Windows Process Creation: Flag Renamed Execution of Common LOLBins Based on OriginalFileName

Alerts when a renamed process executes and Sysmon OriginalFileName matches common Windows LOLBins, suggesting defense-evasion rename behavior.

FreeUnreviewedSigmahighv1
title: "Windows Process Creation: Flag Renamed Execution of Common LOLBins Based on OriginalFileName"
id: 1d1598df-8e5d-4187-b877-c7e0d8163e59
related:
  - id: 36480ae1-a1cb-4eaa-a0d6-29801d7e9142
    type: similar
  - id: 2569ed8c-1147-498a-9b8c-2ad3656b10ed
    type: derived
  - id: a7a7e0e5-1d57-49df-9c58-9fe5bc0346a2
    type: obsolete
  - id: d178a2d7-129a-4ba4-8ee6-d6e1fecd5d20
    type: obsolete
  - id: d4d2574f-ac17-4d9e-b986-aeeae0dc8fe2
    type: obsolete
  - id: 0ba1da6d-b6ce-4366-828c-18826c9de23e
    type: derived
status: test
description: This rule flags process creations where the executed binary name differs from the expected path/filename, while the Sysmon OriginalFileName indicates execution of highly relevant Windows binaries and scripts. Attackers and malware may rename binaries to reduce detection and hinder investigation while still using familiar execution capabilities. The detection relies on Windows process creation telemetry with Sysmon fields, specifically matching a set of OriginalFileName values and correlating them with the process Image ending to exclude known benign rename patterns.
references:
  - https://mgreen27.github.io/posts/2019/05/12/BinaryRename.html
  - https://mgreen27.github.io/posts/2019/05/29/BinaryRename2.html
  - https://www.trendmicro.com/vinfo/hk-en/security/news/cybercrime-and-digital-threats/megacortex-ransomware-spotted-attacking-enterprise-networks
  - https://twitter.com/christophetd/status/1164506034720952320
  - https://threatresearch.ext.hp.com/svcready-a-new-loader-reveals-itself/
  - https://www.huntress.com/blog/malicious-browser-extention-crashfix-kongtuke
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_renamed_binary_highly_relevant.yml
author: Matthew Green - @mgreen27, Florian Roth (Nextron Systems), frack113, Huntrule Team
date: 2019-06-15
modified: 2026-06-29
tags:
  - attack.stealth
  - attack.t1036.003
  - car.2013-05-009
logsource:
  category: process_creation
  product: windows
detection:
  selection:
    - Description: Execute processes remotely
    - Product: Sysinternals PsExec
    - Description|startswith:
        - Windows PowerShell
        - pwsh
    - OriginalFileName:
        - certutil.exe
        - cmstp.exe
        - cscript.exe
        - IE4UINIT.EXE
        - finger.exe
        - mshta.exe
        - msiexec.exe
        - msxsl.exe
        - powershell_ise.exe
        - powershell.exe
        - psexec.c
        - psexec.exe
        - psexesvc.exe
        - pwsh.dll
        - reg.exe
        - regsvr32.exe
        - rundll32.exe
        - WerMgr
        - wmic.exe
        - wscript.exe
  filter:
    Image|endswith:
      - \certutil.exe
      - \cmstp.exe
      - \cscript.exe
      - \ie4uinit.exe
      - \finger.exe
      - \mshta.exe
      - \msiexec.exe
      - \msxsl.exe
      - \powershell_ise.exe
      - \powershell.exe
      - \psexec.exe
      - \psexec64.exe
      - \psexec64a.exe
      - \PSEXESVC.exe
      - \pwsh.exe
      - \reg.exe
      - \regsvr32.exe
      - \rundll32.exe
      - \wermgr.exe
      - \wmic.exe
      - \wscript.exe
  condition: selection and not filter
falsepositives:
  - Custom applications use renamed binaries adding slight change to binary name. Typically this is easy to spot and add to whitelist
  - PsExec installed via Windows Store doesn't contain original filename field (False negative)
level: high
regression_tests_path: regression_data/rules/windows/process_creation/proc_creation_win_renamed_binary_highly_relevant/info.yml
license: DRL-1.1

What it detects

This rule flags process creations where the executed binary name differs from the expected path/filename, while the Sysmon OriginalFileName indicates execution of highly relevant Windows binaries and scripts. Attackers and malware may rename binaries to reduce detection and hinder investigation while still using familiar execution capabilities. The detection relies on Windows process creation telemetry with Sysmon fields, specifically matching a set of OriginalFileName values and correlating them with the process Image ending to exclude known benign rename patterns.

Known false positives

  • Custom applications use renamed binaries adding slight change to binary name. Typically this is easy to spot and add to whitelist
  • PsExec installed via Windows Store doesn't contain original filename field (False negative)

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.