Windows Process Creation: Suspicious Child Process Spawned by Wermgr.EXE
Alerts on suspicious children spawned by wermgr.exe using common execution utilities, with a rundll32 WerConCpl exclusion.
- Product
- windows
- Category
- process_creation
- Author
- Florian Roth (Nextron Systems) (SigmaHQ), DRL 1.1
- Published
- 2022-10-14
- Updated
- 2026-07-30
ATT&CK techniques
Priv Esc → Defense EvasionRecon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule flags Windows process creation events where the parent process is wermgr.exe and the child process image is one of several common command or script execution binaries (e.g., cmd.exe, PowerShell, mshta, regsvr32, rundll32, net utilities, systeminfo, whoami). An attacker can abuse Windows Error Reporting to launch secondary commands, enabling stealthy execution and follow-on actions. Telemetry relies on process creation fields for ParentImage, Image, and (when applicable) CommandLine to match the specific child and to exclude a known rundll32-related WerConCpl launcher pattern.
Reporting behind it
- trendmicro.comhttps://www.trendmicro.com/en_us/research/22/j/black-basta-infiltrates-networks-via-qakbot-brute-ratel-and-coba.html
- echotrail.iohttps://www.echotrail.io/insights/search/wermgr.exe
- github.comhttps://github.com/binderlabs/DirCreate2System
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_wermgr_susp_child_process.yml
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: "Windows Process Creation: Suspicious Child Process Spawned by Wermgr.EXE"
id: 078e33db-8811-4e3f-8850-519bbcd5513c
related:
- id: 5394fcc7-aeb2-43b5-9a09-cac9fc5edcd5
type: similar
- id: 396f6630-f3ac-44e3-bfc8-1b161bc00c4e
type: derived
status: test
description: This rule flags Windows process creation events where the parent process is wermgr.exe and the child process image is one of several common command or script execution binaries (e.g., cmd.exe, PowerShell, mshta, regsvr32, rundll32, net utilities, systeminfo, whoami). An attacker can abuse Windows Error Reporting to launch secondary commands, enabling stealthy execution and follow-on actions. Telemetry relies on process creation fields for ParentImage, Image, and (when applicable) CommandLine to match the specific child and to exclude a known rundll32-related WerConCpl launcher pattern.
references:
- https://www.trendmicro.com/en_us/research/22/j/black-basta-infiltrates-networks-via-qakbot-brute-ratel-and-coba.html
- https://www.echotrail.io/insights/search/wermgr.exe
- https://github.com/binderlabs/DirCreate2System
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_wermgr_susp_child_process.yml
author: Florian Roth (Nextron Systems), Huntrule Team
date: 2022-10-14
modified: 2024-08-29
tags:
- attack.privilege-escalation
- attack.stealth
- attack.t1055
- attack.t1036
logsource:
category: process_creation
product: windows
detection:
selection:
ParentImage|endswith: \wermgr.exe
Image|endswith:
- \cmd.exe
- \cscript.exe
- \ipconfig.exe
- \mshta.exe
- \net.exe
- \net1.exe
- \netstat.exe
- \nslookup.exe
- \powershell_ise.exe
- \powershell.exe
- \pwsh.exe
- \regsvr32.exe
- \rundll32.exe
- \systeminfo.exe
- \whoami.exe
- \wscript.exe
filter_main_rundll32:
Image|endswith: \rundll32.exe
CommandLine|contains|all:
- C:\Windows\system32\WerConCpl.dll
- "LaunchErcApp "
CommandLine|contains:
- -queuereporting
- -responsepester
condition: selection and not 1 of filter_main_*
falsepositives:
- Unknown
level: high
license: DRL-1.1