Windows Process Creation: Suspicious Child Process Spawned by Wermgr.EXE

Alerts on suspicious children spawned by wermgr.exe using common execution utilities, with a rundll32 WerConCpl exclusion.

FreeReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
Florian Roth (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2022-10-14
Updated
2026-07-30

ATT&CK techniques

Priv Esc → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule flags Windows process creation events where the parent process is wermgr.exe and the child process image is one of several common command or script execution binaries (e.g., cmd.exe, PowerShell, mshta, regsvr32, rundll32, net utilities, systeminfo, whoami). An attacker can abuse Windows Error Reporting to launch secondary commands, enabling stealthy execution and follow-on actions. Telemetry relies on process creation fields for ParentImage, Image, and (when applicable) CommandLine to match the specific child and to exclude a known rundll32-related WerConCpl launcher pattern.

Related detections9 linkedT1055 — drag to rearrange
Suspicious Rclone Exfiltration Masquerading as wininit.exe
Suspicious Executable Running from Public Pictures Directory
Suspicious Python Execution via Renamed Synaptics Binary
Suspicious Office Application Spawning Script Or Shell Interpreter
Suspicious Network Connection From wabmig.exe (Turian Injection)
Suspicious Outbound Network Connection from Explorer Process
Suspicious AppLaunch.exe Spawned As Injection Target (via process_creation)
Suspicious BugSleep Marker File in Public Directory
Agent Tesla Persistence via Realtek Named Scheduled Task Batch
Windows Process Creation: Suspicious Child Process Spawned by Wermgr.EXE
Pivot detection · T1055 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.