Windows: Suspicious explorer.exe Child Process Spawned by RazerInstaller.exe

Flags explorer.exe spawned by RazerInstaller.exe when the installer runs at System/high integrity.

FreeReviewedSigma · High · v5
Product
windows
Category
process_creation
Author
Florian Roth (Nextron Systems), Maxime Thiebaut (SigmaHQ), DRL 1.1
Published
2021-08-23
Updated
2026-07-31

ATT&CK techniques

Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule flags the creation of an explorer.exe subprocess when the parent process is RazerInstaller.exe and the parent runs with System integrity. Such subprocess spawning from an installer may be abused to perform actions under elevated context, which attackers can leverage during privilege escalation or defense-impairment. It relies on Windows process creation telemetry, including parent image paths, child image paths, and integrity level values.

Related detections3 linkedT1553 — drag to rearrange
Windows Process Execution with 'University of California, Berkeley' Description
Windows: Detect execution of renamed BOINC.exe binary
macOS Script Editor Spawns Suspicious Command-Line Interpreters
Windows: Suspicious explorer.exe Child Process Spawned by RazerInstaller.exe
Pivot detection · T1553 · 3 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.