Windows Process Creation: DumpStack.log Used to Evade Microsoft Defender

Alerts on Windows processes launched with DumpStack.log in the image name and command-line output argument.

FreeReviewedSigma · Critical · v1
Product
windows
Category
process_creation
Author
Florian Roth (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2022-01-06
Updated
2026-07-30

What it detects

This rule flags Windows process executions where the launched image filename ends with DumpStack.log and where the command line includes the argument ' -o DumpStack.log'. Attackers may use this filename to evade Microsoft Defender behavior during execution. The detection relies on process creation telemetry, specifically the process image path and the full command line.

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.