Windows Process Creation: Explorer Command Lines with Unicode Whitespace Padding and '#'

Alerts when Explorer spawns a process with command lines containing long Unicode whitespace padding followed by '#'.

FreeReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
Swachchhanda Shrawan Poudel (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2025-11-04
Updated
2026-07-30

ATT&CK techniques

Execution → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Persistence

  5. Priv Esc

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule flags Windows process creation events where the parent process is Explorer and the command line contains a '#' character while also including unusually long sequences of whitespace characters (including Unicode space variants). Attackers can use whitespace padding to visually obscure the meaningful portion of a command, helping conceal malicious instructions during user interaction. The detection relies on process creation telemetry with parent image context and command-line strings that preserve Unicode whitespace and punctuation.

Related detections9 linkedT1204 — drag to rearrange
Windows Registry RunMRU Path with Suspicious Space Characters and Delimiter
Windows Registry: Suspicious Space-Padded TypedPaths Details String
Malicious Edge Abuse for Payload Download via Console (via process_creation)
PowerShell Command-Line Obfuscation Constructs (via process_creation)
Obfuscated Edge/Chrome Headless Feature Abuse for Payload Download (via process_creation)
Windows Process Creation: Python One-Liners Decoding Base64 via Command Line
Linux Process Execution of Python Base64 Decode One-Liners
Windows Process Creation: File Upload Clickfix Lure via Browser to Command Execution
Windows ClickFix/FileFix Clipboard Phishing Leading to Suspicious mshta/powershell Command Execution
Windows Process Creation: Explorer Command Lines with Unicode Whitespace Padding and '#'
Pivot detection · T1204 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.