Windows Process Creation: Potential Dridex-Related Execution via svchost/regsvr32 and Recon Tools

Alerts on suspicious svchost.exe or regsvr32.exe process executions with matching command-line and parent/child patterns indicative of Dridex activity.

FreeReviewedSigma · Critical · v5
Product
windows
Category
process_creation
Author
Florian Roth (Nextron Systems), oscd.community, Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2019-01-10
Updated
2026-07-31

ATT&CK techniques

Priv Esc → Discovery
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Defense Evasion

  7. Cred Access

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule flags Windows process creation patterns consistent with Dridex-like activity, focusing on execution chains involving svchost.exe or regsvr32.exe. It matches svchost.exe launching with user Desktop/AppData artifacts, or regsvr32.exe spawned by excel.exe with specific flags and temporary payload paths, and also looks for an unusual svchost.exe parent spawning whoami.exe and net/net1.exe with discovery-oriented arguments. The detection relies on process creation telemetry including Image, CommandLine, and ParentImage to correlate suspicious parent-child relationships and command-line indicators.

Related detections9 linkedT1055 — drag to rearrange
Suspicious Reconnaissance Spawned by Injected SearchProtocolHost via process_creation
Windows Process Creation: SharpView.exe with Recon/Domain Discovery Cmdlets
Suspicious vbc.exe Spawned by Installer Process
Suspicious Office Application Spawning Script Or Shell Interpreter
Suspicious Network Connection From wabmig.exe (Turian Injection)
Suspicious Outbound Network Connection from Explorer Process
Suspicious AppLaunch.exe Spawned As Injection Target (via process_creation)
Suspicious BugSleep Marker File in Public Directory
Suspicious CRAT Injection Named Pipe ChromeUpdatePipe (via pipe_created)
Windows Process Creation: Potential Dridex-Related Execution via svchost/regsvr32 and Recon Tools
Pivot detection · T1055 · 9 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.