Windows process creation matching specific Peach Sandstorm command-line indicator

Alerts on Windows process creations whose command line contains a specific suspicious substring.

FreeReviewedSigma · High · v5
Product
windows
Category
process_creation
Author
X__Junior (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2024-01-15
Updated
2026-07-31

What it detects

This rule flags Windows process creation events where the process command line contains the exact suspicious string pattern 'QP''s\*(58vaP!tF4'. Attackers may use distinctive command-line arguments or embedded payload markers during execution, so matching these strings can help surface related activity. The detection relies on process creation telemetry that includes the full command line.

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.