Windows whoami.exe Execution from Suspicious Parent Processes
Alerts on whoami.exe runs where the parent process is not a typical shell or monitoring agent.
FreeUnreviewedSigmamediumv1
windows-whoami-exe-execution-from-suspicious-parent-processes-8de1cbe8
title: Windows whoami.exe Execution from Suspicious Parent Processes
id: 28a23b3c-db0a-4067-9fba-3e1129f92f0f
status: test
description: This rule flags process creation events where whoami.exe is executed and the parent process is not one of several known, legitimate shells (such as cmd.exe and PowerShell). Attackers commonly use whoami.exe to quickly collect local user context for discovery and follow-on actions. The detection relies on Windows process creation telemetry, matching whoami.exe by filename and evaluating the parent process image path for exceptions and null/empty parent cases.
references:
- https://brica.de/alerts/alert/public/1247926/agent-tesla-keylogger-delivered-inside-a-power-iso-daa-archive/
- https://app.any.run/tasks/7eaba74e-c1ea-400f-9c17-5e30eee89906/
- https://www.youtube.com/watch?v=DsJ9ByX84o4&t=6s
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_whoami_parent_anomaly.yml
author: Florian Roth (Nextron Systems), Huntrule Team
date: 2021-08-12
modified: 2025-03-06
tags:
- attack.discovery
- attack.t1033
- car.2016-03-001
logsource:
category: process_creation
product: windows
detection:
selection:
- Image|endswith: \whoami.exe
- OriginalFileName: whoami.exe
filter_main_known_parents:
ParentImage|endswith:
- \cmd.exe
- \powershell_ise.exe
- \powershell.exe
- \pwsh.exe
filter_optional_ms_monitoring_agent:
ParentImage|endswith: :\Program Files\Microsoft Monitoring Agent\Agent\MonitoringHost.exe
filter_main_parent_null:
ParentImage: null
filter_main_parent_empty:
ParentImage:
- ""
- "-"
condition: selection and not 1 of filter_main_* and not 1 of filter_optional_*
falsepositives:
- Admin activity
- Scripts and administrative tools used in the monitored environment
- Monitoring activity
level: medium
license: DRL-1.1
related:
- id: 8de1cbe8-d6f5-496d-8237-5f44a721c7a0
type: derived
What it detects
This rule flags process creation events where whoami.exe is executed and the parent process is not one of several known, legitimate shells (such as cmd.exe and PowerShell). Attackers commonly use whoami.exe to quickly collect local user context for discovery and follow-on actions. The detection relies on Windows process creation telemetry, matching whoami.exe by filename and evaluating the parent process image path for exceptions and null/empty parent cases.
Known false positives
- Admin activity
- Scripts and administrative tools used in the monitored environment
- Monitoring activity
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.