Windows: Suspicious child process behavior from SolarWinds WebHelpDesk (WebHelpDesk bin with Java)
Alerts on WebHelpDesk (bin) spawning tool-like child processes with download/execution command patterns on Windows.
FreeUnreviewedSigmahighv1
windows-suspicious-child-process-behavior-from-solarwinds-webhelpdesk-webhelpdes-8c7f4a2d
title: "Windows: Suspicious child process behavior from SolarWinds WebHelpDesk (WebHelpDesk bin with Java)"
id: 90daf23e-823c-4ce3-8ca2-82cc81fe0a8a
status: experimental
description: This rule flags Windows process creation where the parent process path indicates SolarWinds WebHelpDesk binaries and the parent command line suggests a Tomcat/Java runtime. It then matches for suspicious child process command lines that include common script/download/execution utilities (e.g., PowerShell web requests, certutil/curl/wget, bitsadmin/Start-BitsTransfer, mshta, wmic, msiexec, or base64-encoded parameters). Such patterns can indicate exploitation or post-exploitation activity where attackers spawn tool-like child processes from the application host. Telemetry required is Windows process creation including ParentImage, ParentCommandLine, and CommandLine.
references:
- https://www.microsoft.com/en-us/security/blog/2026/02/06/active-exploitation-solarwinds-web-help-desk/
- https://www.huntress.com/blog/active-exploitation-solarwinds-web-help-desk-cve-2025-26399
- https://documentation.solarwinds.com/en/success_center/whd/content/release_notes/whd_2026-1_release_notes.htm
- https://github.com/SigmaHQ/sigma/blob/master/rules-emerging-threats/2025/Exploits/CVE-2025-40551/proc_creation_win_exploit_cve_2025_40551.yml
author: Huntress Team, Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule Team
date: 2026-02-11
tags:
- attack.initial-access
- attack.t1190
- cve.2025-26399
- cve.2025-40536
- cve.2025-40551
- detection.emerging-threats
logsource:
category: process_creation
product: windows
detection:
selection_parent:
ParentImage|contains: \WebHelpDesk\bin\
ParentImage|endswith:
- \java.exe
- \javaw.exe
ParentCommandLine|contains: tomcat
selection_suspicious_child:
CommandLine|contains:
- -enc
- base64
- bitsadmin
- certutil
- curl
- Invoke-RestMethod
- Invoke-WebRequest
- "irm "
- "iwr "
- mshta
- msiexec
- Net.WebClient
- Start-BitsTransfer
- wget
- wmic
condition: all of selection_*
falsepositives:
- Unknown
level: high
license: DRL-1.1
related:
- id: 8c7f4a2d-3b9e-4f1c-9a6d-2e8f5c3d9a1b
type: derived
What it detects
This rule flags Windows process creation where the parent process path indicates SolarWinds WebHelpDesk binaries and the parent command line suggests a Tomcat/Java runtime. It then matches for suspicious child process command lines that include common script/download/execution utilities (e.g., PowerShell web requests, certutil/curl/wget, bitsadmin/Start-BitsTransfer, mshta, wmic, msiexec, or base64-encoded parameters). Such patterns can indicate exploitation or post-exploitation activity where attackers spawn tool-like child processes from the application host. Telemetry required is Windows process creation including ParentImage, ParentCommandLine, and CommandLine.
Known false positives
- Unknown
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.