Windows Process Creation: Suspicious SetupComplete.cmd execution for CVE-2019-1378 exploitation

Alerts on cmd.exe parent command lines executing SetupComplete.cmd or PartnerSetupComplete.cmd from Windows Setup script paths.

FreeReviewedSigma · High · v5
Product
windows
Category
process_creation
Author
Florian Roth (Nextron Systems), oscd.community, Jonhnathan Ribeiro (SigmaHQ), DRL 1.1
Published
2019-11-15
Updated
2026-07-31

ATT&CK techniques

Execution → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Cred Access

  5. Discovery

  6. Lateral Movement

  7. Collection

  8. C2

  9. Exfiltration

  10. Impact

What it detects

This rule flags Windows process creation events where the parent command line invokes cmd.exe via /c and includes scripts under C:\Windows\Setup\Scripts\, ending with SetupComplete.cmd or PartnerSetupComplete.cmd. This behavior matters because those script entry points are associated with a privilege escalation exploitation path for CVE-2019-1378. The detection relies on process creation telemetry that includes parent command line details and the child process image path for exclusions.

Related detections9 linkedT1068 — drag to rearrange
Windows Process Creation: CrushFTP spawning PowerShell, CMD, and scripting tool execution
Malicious Shell Spawned by SharePoint Worker Process w3wp
Malicious JuicyPotato Privilege Escalation Execution (UAT-7237)
Suspicious Dell ControlVault DLL Load by Unexpected Process (ReVault)
Malicious Known Vulnerable Driver Load for BYOVD Attack
Suspicious Vulnerable ASUS AsIO3.sys Driver Load
Malicious Qilin EDR Killer BYOVD Driver Load
Suspicious IP Release and Renew via Minimized cmd During Driver Install
Malicious IIS Worker Spawning nslookup via WS_FTP Deserialization
Windows Process Creation: Suspicious SetupComplete.cmd execution for CVE-2019-1378 exploitation
Pivot detection · T1068 · 9 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.