Windows: RunXCmd Command-Line Execution with System or TrustedInstaller Accounts

Flags RunXCmd usage on Windows when invoked to execute commands as System or TrustedInstaller.

FreeReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
Florian Roth (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2022-01-24
Updated
2026-07-30
title: "Windows: RunXCmd Command-Line Execution with System or TrustedInstaller Accounts"
id: 4f270723-7e4e-4c13-a531-0222d4223407
status: test
description: This rule identifies command execution via the RunXCmd tool by matching command-line arguments that specify the System (/account=system) or TrustedInstaller (/account=ti) account, along with the RunXCmd execution parameter (/exec=). Attackers can use this pattern to run commands under elevated or privileged local contexts. The detection relies on Windows process creation telemetry and inspects the process CommandLine fields for these specific substrings.
references:
  - https://www.d7xtech.com/free-software/runx/
  - https://www.winhelponline.com/blog/run-program-as-system-localsystem-account-windows/
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_pua_runxcmd.yml
author: Florian Roth (Nextron Systems), Huntrule Team
date: 2022-01-24
modified: 2023-02-14
tags:
  - attack.execution
  - attack.t1569.002
  - attack.s0029
logsource:
  category: process_creation
  product: windows
detection:
  selection_account:
    CommandLine|contains:
      - " /account=system "
      - " /account=ti "
  selection_exec:
    CommandLine|contains: /exec=
  condition: all of selection_*
falsepositives:
  - Legitimate use by administrators
level: high
license: DRL-1.1
related:
  - id: 93199800-b52a-4dec-b762-75212c196542
    type: derived