Windows Process Creation: PingCastle Execution with Full Healthcheck Scanners

Alerts on Windows execution of PingCastle with full healthcheck and AD/security scanner command-line options.

FreeReviewedSigma · Medium · v1
Product
windows
Category
process_creation
Author
Nasreddine Bencherchali (Nextron Systems), frack113 (SigmaHQ), DRL 1.1
Published
2024-01-11
Updated
2026-07-30

ATT&CK techniques

Recon
  1. Resource Dev

  2. Initial Access

  3. Execution

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule flags execution of PingCastle on Windows when the process matches specific known file hashes or identifiable binary characteristics (PingCastle.exe product/original filename). It further narrows matches by requiring PingCastle command-line options that indicate a healthcheck run with full level and multiple Active Directory/security scanners. This behavior matters because recon and security assessment tooling can be used to gather domain information and validate attack paths. The rule relies on Windows process creation telemetry including file hash fields, image filename/original filename/product, and command-line arguments.

Related detections4 linkedT1595 — drag to rearrange
Suspicious CTF-Framed Vulnerability Scanner User Agent via Webserver
Suspicious Hello-World Scraper Botnet User-Agent in Web Requests
Proxy HTTP GET traffic using Hello-World/1.0 user-agent (possible scraper botnet)
Windows PingCastle Execution From Suspicious Parent Processes
Windows Process Creation: PingCastle Execution with Full Healthcheck Scanners
Pivot detection · T1595 · 4 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.