Windows: Suspicious Child Processes Spawned by sqlservr.exe
Alerts when SQL Server (sqlservr.exe) spawns suspicious command/system tools on Windows.
FreeUnreviewedSigmahighv1
windows-suspicious-child-processes-spawned-by-sqlservr-exe-869b9ca7
title: "Windows: Suspicious Child Processes Spawned by sqlservr.exe"
id: 8616c9f7-17a7-45e4-a0ee-d2b39b311213
related:
- id: 344482e4-a477-436c-aa70-7536d18a48c7
type: obsolete
- id: 869b9ca7-9ea2-4a5a-8325-e80e62f75445
type: derived
status: test
description: This rule flags Windows process creation events where the parent process is Microsoft SQL Server (sqlservr.exe) and the child process matches a set of commonly used command execution and system interrogation utilities. Such behavior can indicate attempts to establish access, escalate privileges, or leverage SQL Server execution paths for further activity. It relies on process creation telemetry with parent and child image paths and, in one optional case, command-line context to exclude a specific known pattern.
references:
- Internal Research
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_mssql_susp_child_process.yml
author: FPT.EagleEye Team, wagga, Huntrule Team
date: 2020-12-11
modified: 2023-05-04
tags:
- attack.t1505.003
- attack.t1190
- attack.initial-access
- attack.persistence
- attack.privilege-escalation
logsource:
category: process_creation
product: windows
detection:
selection:
ParentImage|endswith: \sqlservr.exe
Image|endswith:
- \bash.exe
- \bitsadmin.exe
- \cmd.exe
- \netstat.exe
- \nltest.exe
- \ping.exe
- \powershell.exe
- \pwsh.exe
- \regsvr32.exe
- \rundll32.exe
- \sh.exe
- \systeminfo.exe
- \tasklist.exe
- \wsl.exe
filter_optional_datev:
ParentImage|startswith: C:\Program Files\Microsoft SQL Server\
ParentImage|endswith: DATEV_DBENGINE\MSSQL\Binn\sqlservr.exe
Image: C:\Windows\System32\cmd.exe
CommandLine|startswith: '"C:\Windows\system32\cmd.exe" '
condition: selection and not 1 of filter_optional_*
level: high
license: DRL-1.1
What it detects
This rule flags Windows process creation events where the parent process is Microsoft SQL Server (sqlservr.exe) and the child process matches a set of commonly used command execution and system interrogation utilities. Such behavior can indicate attempts to establish access, escalate privileges, or leverage SQL Server execution paths for further activity. It relies on process creation telemetry with parent and child image paths and, in one optional case, command-line context to exclude a specific known pattern.
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.