Windows Remote Thread Creation Targeting Uncommon Image Processes

Alert on Windows remote thread creation events targeting a predefined list of uncommon processes by image path.

FreeUnreviewedSigmamediumv1
title: Windows Remote Thread Creation Targeting Uncommon Image Processes
id: 63b922ce-fe67-41be-bb49-9bf389b92755
related:
  - id: f016c716-754a-467f-a39e-63c06f773987
    type: obsolete
  - id: a1a144b7-5c9b-4853-a559-2172be8d4a03
    type: derived
status: test
description: This rule flags remote thread creation on Windows where the target process image matches a set of uncommon, explicitly enumerated system or user binaries (for example calc.exe, notepad.exe, sethc.exe, spoolsv.exe, wordpad.exe). Attackers may use remote thread creation to run code inside another process while selecting less expected targets to reduce detection. The detection relies on telemetry for remote thread creation events, including SourceImage and TargetImage paths, plus optional start-function details to narrow common benign cases.
references:
  - https://web.archive.org/web/20220319032520/https://blog.redbluepurple.io/offensive-research/bypassing-injection-detection
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/create_remote_thread/create_remote_thread_win_susp_uncommon_target_image.yml
author: Florian Roth (Nextron Systems), Huntrule Team
date: 2022-03-16
modified: 2025-07-04
tags:
  - attack.privilege-escalation
  - attack.stealth
  - attack.t1055.003
logsource:
  product: windows
  category: create_remote_thread
detection:
  selection:
    TargetImage|endswith:
      - \calc.exe
      - \calculator.exe
      - \mspaint.exe
      - \notepad.exe
      - \ping.exe
      - \sethc.exe
      - \spoolsv.exe
      - \wordpad.exe
      - \write.exe
  filter_main_csrss:
    SourceImage: C:\Windows\System32\csrss.exe
  filter_main_notepad:
    SourceImage:
      - C:\Windows\System32\explorer.exe
      - C:\Windows\System32\OpenWith.exe
    TargetImage: C:\Windows\System32\notepad.exe
  filter_main_sethc:
    SourceImage: C:\Windows\System32\AtBroker.exe
    TargetImage: C:\Windows\System32\Sethc.exe
  filter_optional_aurora_1:
    StartFunction: EtwpNotificationThread
  filter_optional_aurora_2:
    SourceImage|contains: unknown process
  filter_optional_vmtoolsd:
    SourceImage: C:\Program Files\VMware\VMware Tools\vmtoolsd.exe
    StartFunction: GetCommandLineW
    TargetImage:
      - C:\Windows\System32\notepad.exe
      - C:\Windows\System32\spoolsv.exe
  filter_optional_xerox_pjems:
    SourceImage: C:\Program Files\Xerox\XeroxPrintExperience\CommonFiles\XeroxPrintJobEventManagerService.exe
    StartFunction: LoadLibraryW
    TargetImage: C:\Windows\System32\spoolsv.exe
  condition: selection and not 1 of filter_main_* and not 1 of filter_optional_*
falsepositives:
  - Unknown
level: medium
license: DRL-1.1

What it detects

This rule flags remote thread creation on Windows where the target process image matches a set of uncommon, explicitly enumerated system or user binaries (for example calc.exe, notepad.exe, sethc.exe, spoolsv.exe, wordpad.exe). Attackers may use remote thread creation to run code inside another process while selecting less expected targets to reduce detection. The detection relies on telemetry for remote thread creation events, including SourceImage and TargetImage paths, plus optional start-function details to narrow common benign cases.

Known false positives

  • Unknown

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.