Windows process command line matches WinPwn tool execution keywords

Alerts on Windows process executions with command-line keywords associated with WinPwn (WinPwn.exe/ps1/offline mode).

FreeReviewedSigma · High · v2
Product
windows
Category
process_creation
Author
Swachchhanda Shrawan Poudel (SigmaHQ), DRL 1.1
Published
2023-12-04
Updated
2026-07-31

What it detects

This rule flags Windows process creation events whose command line contains specific WinPwn-related keywords such as WinPwn.exe, WinPwn.ps1, or Offline_Winpwn. Attackers may invoke WinPwn for Windows and Active Directory reconnaissance and exploitation workflows. The detection relies on process creation telemetry with access to the process command line string.

Related detections9 linkedT1555.003 — drag to rearrange
Windows PowerShell ScriptBlock keyword match for WinPwn tool usage
Suspicious RegAsm MSBuild or AutoIt Accessing Browser Credential Stores
Suspicious Offensive Recon and Credential Tools Execution (via process_creation)
Windows: Detect winPEAS privilege escalation reconnaissance execution
Suspicious ALPHA SPIDER Veeam Backup Credential Extraction (via process_creation)
Malicious FodHelper UAC Bypass via ms-settings Shell Command Hijack (via registry_set)
Suspicious Clipboard Data Access via Get-Clipboard (BeaverTail OtterCookie)
Suspicious UAT-10608 Hidden Credential Harvesting Script Execution via nohup
Suspicious System Profiler Hardware Enumeration (via process_creation)
Windows process command line matches WinPwn tool execution keywords
Pivot detection · T1555.003 · 9 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.