml
license: DRL-1.1
What it detects
This rule flags Windows process access events where WerFaultSecure.exe accesses MsMpEng.exe and the call trace contains dbgcore.dll or dbghelp.dll. Such behavior matters because it can indicate debugging or dump-related activity used to impair or disrupt defensive monitoring. The detection relies on Sysmon ProcessAccess telemetry with call trace data being present for the access event.
Known false positives
- Legitimate Windows Error Reporting operations
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.