Windows Remote Thread Creation Targeting Uncommon System Image Processes

Alert on Windows remote thread creation events targeting a predefined list of uncommon processes by image path.

FreeReviewedSigma · Medium · v2
Product
windows
Category
create_remote_thread
Author
Florian Roth (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2022-03-16
Updated
2026-07-31

ATT&CK techniques

Priv Esc → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule flags Windows remote thread creation events where the TargetImage ends with a short list of commonly abused or sensitive executables (e.g., calc, notepad, sethc, spoolsv). Attackers use remote thread creation to execute code in another process while attempting to blend in with normal Windows activity. The detection relies on Windows event telemetry for process remote thread creation, including SourceImage, TargetImage, and StartFunction, plus explicit exclusions for several known benign source/target combinations.

Related detections2 linkedT1055.003 — drag to rearrange
Suspicious notepad Spawned by mshta for Process Injection
Windows Maldoc Process Injection via winword.exe CallTrace from LittleCorporal
Windows Remote Thread Creation Targeting Uncommon System Image Processes
Pivot detection · T1055.003 · 2 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.