Windows: Suspicious child process behavior from SolarWinds WebHelpDesk (WebHelpDesk bin with Java)

Alerts on WebHelpDesk (bin) spawning tool-like child processes with download/execution command patterns on Windows.

FreeUnreviewedSigmahighv1
title: "Windows: Suspicious child process behavior from SolarWinds WebHelpDesk (WebHelpDesk bin with Java)"
id: 90daf23e-823c-4ce3-8ca2-82cc81fe0a8a
status: experimental
description: This rule flags Windows process creation where the parent process path indicates SolarWinds WebHelpDesk binaries and the parent command line suggests a Tomcat/Java runtime. It then matches for suspicious child process command lines that include common script/download/execution utilities (e.g., PowerShell web requests, certutil/curl/wget, bitsadmin/Start-BitsTransfer, mshta, wmic, msiexec, or base64-encoded parameters). Such patterns can indicate exploitation or post-exploitation activity where attackers spawn tool-like child processes from the application host. Telemetry required is Windows process creation including ParentImage, ParentCommandLine, and CommandLine.
references:
  - https://www.microsoft.com/en-us/security/blog/2026/02/06/active-exploitation-solarwinds-web-help-desk/
  - https://www.huntress.com/blog/active-exploitation-solarwinds-web-help-desk-cve-2025-26399
  - https://documentation.solarwinds.com/en/success_center/whd/content/release_notes/whd_2026-1_release_notes.htm
  - https://github.com/SigmaHQ/sigma/blob/master/rules-emerging-threats/2025/Exploits/CVE-2025-40551/proc_creation_win_exploit_cve_2025_40551.yml
author: Huntress Team, Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule Team
date: 2026-02-11
tags:
  - attack.initial-access
  - attack.t1190
  - cve.2025-26399
  - cve.2025-40536
  - cve.2025-40551
  - detection.emerging-threats
logsource:
  category: process_creation
  product: windows
detection:
  selection_parent:
    ParentImage|contains: \WebHelpDesk\bin\
    ParentImage|endswith:
      - \java.exe
      - \javaw.exe
    ParentCommandLine|contains: tomcat
  selection_suspicious_child:
    CommandLine|contains:
      - -enc
      - base64
      - bitsadmin
      - certutil
      - curl
      - Invoke-RestMethod
      - Invoke-WebRequest
      - "irm "
      - "iwr "
      - mshta
      - msiexec
      - Net.WebClient
      - Start-BitsTransfer
      - wget
      - wmic
  condition: all of selection_*
falsepositives:
  - Unknown
level: high
license: DRL-1.1
related:
  - id: 8c7f4a2d-3b9e-4f1c-9a6d-2e8f5c3d9a1b
    type: derived

What it detects

This rule flags Windows process creation where the parent process path indicates SolarWinds WebHelpDesk binaries and the parent command line suggests a Tomcat/Java runtime. It then matches for suspicious child process command lines that include common script/download/execution utilities (e.g., PowerShell web requests, certutil/curl/wget, bitsadmin/Start-BitsTransfer, mshta, wmic, msiexec, or base64-encoded parameters). Such patterns can indicate exploitation or post-exploitation activity where attackers spawn tool-like child processes from the application host. Telemetry required is Windows process creation including ParentImage, ParentCommandLine, and CommandLine.

Known false positives

  • Unknown

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.