Windows Remote Thread Created in KeePass.exe

Flags remote thread creation targeting KeePass.exe, a possible indicator of credential theft.

FreeReviewedSigma · High · v2
Product
windows
Category
create_remote_thread
Author
Timon Hackenjos (SigmaHQ), DRL 1.1
Published
2022-04-22
Updated
2026-07-31

ATT&CK techniques

Cred Access
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule flags creation of a remote thread targeting KeePass.exe. Attackers can use remote thread injection to execute code inside a password manager process, which may support credential theft or related credential-access activity. The detection relies on Windows telemetry that records remote thread creation events with a target process image path ending in '\KeePass.exe'.

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.