Windows Process Creation: Suspicious Child Programs Spawned by mshta, PowerShell, wscript, rundll32

Alerts when mshta/PowerShell and similar script hosts spawn tasks, download/transfer, or utility tools on Windows.

FreeReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
Florian Roth (Nextron Systems), Tim Shelton (SigmaHQ), DRL 1.1
Published
2018-04-06
Updated
2026-07-30

ATT&CK techniques

Execution → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Persistence

  5. Priv Esc

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule flags process creation events where a Windows shell or scripting parent process (mshta, PowerShell/pwsh, rundll32, cscript/wscript, wmiprvse, regsvr32) spawns specific child executables often used to stage or execute external functionality (schtasks, nslookup, certutil, bitsadmin, mshta). Such parent-child combinations can indicate execution workflows used for stealth, download/transfer, or proxy execution. The detection relies on process creation telemetry including parent image, child image, and command-line and current-directory context, with exclusions for common environment/script patterns (e.g., SCCM and Amazon WorkSpaces) to reduce false positives.

Related detections9 linkedT1059.001 — drag to rearrange
Windows Process Creation: Suspicious Children Spawned by HTML Help (hh.exe)
Windows: Alert on Suspicious HH.EXE Process Execution
Malicious Script Host Spawning PowerShell With Invoke-Expression (via process_creation)
Suspicious Script Host Spawning PowerShell via BlindEagle Chain
Malicious ClickFix Execution Chain Spawning MSHTA via Pcalua on EtherRAT Infection
Suspicious WScript Spawning PowerShell From VBS Loader via wscript.exe (via process_creation)
Suspicious PowerShell Spawned by Windows Script Host from HTML Smuggling (via process_creation)
Suspicious PowerShell Spawned by Windows Script Host via Process Creation (via process_creation)
Malicious Excel Macro Spawning Scripting Interpreter Downloader (via process_creation)
Windows Process Creation: Suspicious Child Programs Spawned by mshta, PowerShell, wscript, rundll32
Pivot detection · T1059.001 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.