Windows Process Command Lines Using System32/SysWow64 Tasks Folder
Alerts on process command lines referencing the writable System32/SysWow64 Tasks folders with common file staging/copy primitives.
FreeUnreviewedSigmahighv1
windows-process-command-lines-using-system32-syswow64-tasks-folder-cc4e02ba
title: Windows Process Command Lines Using System32/SysWow64 Tasks Folder
id: 2482a3d5-169a-488b-8a8b-8bdb23cd3417
status: test
description: This rule flags Windows process creation events where the command line references the globally writable Tasks directories in C:\Windows\System32\Tasks\ or C:\Windows\SysWow64\Tasks\ and also includes command-line actions commonly used for file creation or copying (e.g., echo, copy, type, file createnew). Such activity matters because attackers may use writable task-related paths to stage or influence scripts and executables that later get run by common Windows script or component utilities. The detection relies on process creation telemetry and command-line content matching those specific directory and command substrings.
references:
- https://twitter.com/subTee/status/1216465628946563073
- https://gist.github.com/am0nsec/8378da08f848424e4ab0cc5b317fdd26
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_susp_task_folder_evasion.yml
author: Sreeman, Huntrule Team
date: 2020-01-13
modified: 2022-12-25
tags:
- attack.privilege-escalation
- attack.persistence
- attack.execution
- attack.stealth
- attack.t1574.001
logsource:
product: windows
category: process_creation
detection:
selection1:
CommandLine|contains:
- "echo "
- "copy "
- "type "
- file createnew
selection2:
CommandLine|contains:
- " C:\\Windows\\System32\\Tasks\\"
- " C:\\Windows\\SysWow64\\Tasks\\"
condition: all of selection*
falsepositives:
- Unknown
level: high
license: DRL-1.1
related:
- id: cc4e02ba-9c06-48e2-b09e-2500cace9ae0
type: derived
What it detects
This rule flags Windows process creation events where the command line references the globally writable Tasks directories in C:\Windows\System32\Tasks\ or C:\Windows\SysWow64\Tasks\ and also includes command-line actions commonly used for file creation or copying (e.g., echo, copy, type, file createnew). Such activity matters because attackers may use writable task-related paths to stage or influence scripts and executables that later get run by common Windows script or component utilities. The detection relies on process creation telemetry and command-line content matching those specific directory and command substrings.
Known false positives
- Unknown
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.