Windows svchost.exe Uncommon Command-Line Parameter Process Creation

Alerts on Windows process starts of svchost.exe that include an uncommon -k parameter format, after excluding common and benign patterns.

FreeReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
Liran Ravich (SigmaHQ), DRL 1.1
Published
2025-11-14
Updated
2026-07-30

ATT&CK techniques

Priv Esc → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule flags process creation events where svchost.exe is executed with an uncommon command-line parameter pattern, excluding known legitimate/typical cases and certain benign parent processes. Unusual parameters can indicate masquerading, process tampering, or other stealth techniques involving the host process. The detection relies on Windows process creation telemetry, including Image path and CommandLine content, with filters for specific parent-image scenarios.

Related detections9 linkedT1036.005 — drag to rearrange
Suspicious AppLaunch.exe Spawned As Injection Target (via process_creation)
Suspicious svchost Masquerading Executed Outside System Directory
Possible Process Injection Target RegAsm Launched Without Arguments via Process Creation
Windows Defender windefend Event 1119 flags RedSun TieringEngineService.exe EICAR test file
Suspicious ALPHA SPIDER Rclone Exfiltration Tool Masquerading as System Binary (via process_creation)
Suspicious Axios NPM macOS Persistence Masquerading as Apple Service
Suspicious Office Application Spawning Script Or Shell Interpreter
Malicious Spoolsv Process Masquerading From Non-System Path (via process_creation)
Suspicious svchost.exe Execution From AppData Roaming Directory
Windows svchost.exe Uncommon Command-Line Parameter Process Creation
Pivot detection · T1036.005 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.