Windows Event Viewer (eventvwr.exe) Spawns Suspicious Child Processes
Alerts when eventvwr.exe spawns unusual child processes in Windows process creation logs.
- Product
- windows
- Category
- process_creation
- Author
- Florian Roth (Nextron Systems) (SigmaHQ), DRL 1.1
- Published
- 2017-03-19
- Updated
- 2026-07-31
ATT&CK techniques
Priv Esc → Defense EvasionRecon
Resource Dev
Initial Access
Execution
Persistence
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule flags Windows process creation events where eventvwr.exe is the parent of a child process, excluding a small set of common benign children (mmc.exe and WerFault.exe variants). Attackers may abuse Event Viewer execution to proxy or initiate other tools as part of privilege escalation attempts. The detection relies on process creation telemetry containing parent and child image paths so the parent can be identified as eventvwr.exe.
Reporting behind it
- enigma0x3.nethttps://enigma0x3.net/2016/08/15/fileless-uac-bypass-using-eventvwr-exe-and-registry-hijacking/
- hybrid-analysis.comhttps://www.hybrid-analysis.com/sample/e122bc8bf291f15cab182a5d2d27b8db1e7019e4e96bb5cdbd1dfe7446f3f51f?environmentId=100
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_eventvwr_susp_child_process.yml
Changelog
v2- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: Windows Event Viewer (eventvwr.exe) Spawns Suspicious Child Processes
id: 1e123aef-b49d-4b83-ad14-36aa39e35d8a
related:
- id: 7c81fec3-1c1d-43b0-996a-46753041b1b6
type: derived
- id: be344333-921d-4c4d-8bb8-e584cf584780
type: derived
status: test
description: This rule flags Windows process creation events where eventvwr.exe is the parent of a child process, excluding a small set of common benign children (mmc.exe and WerFault.exe variants). Attackers may abuse Event Viewer execution to proxy or initiate other tools as part of privilege escalation attempts. The detection relies on process creation telemetry containing parent and child image paths so the parent can be identified as eventvwr.exe.
references:
- https://enigma0x3.net/2016/08/15/fileless-uac-bypass-using-eventvwr-exe-and-registry-hijacking/
- https://www.hybrid-analysis.com/sample/e122bc8bf291f15cab182a5d2d27b8db1e7019e4e96bb5cdbd1dfe7446f3f51f?environmentId=100
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_eventvwr_susp_child_process.yml
author: Florian Roth (Nextron Systems), Huntrule Team
date: 2017-03-19
modified: 2023-09-28
tags:
- attack.privilege-escalation
- attack.t1548.002
- car.2019-04-001
logsource:
category: process_creation
product: windows
detection:
selection:
ParentImage|endswith: \eventvwr.exe
filter_main_generic:
Image|endswith:
- :\Windows\System32\mmc.exe
- :\Windows\System32\WerFault.exe
- :\Windows\SysWOW64\WerFault.exe
condition: selection and not 1 of filter_main_*
falsepositives:
- Unknown
level: high
license: DRL-1.1