Windows Process Creation: Remote Utilities renamed to rutserv.exe or rfusclient.exe

Alerts on suspicious Windows execution tied to "Remote Utilities" where the image does not match known rutserv.exe/rfusclient.exe names.

FreeReviewedSigma · Medium · v1
Product
windows
Category
process_creation
Author
Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2022-09-19
Updated
2026-07-30

What it detects

This rule flags Windows process executions where the process metadata indicates the Product as "Remote Utilities" but the executable path is not one of the known Remote Utilities client binary filenames. Renaming legitimate-looking binaries is a common attacker technique to evade allowlists and make malicious activity blend in with expected software artifacts. The detection relies on process creation telemetry, specifically the Product field and the image path ending in \rutserv.exe or \rfusclient.exe.

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.