Windows Process Creation: AsperaFaspex Parent Spawning PowerShell or Credential-Access Tooling
Detects AsperaFaspex (aspera\ruby parent) spawning suspicious PowerShell, LSASS, web download, privilege, or defensive-evasion commands on Windows.
- Product
- windows
- Category
- process_creation
- Author
- Nasreddine Bencherchali (Nextron Systems), MSTIC (idea) (SigmaHQ), DRL 1.1
- Published
- 2023-04-20
- Updated
- 2026-07-31
What it detects
This rule flags Windows process creation where the parent process path contains "aspera" and "\ruby" and the resulting child activity matches common attacker tradecraft. It looks for suspicious PowerShell/PowerShell ISE usage, including command execution patterns, download/execute indicators, and reconnaissance. It also detects child processes and command lines associated with LSASS access and other defensive-evasion or credential-handling actions based on command-line content and executable names.
Reporting behind it
- microsoft.comhttps://www.microsoft.com/en-us/security/blog/2023/04/18/nation-state-threat-actor-mint-sandstorm-refines-tradecraft-to-attack-high-value-targets/
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules-emerging-threats/2023/TA/Mint-Sandstorm/proc_creation_win_apt_mint_sandstorm_aspera_faspex_susp_child_process.yml
Changelog
v5- v5Candidate ingested via manual entry.2026-07-31
- v4Candidate ingested via manual entry.2026-07-31
- v3Candidate ingested via manual entry.2026-07-31
- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: "Windows Process Creation: AsperaFaspex Parent Spawning PowerShell or Credential-Access Tooling"
id: 1bbd34be-63c1-403a-8c45-76aef98ae112
status: test
description: This rule flags Windows process creation where the parent process path contains "aspera" and "\ruby" and the resulting child activity matches common attacker tradecraft. It looks for suspicious PowerShell/PowerShell ISE usage, including command execution patterns, download/execute indicators, and reconnaissance. It also detects child processes and command lines associated with LSASS access and other defensive-evasion or credential-handling actions based on command-line content and executable names.
references:
- https://www.microsoft.com/en-us/security/blog/2023/04/18/nation-state-threat-actor-mint-sandstorm-refines-tradecraft-to-attack-high-value-targets/
- https://github.com/SigmaHQ/sigma/blob/master/rules-emerging-threats/2023/TA/Mint-Sandstorm/proc_creation_win_apt_mint_sandstorm_aspera_faspex_susp_child_process.yml
author: Nasreddine Bencherchali (Nextron Systems), MSTIC (idea), Huntrule Team
date: 2023-04-20
modified: 2025-10-19
tags:
- attack.execution
- detection.emerging-threats
logsource:
category: process_creation
product: windows
detection:
selection_parent:
ParentImage|contains|all:
- aspera
- \ruby
selection_special_child_powershell_img:
Image|endswith:
- \powershell.exe
- \powershell_ise.exe
selection_special_child_powershell_cli:
- CommandLine|contains:
- " echo "
- -dumpmode
- -ssh
- .dmp
- add-MpPreference
- adscredentials
- bitsadmin
- certutil
- csvhost.exe
- DownloadFile
- DownloadString
- dsquery
- ekern.exe
- FromBase64String
- "iex "
- iex(
- Invoke-Expression
- Invoke-WebRequest
- localgroup administrators
- o365accountconfiguration
- samaccountname=
- set-MpPreference
- svhost.exe
- System.IO.Compression
- System.IO.MemoryStream
- usoprivate
- usoshared
- whoami
- CommandLine|re:
- "[-/–][Ee^]{1,2}[ncodema^]*\\s[A-Za-z0-9+/=]{15,}"
- net\s+user
- net\s+group
- query\s+session
selection_special_child_lsass_1:
CommandLine|contains: lsass
selection_special_child_lsass_2:
CommandLine|contains:
- procdump
- tasklist
- findstr
selection_child_wget:
Image|endswith: \wget.exe
CommandLine|contains: http
selection_child_curl:
Image|endswith: \curl.exe
CommandLine|contains: http
selection_child_script:
CommandLine|contains:
- E:jscript
- e:vbscript
selection_child_localgroup:
CommandLine|contains|all:
- localgroup Administrators
- /add
selection_child_net:
CommandLine|contains: net
CommandLine|contains|all:
- user
- /add
selection_child_reg:
- CommandLine|contains|all:
- reg add
- DisableAntiSpyware
- \Microsoft\Windows Defender
- CommandLine|contains|all:
- reg add
- DisableRestrictedAdmin
- CurrentControlSet\Control\Lsa
selection_child_wmic_1:
CommandLine|contains|all:
- wmic
- process call create
selection_child_wmic_2:
CommandLine|contains|all:
- wmic
- delete
- shadowcopy
selection_child_vssadmin:
CommandLine|contains|all:
- vssadmin
- delete
- shadows
selection_child_wbadmin:
CommandLine|contains|all:
- wbadmin
- delete
- catalog
condition: selection_parent and (all of selection_special_child_powershell_* or all of selection_special_child_lsass_* or 1 of selection_child_*)
falsepositives:
- Unlikely
level: critical
license: DRL-1.1
related:
- id: 91048c0d-5b81-4b85-a099-c9ee4fb87979
type: derived