Windows Process Creation: Flag Renamed Execution of Common LOLBins Based on OriginalFileName
Alerts when a renamed process executes and Sysmon OriginalFileName matches common Windows LOLBins, suggesting defense-evasion rename behavior.
FreeUnreviewedSigmahighv1
windows-process-creation-flag-renamed-execution-of-common-lolbins-based-on-origi-0ba1da6d
title: "Windows Process Creation: Flag Renamed Execution of Common LOLBins Based on OriginalFileName"
id: 1d1598df-8e5d-4187-b877-c7e0d8163e59
related:
- id: 36480ae1-a1cb-4eaa-a0d6-29801d7e9142
type: similar
- id: 2569ed8c-1147-498a-9b8c-2ad3656b10ed
type: derived
- id: a7a7e0e5-1d57-49df-9c58-9fe5bc0346a2
type: obsolete
- id: d178a2d7-129a-4ba4-8ee6-d6e1fecd5d20
type: obsolete
- id: d4d2574f-ac17-4d9e-b986-aeeae0dc8fe2
type: obsolete
- id: 0ba1da6d-b6ce-4366-828c-18826c9de23e
type: derived
status: test
description: This rule flags process creations where the executed binary name differs from the expected path/filename, while the Sysmon OriginalFileName indicates execution of highly relevant Windows binaries and scripts. Attackers and malware may rename binaries to reduce detection and hinder investigation while still using familiar execution capabilities. The detection relies on Windows process creation telemetry with Sysmon fields, specifically matching a set of OriginalFileName values and correlating them with the process Image ending to exclude known benign rename patterns.
references:
- https://mgreen27.github.io/posts/2019/05/12/BinaryRename.html
- https://mgreen27.github.io/posts/2019/05/29/BinaryRename2.html
- https://www.trendmicro.com/vinfo/hk-en/security/news/cybercrime-and-digital-threats/megacortex-ransomware-spotted-attacking-enterprise-networks
- https://twitter.com/christophetd/status/1164506034720952320
- https://threatresearch.ext.hp.com/svcready-a-new-loader-reveals-itself/
- https://www.huntress.com/blog/malicious-browser-extention-crashfix-kongtuke
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_renamed_binary_highly_relevant.yml
author: Matthew Green - @mgreen27, Florian Roth (Nextron Systems), frack113, Huntrule Team
date: 2019-06-15
modified: 2026-06-29
tags:
- attack.stealth
- attack.t1036.003
- car.2013-05-009
logsource:
category: process_creation
product: windows
detection:
selection:
- Description: Execute processes remotely
- Product: Sysinternals PsExec
- Description|startswith:
- Windows PowerShell
- pwsh
- OriginalFileName:
- certutil.exe
- cmstp.exe
- cscript.exe
- IE4UINIT.EXE
- finger.exe
- mshta.exe
- msiexec.exe
- msxsl.exe
- powershell_ise.exe
- powershell.exe
- psexec.c
- psexec.exe
- psexesvc.exe
- pwsh.dll
- reg.exe
- regsvr32.exe
- rundll32.exe
- WerMgr
- wmic.exe
- wscript.exe
filter:
Image|endswith:
- \certutil.exe
- \cmstp.exe
- \cscript.exe
- \ie4uinit.exe
- \finger.exe
- \mshta.exe
- \msiexec.exe
- \msxsl.exe
- \powershell_ise.exe
- \powershell.exe
- \psexec.exe
- \psexec64.exe
- \psexec64a.exe
- \PSEXESVC.exe
- \pwsh.exe
- \reg.exe
- \regsvr32.exe
- \rundll32.exe
- \wermgr.exe
- \wmic.exe
- \wscript.exe
condition: selection and not filter
falsepositives:
- Custom applications use renamed binaries adding slight change to binary name. Typically this is easy to spot and add to whitelist
- PsExec installed via Windows Store doesn't contain original filename field (False negative)
level: high
regression_tests_path: regression_data/rules/windows/process_creation/proc_creation_win_renamed_binary_highly_relevant/info.yml
license: DRL-1.1
What it detects
This rule flags process creations where the executed binary name differs from the expected path/filename, while the Sysmon OriginalFileName indicates execution of highly relevant Windows binaries and scripts. Attackers and malware may rename binaries to reduce detection and hinder investigation while still using familiar execution capabilities. The detection relies on Windows process creation telemetry with Sysmon fields, specifically matching a set of OriginalFileName values and correlating them with the process Image ending to exclude known benign rename patterns.
Known false positives
- Custom applications use renamed binaries adding slight change to binary name. Typically this is easy to spot and add to whitelist
- PsExec installed via Windows Store doesn't contain original filename field (False negative)
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.