Windows Process Execution of .SettingContent-ms Command Line

Flags Windows processes whose command lines reference .SettingContent-ms, a potential trigger for setting-based execution.

FreeReviewedSigma · Medium · v1
Product
windows
Category
process_creation
Author
Sreeman (SigmaHQ), DRL 1.1
Published
2020-03-13
Updated
2026-07-30

ATT&CK techniques

Initial Access → Execution
  1. Recon

  2. Resource Dev

  3. Persistence

  4. Priv Esc

  5. Defense Evasion

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule identifies Windows process creation events where the command line contains the string '.SettingContent-ms'. This file type can be used to redirect execution to Windows setting components, making it a practical mechanism for attackers to trigger arbitrary command execution paths through Windows binaries. Detection relies on process creation telemetry that includes the full command line and uses an exclusion to reduce matches associated with 'immersivecontrolpanel'.

Related detections9 linkedT1566.001 — drag to rearrange
Malicious Edge Abuse for Payload Download via Console (via process_creation)
Suspicious mstsc Launch of RDP File From User Download or Temp Path (via process_creation)
Suspicious Regsvr32 Squiblydoo Remote Scriptlet Execution via Command Line (via process_creation)
Obfuscated Edge/Chrome Headless Feature Abuse for Payload Download (via process_creation)
Possible Mamba 2FA AiTM Phishing URL Pattern
Suspicious DLL Written to Explorer IconCache Path
Suspicious DNS Query to HTML Smuggling AiTM Phishing Domain
Malicious Microsoft Word Spawning Anomalous Child Process via CVE-2023-36884 (via process_creation)
Malicious Equation Editor Child Process Execution via process_creation
Windows Process Execution of .SettingContent-ms Command Line
Pivot detection · T1566.001 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.