Windows WmiPrvSE.exe Spawning Suspicious Script and LOLBIN Child Processes

Flags WmiPrvSE.exe spawning script/utility executables like mshta or regsvr32, with command-line keywords where applicable.

FreeReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
Vadim Khrykov (ThreatIntel), Cyb3rEng, Florian Roth (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2021-08-23
Updated
2026-07-30

ATT&CK techniques

Execution → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule identifies Windows process creation events where WmiPrvSE.exe launches uncommon child executables associated with scripting and living-off-the-land abuse. Attackers may leverage WmiPrvSE as a trusted host to execute commands indirectly through interpreters or utility binaries such as certutil, cscript, mshta, msiexec, regsvr32, rundll32, verclsid, and wscript. It relies on telemetry from Windows process_creation, including parent process image paths and child process image and command line content to match suspicious relationships.

Related detections9 linkedT1047 — drag to rearrange
Windows Process Creation: Office-Launched WMIC with LOLBIN-Style Command Arguments
Windows: Suspicious Process Spawning from Microsoft Office Applications
Malicious Office Application Loading a User-Path DLL via Regsvr32 or Rundll32 (via process_creation)
Windows Process Creation: Maze Ransomware Doc Dropper and Shadow Copy Deletion Indicators
Windows Process Creation: Suspicious Children Spawned by HTML Help (hh.exe)
Windows: Alert on Suspicious HH.EXE Process Execution
Suspicious OneNote Spawning Script Interpreter (via process_creation)
Lateral Movement via WMIC Remote Process Creation
Suspicious vbc.exe Spawned by Installer Process
Windows WmiPrvSE.exe Spawning Suspicious Script and LOLBIN Child Processes
Pivot detection · T1047 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.