Windows vmtoolsd.exe Child Process Spawn via Scripting/Utility Binaries
Alert on vmtoolsd.exe spawning cmd/powershell/mshta/regsvr32/rundll32/wscript child processes with VM Tools batch-script command lines.
FreeUnreviewedSigmahighv1
windows-vmtoolsd-exe-child-process-spawn-via-scripting-utility-binaries-5687f942
title: Windows vmtoolsd.exe Child Process Spawn via Scripting/Utility Binaries
id: 88ccd9f2-e74c-4efc-80b8-60fda32ca59e
status: test
description: This rule flags Windows process creation events where vmtoolsd.exe spawns a suspicious child process running from common script and execution utilities (cmd.exe, cscript.exe, mshta.exe, PowerShell/pwsh, regsvr32, rundll32, wscript). The behavior is notable because VMware Tools could be leveraged to set up persistence through command execution, so unexpected parent-child combinations may indicate malicious activity. It relies on process creation telemetry including ParentImage/child Image and CommandLine, including matching on specific command-line strings associated with VM default batch scripts.
references:
- https://bohops.com/2021/10/08/analyzing-and-detecting-a-vmtools-persistence-technique/
- https://user-images.githubusercontent.com/61026070/136518004-b68cce7d-f9b8-4e9a-9b7b-53b1568a9a94.png
- https://github.com/vmware/open-vm-tools/blob/master/open-vm-tools/tools.conf
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_vmware_vmtoolsd_susp_child_process.yml
author: bohops, Bhabesh Raj, Huntrule Team
date: 2021-10-08
modified: 2023-07-25
tags:
- attack.execution
- attack.persistence
- attack.t1059
logsource:
category: process_creation
product: windows
detection:
selection_parent:
ParentImage|endswith: \vmtoolsd.exe
selection_img:
- Image|endswith:
- \cmd.exe
- \cscript.exe
- \mshta.exe
- \powershell.exe
- \pwsh.exe
- \regsvr32.exe
- \rundll32.exe
- \wscript.exe
- OriginalFileName:
- Cmd.Exe
- cscript.exe
- MSHTA.EXE
- PowerShell.EXE
- pwsh.dll
- REGSVR32.EXE
- RUNDLL32.EXE
- wscript.exe
filter_main_vmwaretools_script:
Image|endswith: \cmd.exe
CommandLine|contains:
- \VMware\VMware Tools\poweron-vm-default.bat
- \VMware\VMware Tools\poweroff-vm-default.bat
- \VMware\VMware Tools\resume-vm-default.bat
- \VMware\VMware Tools\suspend-vm-default.bat
filter_main_empty:
Image|endswith: \cmd.exe
CommandLine: ""
filter_main_null:
Image|endswith: \cmd.exe
CommandLine: null
condition: all of selection* and not 1 of filter_main_*
falsepositives:
- Legitimate use by VM administrator
level: high
license: DRL-1.1
related:
- id: 5687f942-867b-4578-ade7-1e341c46e99a
type: derived
What it detects
This rule flags Windows process creation events where vmtoolsd.exe spawns a suspicious child process running from common script and execution utilities (cmd.exe, cscript.exe, mshta.exe, PowerShell/pwsh, regsvr32, rundll32, wscript). The behavior is notable because VMware Tools could be leveraged to set up persistence through command execution, so unexpected parent-child combinations may indicate malicious activity. It relies on process creation telemetry including ParentImage/child Image and CommandLine, including matching on specific command-line strings associated with VM default batch scripts.
Known false positives
- Legitimate use by VM administrator
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.