Windows: Suspicious Parent Process for cmd.exe Execution

Alerts on cmd.exe executions that have a suspicious/atypical parent process among listed Windows binaries.

FreeUnreviewedSigmamediumv1
title: "Windows: Suspicious Parent Process for cmd.exe Execution"
id: 08294d6b-0134-4a07-98c2-3632033e2658
status: test
description: This rule flags process creation events where the Image ends with cmd.exe and the parent process is one of several specific system or service executables. This matters because attackers often launch command-line activity through unexpected parent chains to blend in with normal process behavior. The detection relies on process creation telemetry, specifically the cmd.exe executable path and the ParentImage path suffix.
references:
  - https://www.elastic.co/guide/en/security/current/unusual-parent-process-for-cmd.exe.html
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_cmd_unusual_parent.yml
author: Tim Rauch, Elastic (idea), Huntrule Team
date: 2022-09-21
modified: 2023-12-05
tags:
  - attack.execution
  - attack.t1059
logsource:
  category: process_creation
  product: windows
detection:
  selection:
    Image|endswith: \cmd.exe
    ParentImage|endswith:
      - \csrss.exe
      - \ctfmon.exe
      - \dllhost.exe
      - \epad.exe
      - \FlashPlayerUpdateService.exe
      - \GoogleUpdate.exe
      - \jucheck.exe
      - \jusched.exe
      - \LogonUI.exe
      - \lsass.exe
      - \regsvr32.exe
      - \SearchIndexer.exe
      - \SearchProtocolHost.exe
      - \SIHClient.exe
      - \sihost.exe
      - \slui.exe
      - \spoolsv.exe
      - \sppsvc.exe
      - \taskhostw.exe
      - \unsecapp.exe
      - \WerFault.exe
      - \wermgr.exe
      - \wlanext.exe
      - \WUDFHost.exe
  condition: selection
falsepositives:
  - Unknown
level: medium
license: DRL-1.1
related:
  - id: 4b991083-3d0e-44ce-8fc4-b254025d8d4b
    type: derived

What it detects

This rule flags process creation events where the Image ends with cmd.exe and the parent process is one of several specific system or service executables. This matters because attackers often launch command-line activity through unexpected parent chains to blend in with normal process behavior. The detection relies on process creation telemetry, specifically the cmd.exe executable path and the ParentImage path suffix.

Known false positives

  • Unknown

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.