Windows WmiPrvSE.exe Spawning Suspicious Script and LOLBIN Child Processes
Flags WmiPrvSE.exe spawning script/utility executables like mshta or regsvr32, with command-line keywords where applicable.
FreeUnreviewedSigmahighv1
windows-wmiprvse-exe-spawning-suspicious-script-and-lolbin-child-processes-8a582fe2
title: Windows WmiPrvSE.exe Spawning Suspicious Script and LOLBIN Child Processes
id: 34b941b8-25bb-417a-9d44-68c82a7cff91
related:
- id: 692f0bec-83ba-4d04-af7e-e884a96059b6
type: similar
- id: d21374ff-f574-44a7-9998-4a8c8bf33d7d
type: similar
- id: 18cf6cf0-39b0-4c22-9593-e244bdc9a2d4
type: obsolete
- id: 8a582fe2-0882-4b89-a82a-da6b2dc32937
type: derived
status: test
description: This rule identifies Windows process creation events where WmiPrvSE.exe launches uncommon child executables associated with scripting and living-off-the-land abuse. Attackers may leverage WmiPrvSE as a trusted host to execute commands indirectly through interpreters or utility binaries such as certutil, cscript, mshta, msiexec, regsvr32, rundll32, verclsid, and wscript. It relies on telemetry from Windows process_creation, including parent process image paths and child process image and command line content to match suspicious relationships.
references:
- https://thedfirreport.com/2021/03/29/sodinokibi-aka-revil-ransomware/
- https://github.com/vadim-hunter/Detection-Ideas-Rules/blob/02bcbfc2bfb8b4da601bb30de0344ae453aa1afe/Threat%20Intelligence/The%20DFIR%20Report/20210329_Sodinokibi_(aka_REvil)_Ransomware.yaml
- https://blog.osarmor.com/319/onenote-attachment-delivers-asyncrat-malware/
- https://twitter.com/ForensicITGuy/status/1334734244120309760
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_wmiprvse_susp_child_processes.yml
author: Vadim Khrykov (ThreatIntel), Cyb3rEng, Florian Roth (Nextron Systems), Huntrule Team
date: 2021-08-23
modified: 2023-11-10
tags:
- attack.execution
- attack.stealth
- attack.t1047
- attack.t1204.002
- attack.t1218.010
logsource:
product: windows
category: process_creation
detection:
selection_parent:
ParentImage|endswith: \wbem\WmiPrvSE.exe
selection_children_1:
Image|endswith:
- \certutil.exe
- \cscript.exe
- \mshta.exe
- \msiexec.exe
- \regsvr32.exe
- \rundll32.exe
- \verclsid.exe
- \wscript.exe
selection_children_2:
Image|endswith: \cmd.exe
CommandLine|contains:
- cscript
- mshta
- powershell
- pwsh
- regsvr32
- rundll32
- wscript
filter_main_werfault:
Image|endswith: \WerFault.exe
filter_main_wmiprvse:
Image|endswith: \WmiPrvSE.exe
filter_main_msiexec:
Image|endswith: \msiexec.exe
CommandLine|contains: "/i "
condition: selection_parent and 1 of selection_children_* and not 1 of filter_main_*
falsepositives:
- Unknown
level: high
license: DRL-1.1
What it detects
This rule identifies Windows process creation events where WmiPrvSE.exe launches uncommon child executables associated with scripting and living-off-the-land abuse. Attackers may leverage WmiPrvSE as a trusted host to execute commands indirectly through interpreters or utility binaries such as certutil, cscript, mshta, msiexec, regsvr32, rundll32, verclsid, and wscript. It relies on telemetry from Windows process_creation, including parent process image paths and child process image and command line content to match suspicious relationships.
Known false positives
- Unknown
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.