Windows Rare Remote Thread Creation Triggered by Uncommon Source Images
Alerts on remote thread creation on Windows when the source executable is rare, with exclusions for known benign image pairings.
FreeUnreviewedSigmahighv1
windows-rare-remote-thread-creation-triggered-by-uncommon-source-images-02d1d718
title: Windows Rare Remote Thread Creation Triggered by Uncommon Source Images
id: dd839929-336c-427e-8222-e11973a2cae2
related:
- id: 66d31e5f-52d6-40a4-9615-002d3789a119
type: derived
- id: 02d1d718-dd13-41af-989d-ea85c7fab93f
type: derived
status: test
description: This rule flags Windows events where a process creates a remote thread and the creating process (SourceImage) matches a set of uncommon executables, while excluding several common benign combinations. Remote thread creation is a strong indicator of in-memory code execution techniques used by attackers to inject or run code within another process. The detection relies on telemetry that records the SourceImage, TargetImage, and the remote thread creation operation context. It also uses targeted exclusions to reduce noise from specific legitimate Windows or application behaviors.
references:
- Personal research, statistical analysis
- https://lolbas-project.github.io
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/create_remote_thread/create_remote_thread_win_susp_relevant_source_image.yml
author: Perez Diego (@darkquassar), oscd.community, Huntrule Team
date: 2019-10-27
modified: 2025-12-08
tags:
- attack.privilege-escalation
- attack.stealth
- attack.t1055
logsource:
product: windows
category: create_remote_thread
detection:
selection:
SourceImage|endswith:
- \bash.exe
- \cscript.exe
- \cvtres.exe
- \defrag.exe
- \dialer.exe
- \dnx.exe
- \esentutl.exe
- \excel.exe
- \expand.exe
- \find.exe
- \findstr.exe
- \forfiles.exe
- \gpupdate.exe
- \hh.exe
- \installutil.exe
- \lync.exe
- \makecab.exe
- \mDNSResponder.exe
- \monitoringhost.exe
- \msbuild.exe
- \mshta.exe
- \mspaint.exe
- \outlook.exe
- \ping.exe
- \provtool.exe
- \python.exe
- \regsvr32.exe
- \robocopy.exe
- \runonce.exe
- \sapcimc.exe
- \smartscreen.exe
- \spoolsv.exe
- \tstheme.exe
- \userinit.exe
- \vssadmin.exe
- \vssvc.exe
- \w3wp.exe
- \winscp.exe
- \winword.exe
- \wmic.exe
- \wscript.exe
filter_main_conhost:
SourceImage:
- C:\Windows\System32\Defrag.exe
- C:\Windows\System32\makecab.exe
TargetImage: C:\Windows\System32\conhost.exe
filter_main_provtol_svchost:
SourceImage: C:\Windows\System32\provtool.exe
TargetImage: C:\Windows\System32\svchost.exe
filter_main_provtool_system:
SourceImage: C:\Windows\System32\provtool.exe
TargetImage: System
filter_main_userinit:
SourceImage: C:\Windows\System32\userinit.exe
TargetImage: C:\Windows\explorer.exe
filter_main_winword:
SourceImage|endswith: \WINWORD.EXE
TargetImage|startswith:
- C:\Program Files (x86)\
- C:\Program Files\
filter_main_ms_office:
SourceImage|startswith:
- C:\Program Files\Microsoft Office\
- C:\Program Files (x86)\Microsoft Office\
TargetImage: System
filter_optional_explorer_vmtools:
SourceImage|endswith: \SysWOW64\explorer.exe
TargetImage:
- C:\Program Files (x86)\VMware\VMware Tools\vmtoolsd.exe
- C:\Program Files\VMware\VMware Tools\vmtoolsd.exe
condition: selection and not 1 of filter_main_* and not 1 of filter_optional_*
falsepositives:
- This rule is best put in testing first in order to create a baseline that reflects the data in your environment.
level: high
license: DRL-1.1
What it detects
This rule flags Windows events where a process creates a remote thread and the creating process (SourceImage) matches a set of uncommon executables, while excluding several common benign combinations. Remote thread creation is a strong indicator of in-memory code execution techniques used by attackers to inject or run code within another process. The detection relies on telemetry that records the SourceImage, TargetImage, and the remote thread creation operation context. It also uses targeted exclusions to reduce noise from specific legitimate Windows or application behaviors.
Known false positives
- This rule is best put in testing first in order to create a baseline that reflects the data in your environment.
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.