Windows whoami.exe Execution from Suspicious Parent Processes

Alerts on whoami.exe runs where the parent process is not a typical shell or monitoring agent.

FreeUnreviewedSigmamediumv1
title: Windows whoami.exe Execution from Suspicious Parent Processes
id: 28a23b3c-db0a-4067-9fba-3e1129f92f0f
status: test
description: This rule flags process creation events where whoami.exe is executed and the parent process is not one of several known, legitimate shells (such as cmd.exe and PowerShell). Attackers commonly use whoami.exe to quickly collect local user context for discovery and follow-on actions. The detection relies on Windows process creation telemetry, matching whoami.exe by filename and evaluating the parent process image path for exceptions and null/empty parent cases.
references:
  - https://brica.de/alerts/alert/public/1247926/agent-tesla-keylogger-delivered-inside-a-power-iso-daa-archive/
  - https://app.any.run/tasks/7eaba74e-c1ea-400f-9c17-5e30eee89906/
  - https://www.youtube.com/watch?v=DsJ9ByX84o4&t=6s
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_whoami_parent_anomaly.yml
author: Florian Roth (Nextron Systems), Huntrule Team
date: 2021-08-12
modified: 2025-03-06
tags:
  - attack.discovery
  - attack.t1033
  - car.2016-03-001
logsource:
  category: process_creation
  product: windows
detection:
  selection:
    - Image|endswith: \whoami.exe
    - OriginalFileName: whoami.exe
  filter_main_known_parents:
    ParentImage|endswith:
      - \cmd.exe
      - \powershell_ise.exe
      - \powershell.exe
      - \pwsh.exe
  filter_optional_ms_monitoring_agent:
    ParentImage|endswith: :\Program Files\Microsoft Monitoring Agent\Agent\MonitoringHost.exe
  filter_main_parent_null:
    ParentImage: null
  filter_main_parent_empty:
    ParentImage:
      - ""
      - "-"
  condition: selection and not 1 of filter_main_* and not 1 of filter_optional_*
falsepositives:
  - Admin activity
  - Scripts and administrative tools used in the monitored environment
  - Monitoring activity
level: medium
license: DRL-1.1
related:
  - id: 8de1cbe8-d6f5-496d-8237-5f44a721c7a0
    type: derived

What it detects

This rule flags process creation events where whoami.exe is executed and the parent process is not one of several known, legitimate shells (such as cmd.exe and PowerShell). Attackers commonly use whoami.exe to quickly collect local user context for discovery and follow-on actions. The detection relies on Windows process creation telemetry, matching whoami.exe by filename and evaluating the parent process image path for exceptions and null/empty parent cases.

Known false positives

  • Admin activity
  • Scripts and administrative tools used in the monitored environment
  • Monitoring activity

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.