Windows Process Explorer Driver (.sys) Created by Non-Process-Explorer Binaries
Alerts on creation of PROCEXP-named .sys drivers by processes other than Process Explorer.
FreeUnreviewedSigmahighv1
windows-process-explorer-driver-sys-created-by-non-process-explorer-binaries-de46c52b
title: Windows Process Explorer Driver (.sys) Created by Non-Process-Explorer Binaries
id: 5124688d-0ca1-45bc-a2ec-17e8ac6129e5
status: test
description: This rule flags file creations of Windows driver files whose name contains "\PROCEXP" and ends with ".sys" when the creating process is not one of the Process Explorer executables (procexp.exe, procexp64.exe, procexp64a.exe). Creating and temporarily deploying the Process Explorer driver can be used to enable privileged access and persistence techniques. It relies on file event telemetry capturing the target filename and the creating process image.
references:
- https://learn.microsoft.com/en-us/sysinternals/downloads/process-explorer
- https://github.com/Yaxser/Backstab
- https://www.elastic.co/security-labs/stopping-vulnerable-driver-attacks
- https://news.sophos.com/en-us/2023/04/19/aukill-edr-killer-malware-abuses-process-explorer-driver/
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/file/file_event/file_event_win_sysinternals_procexp_driver_susp_creation.yml
author: Florian Roth (Nextron Systems), Huntrule Team
date: 2023-05-05
modified: 2026-06-29
tags:
- attack.persistence
- attack.privilege-escalation
- attack.t1068
logsource:
product: windows
category: file_event
detection:
selection:
TargetFilename|contains: \PROCEXP
TargetFilename|endswith: .sys
filter_main_process_explorer:
Image|endswith:
- \procexp.exe
- \procexp64.exe
- \procexp64a.exe
condition: selection and not 1 of filter_main_*
falsepositives:
- Some false positives may occur with legitimate renamed process explorer binaries
level: high
license: DRL-1.1
related:
- id: de46c52b-0bf8-4936-a327-aace94f94ac6
type: derived
What it detects
This rule flags file creations of Windows driver files whose name contains "\PROCEXP" and ends with ".sys" when the creating process is not one of the Process Explorer executables (procexp.exe, procexp64.exe, procexp64a.exe). Creating and temporarily deploying the Process Explorer driver can be used to enable privileged access and persistence techniques. It relies on file event telemetry capturing the target filename and the creating process image.
Known false positives
- Some false positives may occur with legitimate renamed process explorer binaries
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.