Windows Process Creation: Winnti Pipemon setup* Command-Line Parameters
Alerts on Windows processes launching Pipemon-style setup.exe command lines with specific -p or -x:n flags.
- Product
- windows
- Category
- process_creation
- Author
- Florian Roth (Nextron Systems), oscd.community (SigmaHQ), DRL 1.1
- Published
- 2020-07-30
- Updated
- 2026-07-31
ATT&CK techniques
Execution → Defense EvasionRecon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule flags Windows process creation events where the command line matches specific Pipemon setup executables and argument patterns. Attackers may use these parameters to execute or stage malware components while attempting to blend in with similarly named installers. The detection relies on process creation telemetry with full command-line visibility, matching on substring and suffix conditions.
Reporting behind it
Changelog
v5- v5Candidate ingested via manual entry.2026-07-31
- v4Candidate ingested via manual entry.2026-07-31
- v3Candidate ingested via manual entry.2026-07-31
- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: "Windows Process Creation: Winnti Pipemon setup* Command-Line Parameters"
id: ded7cb1c-110f-4461-bf2f-a5466454d895
status: stable
description: This rule flags Windows process creation events where the command line matches specific Pipemon setup executables and argument patterns. Attackers may use these parameters to execute or stage malware components while attempting to blend in with similarly named installers. The detection relies on process creation telemetry with full command-line visibility, matching on substring and suffix conditions.
references:
- https://www.welivesecurity.com/2020/05/21/no-game-over-winnti-group/
- https://github.com/SigmaHQ/sigma/blob/master/rules-emerging-threats/2020/TA/Winnti/proc_creation_win_apt_winnti_pipemon.yml
author: Florian Roth (Nextron Systems), oscd.community, Huntrule Team
date: 2020-07-30
modified: 2021-11-27
tags:
- attack.privilege-escalation
- attack.persistence
- attack.execution
- attack.stealth
- attack.t1574.001
- attack.g0044
- detection.emerging-threats
logsource:
category: process_creation
product: windows
detection:
selection_1:
CommandLine|contains: setup0.exe -p
selection_2:
CommandLine|contains: setup.exe
CommandLine|endswith:
- -x:0
- -x:1
- -x:2
condition: 1 of selection_*
falsepositives:
- Legitimate setups that use similar flags
level: critical
license: DRL-1.1
related:
- id: 73d70463-75c9-4258-92c6-17500fe972f2
type: derived