Windows Process Creation: Mouse Lock Execution with “Misc314” Indicator

Alerts on Windows executions of Mouse Lock where Company includes “Misc314” and CommandLine contains “Mouse Lock_”.

FreeReviewedSigma · Medium · v1
Product
windows
Category
process_creation
Author
Cian Heasley (SigmaHQ), DRL 1.1
Published
2020-08-13
Updated
2026-07-30

ATT&CK techniques

Cred Access → Collection
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Discovery

  9. Lateral Movement

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule flags Windows process creation events where the process metadata contains the “Mouse Lock” product name and the command line includes the “Mouse Lock_” pattern, along with a “Misc314” company indicator. Attackers may use legitimate tooling repackaged or invoked in automated ways to support credential access and data collection objectives. The detection relies on process-creation telemetry fields for Product, Company, and CommandLine substring matches.

Related detections2 linkedT1056.002 — drag to rearrange
Windows DLL image load: credui.dll loaded by an uncommon process
macOS GUI Credential Prompt Capture via osascript
Windows Process Creation: Mouse Lock Execution with “Misc314” Indicator
Pivot detection · T1056.002 · 2 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.