Windows process execution: WerFault.exe launched from WinSxS by services.exe

Alerts on WerFault.exe running from WinSxS when spawned by services.exe on Windows.

FreeReviewedSigma · High · v5
Product
windows
Category
process_creation
Author
Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2023-05-04
Updated
2026-07-31

What it detects

This rule flags process creation where services.exe starts WerFault.exe, with the WerFault executable path under C:\Windows\WinSxS\ and ending in \WerFault.exe. The WerFault binary is commonly used for Windows error reporting, but unusual parent-child relationships and nonstandard execution paths can indicate malware persistence or execution chaining. The detection relies on Windows process creation telemetry capturing both parent image and full child image path.

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.