Windows: Suspicious child processes spawned by pc-app.exe (PaperCut MF/NG potential exploitation)

Alert on pc-app.exe spawning common command or scripting utilities on Windows.

FreeReviewedSigma · High · v5
Product
windows
Category
process_creation
Author
Nasreddine Bencherchali (Nextron Systems), Huntress DE&TH Team (idea) (SigmaHQ), DRL 1.1
Published
2023-04-20
Updated
2026-07-31

What it detects

This rule identifies Windows process creation events where pc-app.exe spawns a child process from a common scripting, execution, and living-off-the-land tool set (for example PowerShell, cmd.exe, mshta.exe, certutil.exe, and wmic.exe). Such parent-child relationships can indicate attempted exploitation or post-exploitation activity against a PaperCut MF/NG component running as pc-app.exe. It relies on process_creation telemetry with parent and image path fields that end with pc-app.exe and the matched child executable names.

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.