Windows: Uncommon Child Processes Spawned by SndVol.exe

Alerts when SndVol.exe launches unusual child processes, using Windows process creation logs.

FreeReviewedSigma · Medium · v1
Product
windows
Category
process_creation
Author
X__Junior (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2023-06-09
Updated
2026-07-30

What it detects

This rule flags process creation events where SndVol.exe spawns a child process that is not part of the explicitly allowed rundll32 control-run pattern. Attackers can abuse commonly trusted Windows binaries like the volume mixer to launch additional payloads while blending into normal user activity. The detection relies on Windows process creation telemetry, matching the parent process executable name and inspecting the spawned child executable and command line.

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.