Windows: Suspicious Parent Process for cmd.exe Execution
Alerts on cmd.exe executions that have a suspicious/atypical parent process among listed Windows binaries.
FreeUnreviewedSigmamediumv1
windows-suspicious-parent-process-for-cmd-exe-execution-4b991083
title: "Windows: Suspicious Parent Process for cmd.exe Execution"
id: 08294d6b-0134-4a07-98c2-3632033e2658
status: test
description: This rule flags process creation events where the Image ends with cmd.exe and the parent process is one of several specific system or service executables. This matters because attackers often launch command-line activity through unexpected parent chains to blend in with normal process behavior. The detection relies on process creation telemetry, specifically the cmd.exe executable path and the ParentImage path suffix.
references:
- https://www.elastic.co/guide/en/security/current/unusual-parent-process-for-cmd.exe.html
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_cmd_unusual_parent.yml
author: Tim Rauch, Elastic (idea), Huntrule Team
date: 2022-09-21
modified: 2023-12-05
tags:
- attack.execution
- attack.t1059
logsource:
category: process_creation
product: windows
detection:
selection:
Image|endswith: \cmd.exe
ParentImage|endswith:
- \csrss.exe
- \ctfmon.exe
- \dllhost.exe
- \epad.exe
- \FlashPlayerUpdateService.exe
- \GoogleUpdate.exe
- \jucheck.exe
- \jusched.exe
- \LogonUI.exe
- \lsass.exe
- \regsvr32.exe
- \SearchIndexer.exe
- \SearchProtocolHost.exe
- \SIHClient.exe
- \sihost.exe
- \slui.exe
- \spoolsv.exe
- \sppsvc.exe
- \taskhostw.exe
- \unsecapp.exe
- \WerFault.exe
- \wermgr.exe
- \wlanext.exe
- \WUDFHost.exe
condition: selection
falsepositives:
- Unknown
level: medium
license: DRL-1.1
related:
- id: 4b991083-3d0e-44ce-8fc4-b254025d8d4b
type: derived
What it detects
This rule flags process creation events where the Image ends with cmd.exe and the parent process is one of several specific system or service executables. This matters because attackers often launch command-line activity through unexpected parent chains to blend in with normal process behavior. The detection relies on process creation telemetry, specifically the cmd.exe executable path and the ParentImage path suffix.
Known false positives
- Unknown
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.