Windows Process Creation Alerts for Suspicious Lazarus-Linked Command-Line Execution

Alerts on Windows process executions with command-line substrings consistent with behaviors described in Lazarus activity reports.

FreeReviewedSigma · Critical · v5
Product
windows
Category
process_creation
Author
Florian Roth (Nextron Systems), wagga (SigmaHQ), DRL 1.1
Published
2020-12-23
Updated
2026-07-31
title: Windows Process Creation Alerts for Suspicious Lazarus-Linked Command-Line Execution
id: bd430b38-0e10-431f-810d-9765e5c0e01a
related:
  - id: 7b49c990-4a9a-4e65-ba95-47c9cc448f6e
    type: obsolete
  - id: 24c4d154-05a4-4b99-b57d-9b977472443a
    type: derived
status: test
description: This rule flags Windows process creation events whose command lines contain one of several specific patterns used for registry dumping, netstat output redirection, network share discovery, persistence-related execution, and rundll32-based DLL/file loading. Such command-line-driven behaviors can indicate attacker staging and collection activity, where execution often blends into normal Windows tooling. Detection relies on process creation telemetry with the full CommandLine field to match the listed string patterns.
references:
  - https://securelist.com/lazarus-covets-covid-19-related-intelligence/99906/
  - https://www.hvs-consulting.de/lazarus-report/
  - https://github.com/SigmaHQ/sigma/blob/master/rules-emerging-threats/2020/TA/Lazarus/proc_creation_win_apt_lazarus_group_activity.yml
author: Florian Roth (Nextron Systems), wagga, Huntrule Team
date: 2020-12-23
modified: 2023-03-10
tags:
  - attack.g0032
  - attack.execution
  - attack.t1059
  - detection.emerging-threats
logsource:
  category: process_creation
  product: windows
detection:
  selection_generic:
    CommandLine|contains:
      - reg.exe save hklm\sam %temp%\~reg_sam.save
      - 1q2w3e4r@#$@#$@#$
      - " -hp1q2w3e4 "
      - ".dat data03 10000 -p "
  selection_netstat:
    CommandLine|contains|all:
      - "netstat -aon | find "
      - ESTA
      - " > %temp%\\~"
  selection_network_discovery:
    CommandLine|contains|all:
      - .255 10 C:\ProgramData\IBM\
      - .DAT
  selection_persistence:
    CommandLine|contains|all:
      - " /c "
      - " -p 0x"
    CommandLine|contains:
      - C:\ProgramData\
      - C:\RECYCLER\
  selection_rundll32:
    CommandLine|contains|all:
      - "rundll32 "
      - C:\ProgramData\
    CommandLine|contains:
      - .bin,
      - .tmp,
      - .dat,
      - .io,
      - .ini,
      - .db,
  condition: 1 of selection_*
falsepositives:
  - Unlikely
level: critical
license: DRL-1.1