Windows Process Creation: AsperaFaspex Parent Spawning PowerShell or Credential-Access Tooling

Detects AsperaFaspex (aspera\ruby parent) spawning suspicious PowerShell, LSASS, web download, privilege, or defensive-evasion commands on Windows.

FreeReviewedSigma · Critical · v5
Product
windows
Category
process_creation
Author
Nasreddine Bencherchali (Nextron Systems), MSTIC (idea) (SigmaHQ), DRL 1.1
Published
2023-04-20
Updated
2026-07-31

What it detects

This rule flags Windows process creation where the parent process path contains "aspera" and "\ruby" and the resulting child activity matches common attacker tradecraft. It looks for suspicious PowerShell/PowerShell ISE usage, including command execution patterns, download/execute indicators, and reconnaissance. It also detects child processes and command lines associated with LSASS access and other defensive-evasion or credential-handling actions based on command-line content and executable names.

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.