Windows SpeechRuntime.exe Child Process Creation

Alerts when SpeechRuntime.exe spawns a child process, highlighting potential abuse for lateral movement on Windows.

FreeReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
andrewdanis (SigmaHQ), DRL 1.1
Published
2025-10-23
Updated
2026-07-30

ATT&CK techniques

Defense Evasion → Lateral Movement
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Cred Access

  8. Discovery

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule flags process creation events where the parent process image ends with \SpeechRuntime.exe, capturing potentially suspicious activity driven by the Speech Runtime. Attackers may abuse a legitimate binary to spawn additional processes as part of lateral movement techniques. The detection relies on Windows process creation telemetry that includes the parent image path and child process start events.

Related detections9 linkedT1218 — drag to rearrange
Windows: Detect Suspicious DLL Loads by BaaUpdate.exe from Publicly Writable Paths
Windows: Detect baaupdate.exe Spawning Scripting, Admin, or LOLBin Child Processes
Suspicious Cabinet Extraction of Masqueraded vstm Archive via extrac32
Malicious DLL Execution via Wuauclt Update Handler (via process_creation)
Malicious Impacket DCOMexec Process Abuse via MMC (via process_creation)
Malicious Impacket DCOMexec Privilege Abuse via MMC (via security)
Malicious aspnet_compiler.exe Injection Host Spawned by PowerShell via process_creation
Malicious regsvcs LOLBin Loading Ransomware DLL from UNC Path
Suspicious RegAsm or RegSvcs Spawned by Script Host (via process_creation)
Windows SpeechRuntime.exe Child Process Creation
Pivot detection · T1218 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.