Windows Process Creation: Exchange Server Artifact Discovery and File Staging Patterns

Alerts on Exchange-focused suspicious Windows command-line activity involving dumping, temp file creation, and compression utilities.

FreeReviewedSigma · Critical · v5
Product
windows
Category
process_creation
Author
Florian Roth (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2021-03-09
Updated
2026-07-31

ATT&CK techniques

Execution → Priv Esc
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Defense Evasion

  5. Cred Access

  6. Discovery

  7. Lateral Movement

  8. Collection

  9. C2

  10. Exfiltration

  11. Impact

What it detects

This rule flags Windows process creation events whose command lines and executable paths match a set of behaviors commonly used to stage and collect data on Exchange server hosts. It looks for combinations indicating attribute changes to web-accessible script content, scheduled task usage via VSPerfMon, creation of shadow-copy listings, and compression/minidump techniques (including makecab and comsvcs DLL minidumps). Telemetry relies on process creation details such as Image, ParentImage, and full CommandLine, including path fragments like inetpub\wwwroot and compression/minidump parameters.

Related detections9 linkedT1546 — drag to rearrange
Malicious Axios npm Compromise Windows Payload Artifacts wt.exe and 6202033 (via process_creation)
AdminSDHolder Permissions Changed for Persistence (via security)
Suspicious Persistence via Shell Script Dropped in profile.d Directory (via file_event)
Suspicious Command Processor AutoRun Persistence via Registry Set
Suspicious Python Site Hook or PTH File Written to Site-Packages via File Event
Suspicious MOTD Or Git Hook Script Creation For Linux Persistence
Windows: Suspicious Outlook VbaProject.OTM Macro File Created
Windows MSSQL: Extended Stored Procedure execution with provider name MSSQLSERVER and message containing 'maggie'
Windows: SharPersist Execution via Process Image and Scheduled Task/Startup/Registry/Service Command Lines
Windows Process Creation: Exchange Server Artifact Discovery and File Staging Patterns
Pivot detection · T1546 · 9 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.