Windows process creation: CrackMapExec execution via characteristic command-line flags

Alerts on Windows process creation showing CrackMapExec-style command-line flags for local auth and module execution.

FreeReviewedSigma · High · v2
Product
windows
Category
process_creation
Author
Florian Roth (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2022-02-25
Updated
2026-07-31

ATT&CK techniques

Execution → Discovery
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Defense Evasion

  5. Cred Access

  6. Lateral Movement

  7. Collection

  8. C2

  9. Exfiltration

  10. Impact

What it detects

This rule flags Windows process creation events where the executable name ends with "\crackmapexec.exe" and the command line contains characteristic flag combinations, including module usage and local-auth options. The behavior matters because CrackMapExec is often used for credential checking and remote management activities, and attackers may replace the binary while keeping the same operational flags. Detection relies on process creation telemetry with command-line arguments and the process image path.

Related detections9 linkedT1059.001 — drag to rearrange
Windows Process Creation: Suspicious Children Spawned by HTML Help (hh.exe)
Windows: Alert on Suspicious HH.EXE Process Execution
Malicious Shadow Copy Deletion Via WMI
Malicious Axios npm Compromise Windows Payload Artifacts wt.exe and 6202033 (via process_creation)
MSSQL Server Process Spawning Command Shell via xp_cmdshell
Suspicious MSSQL xp_cmdshell OS Command Execution via sqlservr.exe (via process_creation)
Malicious Fire Ant Host-to-Guest Command Execution via VMware Tools (via process_creation)
Malicious Office Application Spawning a Command Shell or Script Interpreter (via process_creation)
Malicious PowerShell or Command Shell Spawned by SQL Server via xp_cmdshell
Windows process creation: CrackMapExec execution via characteristic command-line flags
Pivot detection · T1059.001 · 9 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.