Windows Process Creation Alerts for Suspicious Lazarus-Linked Command-Line Execution
Alerts on Windows process executions with command-line substrings consistent with behaviors described in Lazarus activity reports.
- Product
- windows
- Category
- process_creation
- Author
- Florian Roth (Nextron Systems), wagga (SigmaHQ), DRL 1.1
- Published
- 2020-12-23
- Updated
- 2026-07-31
ATT&CK techniques
ExecutionRecon
Resource Dev
Initial Access
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule flags Windows process creation events whose command lines contain one of several specific patterns used for registry dumping, netstat output redirection, network share discovery, persistence-related execution, and rundll32-based DLL/file loading. Such command-line-driven behaviors can indicate attacker staging and collection activity, where execution often blends into normal Windows tooling. Detection relies on process creation telemetry with the full CommandLine field to match the listed string patterns.
Reporting behind it
Changelog
v5- v5Candidate ingested via manual entry.2026-07-31
- v4Candidate ingested via manual entry.2026-07-31
- v3Candidate ingested via manual entry.2026-07-31
- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: Windows Process Creation Alerts for Suspicious Lazarus-Linked Command-Line Execution
id: bd430b38-0e10-431f-810d-9765e5c0e01a
related:
- id: 7b49c990-4a9a-4e65-ba95-47c9cc448f6e
type: obsolete
- id: 24c4d154-05a4-4b99-b57d-9b977472443a
type: derived
status: test
description: This rule flags Windows process creation events whose command lines contain one of several specific patterns used for registry dumping, netstat output redirection, network share discovery, persistence-related execution, and rundll32-based DLL/file loading. Such command-line-driven behaviors can indicate attacker staging and collection activity, where execution often blends into normal Windows tooling. Detection relies on process creation telemetry with the full CommandLine field to match the listed string patterns.
references:
- https://securelist.com/lazarus-covets-covid-19-related-intelligence/99906/
- https://www.hvs-consulting.de/lazarus-report/
- https://github.com/SigmaHQ/sigma/blob/master/rules-emerging-threats/2020/TA/Lazarus/proc_creation_win_apt_lazarus_group_activity.yml
author: Florian Roth (Nextron Systems), wagga, Huntrule Team
date: 2020-12-23
modified: 2023-03-10
tags:
- attack.g0032
- attack.execution
- attack.t1059
- detection.emerging-threats
logsource:
category: process_creation
product: windows
detection:
selection_generic:
CommandLine|contains:
- reg.exe save hklm\sam %temp%\~reg_sam.save
- 1q2w3e4r@#$@#$@#$
- " -hp1q2w3e4 "
- ".dat data03 10000 -p "
selection_netstat:
CommandLine|contains|all:
- "netstat -aon | find "
- ESTA
- " > %temp%\\~"
selection_network_discovery:
CommandLine|contains|all:
- .255 10 C:\ProgramData\IBM\
- .DAT
selection_persistence:
CommandLine|contains|all:
- " /c "
- " -p 0x"
CommandLine|contains:
- C:\ProgramData\
- C:\RECYCLER\
selection_rundll32:
CommandLine|contains|all:
- "rundll32 "
- C:\ProgramData\
CommandLine|contains:
- .bin,
- .tmp,
- .dat,
- .io,
- .ini,
- .db,
condition: 1 of selection_*
falsepositives:
- Unlikely
level: critical
license: DRL-1.1