Windows Process Creation: Exchange Server Artifact Discovery and File Staging Patterns
Alerts on Exchange-focused suspicious Windows command-line activity involving dumping, temp file creation, and compression utilities.
- Product
- windows
- Category
- process_creation
- Author
- Florian Roth (Nextron Systems) (SigmaHQ), DRL 1.1
- Published
- 2021-03-09
- Updated
- 2026-07-31
ATT&CK techniques
Execution → Priv EscRecon
Resource Dev
Initial Access
Execution
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule flags Windows process creation events whose command lines and executable paths match a set of behaviors commonly used to stage and collect data on Exchange server hosts. It looks for combinations indicating attribute changes to web-accessible script content, scheduled task usage via VSPerfMon, creation of shadow-copy listings, and compression/minidump techniques (including makecab and comsvcs DLL minidumps). Telemetry relies on process creation details such as Image, ParentImage, and full CommandLine, including path fragments like inetpub\wwwroot and compression/minidump parameters.
Reporting behind it
- blog.truesec.comhttps://blog.truesec.com/2021/03/07/exchange-zero-day-proxylogon-and-hafnium/
- microsoft.comhttps://www.microsoft.com/security/blog/2021/03/02/hafnium-targeting-exchange-servers/
- discuss.elastic.cohttps://discuss.elastic.co/t/detection-and-response-for-hafnium-activity/266289/3
- twitter.comhttps://twitter.com/GadixCRK/status/1369313704869834753?s=20
- twitter.comhttps://twitter.com/BleepinComputer/status/1372218235949617161
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules-emerging-threats/2021/TA/HAFNIUM/proc_creation_win_apt_hafnium.yml
Changelog
v5- v5Candidate ingested via manual entry.2026-07-31
- v4Candidate ingested via manual entry.2026-07-31
- v3Candidate ingested via manual entry.2026-07-31
- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: "Windows Process Creation: Exchange Server Artifact Discovery and File Staging Patterns"
id: fe4f05ff-14a7-4d06-a1b5-7f5d7cd28e5e
status: test
description: This rule flags Windows process creation events whose command lines and executable paths match a set of behaviors commonly used to stage and collect data on Exchange server hosts. It looks for combinations indicating attribute changes to web-accessible script content, scheduled task usage via VSPerfMon, creation of shadow-copy listings, and compression/minidump techniques (including makecab and comsvcs DLL minidumps). Telemetry relies on process creation details such as Image, ParentImage, and full CommandLine, including path fragments like inetpub\wwwroot and compression/minidump parameters.
references:
- https://blog.truesec.com/2021/03/07/exchange-zero-day-proxylogon-and-hafnium/
- https://www.microsoft.com/security/blog/2021/03/02/hafnium-targeting-exchange-servers/
- https://discuss.elastic.co/t/detection-and-response-for-hafnium-activity/266289/3
- https://twitter.com/GadixCRK/status/1369313704869834753?s=20
- https://twitter.com/BleepinComputer/status/1372218235949617161
- https://github.com/SigmaHQ/sigma/blob/master/rules-emerging-threats/2021/TA/HAFNIUM/proc_creation_win_apt_hafnium.yml
author: Florian Roth (Nextron Systems), Huntrule Team
date: 2021-03-09
modified: 2023-03-09
tags:
- attack.privilege-escalation
- attack.execution
- attack.persistence
- attack.t1546
- attack.t1053
- attack.g0125
- detection.emerging-threats
logsource:
category: process_creation
product: windows
detection:
selection_attrib:
CommandLine|contains|all:
- attrib
- " +h "
- " +s "
- " +r "
- .aspx
selection_vsperfmon:
- Image|contains: \ProgramData\VSPerfMon\
- CommandLine|contains|all:
- schtasks
- VSPerfMon
selection_opera_1:
Image|endswith: Opera_browser.exe
ParentImage|endswith:
- \services.exe
- \svchost.exe
selection_opera_2:
Image|endswith: Users\Public\opera\Opera_browser.exe
selection_vssadmin:
CommandLine|contains|all:
- vssadmin list shadows
- Temp\__output
selection_makecab_1:
Image|endswith: \makecab.exe
CommandLine|contains|all:
- inetpub\wwwroot\
- .dmp.zip
selection_makecab_2:
Image|endswith: \makecab.exe
CommandLine|contains:
- Microsoft\Exchange Server\
- compressionmemory
- .gif
selection_7zip:
CommandLine|contains|all:
- " -t7z "
- C:\Programdata\pst
- \it.zip
selection_rundll32:
CommandLine|contains|all:
- \comsvcs.dll
- Minidump
- "full "
- \inetpub\wwwroot
selection_other:
CommandLine|contains:
- Windows\Temp\xx.bat
- Windows\WwanSvcdcs
- Windows\Temp\cw.exe
condition: 1 of selection*
falsepositives:
- Unlikely
level: critical
license: DRL-1.1
related:
- id: bbb2dedd-a0e3-46ab-ba6c-6c82ae7a9aa7
type: derived