Windows whoami.exe Execution from Suspicious Parent Processes

Alerts on whoami.exe runs where the parent process is not a typical shell or monitoring agent.

FreeReviewedSigma · Medium · v1
Product
windows
Category
process_creation
Author
Florian Roth (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2021-08-12
Updated
2026-07-30
title: Windows whoami.exe Execution from Suspicious Parent Processes
id: 28a23b3c-db0a-4067-9fba-3e1129f92f0f
status: test
description: This rule flags process creation events where whoami.exe is executed and the parent process is not one of several known, legitimate shells (such as cmd.exe and PowerShell). Attackers commonly use whoami.exe to quickly collect local user context for discovery and follow-on actions. The detection relies on Windows process creation telemetry, matching whoami.exe by filename and evaluating the parent process image path for exceptions and null/empty parent cases.
references:
  - https://brica.de/alerts/alert/public/1247926/agent-tesla-keylogger-delivered-inside-a-power-iso-daa-archive/
  - https://app.any.run/tasks/7eaba74e-c1ea-400f-9c17-5e30eee89906/
  - https://www.youtube.com/watch?v=DsJ9ByX84o4&t=6s
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_whoami_parent_anomaly.yml
author: Florian Roth (Nextron Systems), Huntrule Team
date: 2021-08-12
modified: 2025-03-06
tags:
  - attack.discovery
  - attack.t1033
  - car.2016-03-001
logsource:
  category: process_creation
  product: windows
detection:
  selection:
    - Image|endswith: \whoami.exe
    - OriginalFileName: whoami.exe
  filter_main_known_parents:
    ParentImage|endswith:
      - \cmd.exe
      - \powershell_ise.exe
      - \powershell.exe
      - \pwsh.exe
  filter_optional_ms_monitoring_agent:
    ParentImage|endswith: :\Program Files\Microsoft Monitoring Agent\Agent\MonitoringHost.exe
  filter_main_parent_null:
    ParentImage: null
  filter_main_parent_empty:
    ParentImage:
      - ""
      - "-"
  condition: selection and not 1 of filter_main_* and not 1 of filter_optional_*
falsepositives:
  - Admin activity
  - Scripts and administrative tools used in the monitored environment
  - Monitoring activity
level: medium
license: DRL-1.1
related:
  - id: 8de1cbe8-d6f5-496d-8237-5f44a721c7a0
    type: derived