Windows Process Creation: Exchange Server Artifact Discovery and File Staging Patterns

Alerts on Exchange-focused suspicious Windows command-line activity involving dumping, temp file creation, and compression utilities.

FreeReviewedSigma · Critical · v5
Product
windows
Category
process_creation
Author
Florian Roth (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2021-03-09
Updated
2026-07-31
title: "Windows Process Creation: Exchange Server Artifact Discovery and File Staging Patterns"
id: fe4f05ff-14a7-4d06-a1b5-7f5d7cd28e5e
status: test
description: This rule flags Windows process creation events whose command lines and executable paths match a set of behaviors commonly used to stage and collect data on Exchange server hosts. It looks for combinations indicating attribute changes to web-accessible script content, scheduled task usage via VSPerfMon, creation of shadow-copy listings, and compression/minidump techniques (including makecab and comsvcs DLL minidumps). Telemetry relies on process creation details such as Image, ParentImage, and full CommandLine, including path fragments like inetpub\wwwroot and compression/minidump parameters.
references:
  - https://blog.truesec.com/2021/03/07/exchange-zero-day-proxylogon-and-hafnium/
  - https://www.microsoft.com/security/blog/2021/03/02/hafnium-targeting-exchange-servers/
  - https://discuss.elastic.co/t/detection-and-response-for-hafnium-activity/266289/3
  - https://twitter.com/GadixCRK/status/1369313704869834753?s=20
  - https://twitter.com/BleepinComputer/status/1372218235949617161
  - https://github.com/SigmaHQ/sigma/blob/master/rules-emerging-threats/2021/TA/HAFNIUM/proc_creation_win_apt_hafnium.yml
author: Florian Roth (Nextron Systems), Huntrule Team
date: 2021-03-09
modified: 2023-03-09
tags:
  - attack.privilege-escalation
  - attack.execution
  - attack.persistence
  - attack.t1546
  - attack.t1053
  - attack.g0125
  - detection.emerging-threats
logsource:
  category: process_creation
  product: windows
detection:
  selection_attrib:
    CommandLine|contains|all:
      - attrib
      - " +h "
      - " +s "
      - " +r "
      - .aspx
  selection_vsperfmon:
    - Image|contains: \ProgramData\VSPerfMon\
    - CommandLine|contains|all:
        - schtasks
        - VSPerfMon
  selection_opera_1:
    Image|endswith: Opera_browser.exe
    ParentImage|endswith:
      - \services.exe
      - \svchost.exe
  selection_opera_2:
    Image|endswith: Users\Public\opera\Opera_browser.exe
  selection_vssadmin:
    CommandLine|contains|all:
      - vssadmin list shadows
      - Temp\__output
  selection_makecab_1:
    Image|endswith: \makecab.exe
    CommandLine|contains|all:
      - inetpub\wwwroot\
      - .dmp.zip
  selection_makecab_2:
    Image|endswith: \makecab.exe
    CommandLine|contains:
      - Microsoft\Exchange Server\
      - compressionmemory
      - .gif
  selection_7zip:
    CommandLine|contains|all:
      - " -t7z "
      - C:\Programdata\pst
      - \it.zip
  selection_rundll32:
    CommandLine|contains|all:
      - \comsvcs.dll
      - Minidump
      - "full "
      - \inetpub\wwwroot
  selection_other:
    CommandLine|contains:
      - Windows\Temp\xx.bat
      - Windows\WwanSvcdcs
      - Windows\Temp\cw.exe
  condition: 1 of selection*
falsepositives:
  - Unlikely
level: critical
license: DRL-1.1
related:
  - id: bbb2dedd-a0e3-46ab-ba6c-6c82ae7a9aa7
    type: derived