Windows Process Creation: Hermetic Wiper–style Postgres/PowerShell Command-Line Patterns

Flags Windows process creation with wiper-like PowerShell comsvcs MiniDump and related command-line/paths.

FreeReviewedSigma · High · v5
Product
windows
Category
process_creation
Author
Florian Roth (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2022-02-25
Updated
2026-07-31

ATT&CK techniques

Lateral Movement
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule matches specific Windows process creation behaviors that align with observed Hermetic Wiper intrusion activity, including executions referencing postgresql.exe and PowerShell command lines consistent with dumping behavior. Attackers can use such patterns to stage actions, move or access files via administrative shares, and produce artifacts that support follow-on activity. The detection relies on process execution telemetry containing the executed image path and command-line arguments.

Related detections9 linkedT1021.001 — drag to rearrange
Suspicious Enabling of Remote Desktop via fDenyTSConnections Registry by DeadLock Ransomware
Suspicious Plink SSH Tunnel Execution (via process_creation)
Suspicious Remote Desktop Enabled via fDenyTSConnections Registry by Sandworm
Suspicious RDP Shadow Session Started - Native (via rdp)
Malicious RDP BlueeKeep Connection Closed - CVE-2019-0708 (via rdp)
Obfuscated RDP Tunneling Configuration Enabled for Port Forwarding (via process_creation)
Malicious RDP Shadow Session Configuration Enabled - Registry (via registry_event)
Malicious RDP Tunneling (via rdp)
Suspicious Denied RDP Login with Valid Credentials (via security)
Windows Process Creation: Hermetic Wiper–style Postgres/PowerShell Command-Line Patterns
Pivot detection · T1021.001 · 9 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.