Windows Process Creation: AsperaFaspex Parent Spawning PowerShell or Credential-Access Tooling

Detects AsperaFaspex (aspera\ruby parent) spawning suspicious PowerShell, LSASS, web download, privilege, or defensive-evasion commands on Windows.

FreeReviewedSigma · Critical · v5
Product
windows
Category
process_creation
Author
Nasreddine Bencherchali (Nextron Systems), MSTIC (idea) (SigmaHQ), DRL 1.1
Published
2023-04-20
Updated
2026-07-31
title: "Windows Process Creation: AsperaFaspex Parent Spawning PowerShell or Credential-Access Tooling"
id: 1bbd34be-63c1-403a-8c45-76aef98ae112
status: test
description: This rule flags Windows process creation where the parent process path contains "aspera" and "\ruby" and the resulting child activity matches common attacker tradecraft. It looks for suspicious PowerShell/PowerShell ISE usage, including command execution patterns, download/execute indicators, and reconnaissance. It also detects child processes and command lines associated with LSASS access and other defensive-evasion or credential-handling actions based on command-line content and executable names.
references:
  - https://www.microsoft.com/en-us/security/blog/2023/04/18/nation-state-threat-actor-mint-sandstorm-refines-tradecraft-to-attack-high-value-targets/
  - https://github.com/SigmaHQ/sigma/blob/master/rules-emerging-threats/2023/TA/Mint-Sandstorm/proc_creation_win_apt_mint_sandstorm_aspera_faspex_susp_child_process.yml
author: Nasreddine Bencherchali (Nextron Systems), MSTIC (idea), Huntrule Team
date: 2023-04-20
modified: 2025-10-19
tags:
  - attack.execution
  - detection.emerging-threats
logsource:
  category: process_creation
  product: windows
detection:
  selection_parent:
    ParentImage|contains|all:
      - aspera
      - \ruby
  selection_special_child_powershell_img:
    Image|endswith:
      - \powershell.exe
      - \powershell_ise.exe
  selection_special_child_powershell_cli:
    - CommandLine|contains:
        - " echo "
        - -dumpmode
        - -ssh
        - .dmp
        - add-MpPreference
        - adscredentials
        - bitsadmin
        - certutil
        - csvhost.exe
        - DownloadFile
        - DownloadString
        - dsquery
        - ekern.exe
        - FromBase64String
        - "iex "
        - iex(
        - Invoke-Expression
        - Invoke-WebRequest
        - localgroup administrators
        - o365accountconfiguration
        - samaccountname=
        - set-MpPreference
        - svhost.exe
        - System.IO.Compression
        - System.IO.MemoryStream
        - usoprivate
        - usoshared
        - whoami
    - CommandLine|re:
        - "[-/–][Ee^]{1,2}[ncodema^]*\\s[A-Za-z0-9+/=]{15,}"
        - net\s+user
        - net\s+group
        - query\s+session
  selection_special_child_lsass_1:
    CommandLine|contains: lsass
  selection_special_child_lsass_2:
    CommandLine|contains:
      - procdump
      - tasklist
      - findstr
  selection_child_wget:
    Image|endswith: \wget.exe
    CommandLine|contains: http
  selection_child_curl:
    Image|endswith: \curl.exe
    CommandLine|contains: http
  selection_child_script:
    CommandLine|contains:
      - E:jscript
      - e:vbscript
  selection_child_localgroup:
    CommandLine|contains|all:
      - localgroup Administrators
      - /add
  selection_child_net:
    CommandLine|contains: net
    CommandLine|contains|all:
      - user
      - /add
  selection_child_reg:
    - CommandLine|contains|all:
        - reg add
        - DisableAntiSpyware
        - \Microsoft\Windows Defender
    - CommandLine|contains|all:
        - reg add
        - DisableRestrictedAdmin
        - CurrentControlSet\Control\Lsa
  selection_child_wmic_1:
    CommandLine|contains|all:
      - wmic
      - process call create
  selection_child_wmic_2:
    CommandLine|contains|all:
      - wmic
      - delete
      - shadowcopy
  selection_child_vssadmin:
    CommandLine|contains|all:
      - vssadmin
      - delete
      - shadows
  selection_child_wbadmin:
    CommandLine|contains|all:
      - wbadmin
      - delete
      - catalog
  condition: selection_parent and (all of selection_special_child_powershell_* or all of selection_special_child_lsass_* or 1 of selection_child_*)
falsepositives:
  - Unlikely
level: critical
license: DRL-1.1
related:
  - id: 91048c0d-5b81-4b85-a099-c9ee4fb87979
    type: derived