wusa.exe Execution with Parent in Suspicious Windows Paths
Alerts when wusa.exe is spawned by a parent running from common suspicious Windows directories, excluding .msu-related noise.
FreeUnreviewedSigmahighv1
wusa-exe-execution-with-parent-in-suspicious-windows-paths-ef64fc9c
title: wusa.exe Execution with Parent in Suspicious Windows Paths
id: 1dcf3c41-7474-4db1-a676-af3946f6e82b
status: test
description: This rule flags process creation where wusa.exe (Windows Update Standalone Installer) is launched and its parent process path matches common suspicious locations (such as Perflogs, Public, Temp directories, or Temporary Internet). Attackers may use legitimate Windows binaries placed or invoked from unusual locations to help bypass security controls and execute with elevated context. It relies on Windows process creation telemetry, specifically the child Image ending in \wusa.exe, ParentImage path substrings, and CommandLine containing .msu to focus on update-file execution.
references:
- https://www.fortinet.com/blog/threat-research/konni-campaign-distributed-via-malicious-document
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_wusa_susp_parent_execution.yml
author: X__Junior (Nextron Systems), Huntrule Team
date: 2023-11-26
modified: 2024-08-15
tags:
- attack.execution
logsource:
category: process_creation
product: windows
detection:
selection_img:
Image|endswith: \wusa.exe
selection_paths_1:
ParentImage|contains:
- :\Perflogs\
- :\Users\Public\
- :\Windows\Temp\
- \Appdata\Local\Temp\
- \Temporary Internet
selection_paths_2:
- ParentImage|contains|all:
- :\Users\
- \Favorites\
- ParentImage|contains|all:
- :\Users\
- \Favourites\
- ParentImage|contains|all:
- :\Users\
- \Contacts\
- ParentImage|contains|all:
- :\Users\
- \Pictures\
filter_main_msu:
CommandLine|contains: .msu
condition: selection_img and 1 of selection_paths_* and not 1 of filter_main_*
falsepositives:
- Unknown
level: high
license: DRL-1.1
related:
- id: ef64fc9c-a45e-43cc-8fd8-7d75d73b4c99
type: derived
What it detects
This rule flags process creation where wusa.exe (Windows Update Standalone Installer) is launched and its parent process path matches common suspicious locations (such as Perflogs, Public, Temp directories, or Temporary Internet). Attackers may use legitimate Windows binaries placed or invoked from unusual locations to help bypass security controls and execute with elevated context. It relies on Windows process creation telemetry, specifically the child Image ending in \wusa.exe, ParentImage path substrings, and CommandLine containing .msu to focus on update-file execution.
Known false positives
- Unknown
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.