Windows process execution via stordiag.exe launching schtasks.exe, systeminfo.exe, or fltmc.exe
Detects stordiag.exe spawning schtasks.exe, systeminfo.exe, or fltmc.exe to support system discovery or config actions on Windows.
FreeUnreviewedSigmahighv1
windows-process-execution-via-stordiag-exe-launching-schtasks-exe-systeminfo-exe-961e0abb
title: Windows process execution via stordiag.exe launching schtasks.exe, systeminfo.exe, or fltmc.exe
id: de1f547d-3474-41ce-9abf-cc3928c0cac6
status: test
description: This rule flags process creation where stordiag.exe is the parent process and it spawns schtasks.exe, systeminfo.exe, or fltmc.exe. Such chaining is relevant because stordiag.exe can be abused to execute other system discovery or configuration-related utilities under a less expected parent. The detection relies on Windows process creation telemetry capturing the parent image path and the spawned image path, with a filter excluding executions originating from the standard system directories.
references:
- https://strontic.github.io/xcyclopedia/library/stordiag.exe-1F08FC87C373673944F6A7E8B18CD845.html
- https://twitter.com/eral4m/status/1451112385041911809
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_stordiag_susp_child_process.yml
author: Austin Songer (@austinsonger), Huntrule Team
date: 2021-10-21
modified: 2022-12-25
tags:
- attack.stealth
- attack.t1218
logsource:
category: process_creation
product: windows
detection:
selection:
ParentImage|endswith: \stordiag.exe
Image|endswith:
- \schtasks.exe
- \systeminfo.exe
- \fltmc.exe
filter:
ParentImage|startswith:
- c:\windows\system32\
- c:\windows\syswow64\
condition: selection and not filter
falsepositives:
- Legitimate usage of stordiag.exe.
level: high
license: DRL-1.1
related:
- id: 961e0abb-1b1e-4c84-a453-aafe56ad0d34
type: derived
What it detects
This rule flags process creation where stordiag.exe is the parent process and it spawns schtasks.exe, systeminfo.exe, or fltmc.exe. Such chaining is relevant because stordiag.exe can be abused to execute other system discovery or configuration-related utilities under a less expected parent. The detection relies on Windows process creation telemetry capturing the parent image path and the spawned image path, with a filter excluding executions originating from the standard system directories.
Known false positives
- Legitimate usage of stordiag.exe.
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.