Windows: Process Explorer Driver (.sys) Creation by Non-Process Explorer Process
Alerts on creation of PROCEXP-named .sys drivers by processes other than Process Explorer.
- Product
- windows
- Category
- file_event
- Author
- Florian Roth (Nextron Systems) (SigmaHQ), DRL 1.1
- Published
- 2023-05-05
- Updated
- 2026-07-31
ATT&CK techniques
Priv EscRecon
Resource Dev
Initial Access
Execution
Persistence
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule identifies creation of a Process Explorer-related driver file by processes other than the original Process Explorer binaries (procexp.exe, procexp64.exe, procexp64a.exe). Attackers may drop and temporarily use drivers to support privileged capabilities before deleting them. Detection relies on Windows file event telemetry capturing the target .sys path containing '\PROCEXP' and the creating process image name.
Reporting behind it
- learn.microsoft.comhttps://learn.microsoft.com/en-us/sysinternals/downloads/process-explorer
- github.comhttps://github.com/Yaxser/Backstab
- elastic.cohttps://www.elastic.co/security-labs/stopping-vulnerable-driver-attacks
- news.sophos.comhttps://news.sophos.com/en-us/2023/04/19/aukill-edr-killer-malware-abuses-process-explorer-driver/
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules/windows/file/file_event/file_event_win_sysinternals_procexp_driver_susp_creation.yml
Changelog
v2- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: "Windows: Process Explorer Driver (.sys) Creation by Non-Process Explorer Process"
id: 5124688d-0ca1-45bc-a2ec-17e8ac6129e5
status: test
description: This rule identifies creation of a Process Explorer-related driver file by processes other than the original Process Explorer binaries (procexp.exe, procexp64.exe, procexp64a.exe). Attackers may drop and temporarily use drivers to support privileged capabilities before deleting them. Detection relies on Windows file event telemetry capturing the target .sys path containing '\PROCEXP' and the creating process image name.
references:
- https://learn.microsoft.com/en-us/sysinternals/downloads/process-explorer
- https://github.com/Yaxser/Backstab
- https://www.elastic.co/security-labs/stopping-vulnerable-driver-attacks
- https://news.sophos.com/en-us/2023/04/19/aukill-edr-killer-malware-abuses-process-explorer-driver/
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/file/file_event/file_event_win_sysinternals_procexp_driver_susp_creation.yml
author: Florian Roth (Nextron Systems), Huntrule Team
date: 2023-05-05
modified: 2026-06-29
tags:
- attack.persistence
- attack.privilege-escalation
- attack.t1068
logsource:
product: windows
category: file_event
detection:
selection:
TargetFilename|contains: \PROCEXP
TargetFilename|endswith: .sys
filter_main_process_explorer:
Image|endswith:
- \procexp.exe
- \procexp64.exe
- \procexp64a.exe
condition: selection and not 1 of filter_main_*
falsepositives:
- Some false positives may occur with legitimate renamed process explorer binaries
level: high
license: DRL-1.1
related:
- id: de46c52b-0bf8-4936-a327-aace94f94ac6
type: derived