Suspicious ArcSOC.exe Child Process

 Original Source: [Sigma source]
Title: Suspicious ArcSOC.exe Child Process
Status: experimental
Description:Detects script interpreters, command-line tools, and similar suspicious child processes of ArcSOC.exe. ArcSOC.exe is the process name which hosts ArcGIS Server REST services. If an attacker compromises an ArcGIS Server system and uploads a malicious Server Object Extension (SOE), they can send crafted requests to the corresponding service endpoint and remotely execute code from the ArcSOC.exe process.
References:
  -https://reliaquest.com/blog/threat-spotlight-inside-flax-typhoons-arcgis-compromise/
  -https://enterprise.arcgis.com/en/server/12.0/administer/windows/inside-an-arcgis-server-site.htm
Author: Micah Babinski
Date: 2025-11-25
modified:None
Tags:
  • -'attack.execution'
  • -'attack.t1059'
  • -'attack.t1203'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection:
    ParentImage|endswith: '\ArcSOC.exe'
    Image|endswith:
      -'\cmd.exe'
      -'\cscript.exe'
      -'\mshta.exe'
      -'\powershell.exe'
      -'\pwsh.exe'
      -'\regsvr32.exe'
      -'\rundll32.exe'
      -'\wmic.exe'
      -'\wscript.exe'

  filter_main_cmd:
    Image|endswith: '\cmd.exe'
    CommandLine: 'cmd.exe /c "ver"'
  condition:selection and not 1 of filter_main_*
Falsepositives:
  -Unknown
Level: high