Windows Process Access: WerFaultSecure to MsMpEng.exe with dbgcore.dll/dbghelp.dll call trace

Alerts on WerFaultSecure.exe accessing MsMpEng.exe with dbgcore/dbghelp DLLs in the call trace.

FreeUnreviewedSigmahighv1
title: "Windows Process Access: WerFaultSecure to MsMpEng.exe with dbgcore.dll/dbghelp.dll call trace"
id: ec16a6e9-5b3a-41e8-9f48-b593d58dbb08
related:
  - id: 8a2f4b1c-3d5e-4f7a-9b2c-1e4f6d8a9c2b
    type: similar
  - id: 1f0b4cac-9c81-41f4-95d0-8475ff46b3e2
    type: similar
  - id: 387df17d-3b04-448f-8669-9e7fd5e5fd8c
    type: derived
status: experimental
description: This rule flags Windows process access events where WerFaultSecure.exe accesses MsMpEng.exe and the call trace contains dbgcore.dll or dbghelp.dll. Such behavior matters because it can indicate debugging or dump-related activity used to impair or disrupt defensive monitoring. The detection relies on Sysmon ProcessAccess telemetry with call trace data being present for the access event.
references:
  - https://blog.axelarator.net/hunting-for-edr-freeze/
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_access/proc_access_win_werfaultsecure_msmpeng_access.yml
author: Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule Team
date: 2025-11-27
tags:
  - attack.defense-impairment
  - attack.t1685
logsource:
  category: process_access
  product: windows
  definition: |
    Requires Sysmon Event ID 10 (ProcessAccess) with CallTrace enabled.
    Example sysmon config snippet with grouping, as logging individual ProcessAccess events can generate excessive logs:
    <ProcessAccess onmatch="include">
        <Rule groupRelation="and">
        <TargetImage condition="end with">\MsMpEng.exe</TargetImage>
        <SourceImage condition="end with">\WerFaultSecure.exe</SourceImage>
        </Rule>
    </ProcessAccess>
detection:
  selection:
    SourceImage|endswith: \WerFaultSecure.exe
    TargetImage|endswith: \MsMpEng.exe
    CallTrace|contains:
      - \dbgcore.dll
      - \dbghelp.dll
  condition: selection
falsepositives:
  - Legitimate Windows Error Reporting operations
level: high
regression_tests_path: regression_data/rules/windows/process_access/proc_access_win_werfaultsecure_msmpeng_access/info.yml
license: DRL-1.1

What it detects

This rule flags Windows process access events where WerFaultSecure.exe accesses MsMpEng.exe and the call trace contains dbgcore.dll or dbghelp.dll. Such behavior matters because it can indicate debugging or dump-related activity used to impair or disrupt defensive monitoring. The detection relies on Sysmon ProcessAccess telemetry with call trace data being present for the access event.

Known false positives

  • Legitimate Windows Error Reporting operations

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.