Potentially Suspicious Child Processes Spawned by ConHost

 Original Source: [Sigma source]
Title: Potentially Suspicious Child Processes Spawned by ConHost
Status: experimental
Description:Detects suspicious child processes related to Windows Shell utilities spawned by `conhost.exe`, which could indicate malicious activity using trusted system components.
References:
  -https://tria.ge/241015-l98snsyeje/behavioral2
Author: Swachchhanda Shrawan Poudel (Nextron Systems)
Date: 2025-02-05
modified:None
Tags:
  • -'attack.stealth'
  • -'attack.t1202'
  • -'attack.t1218'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_parent:
    ParentImage|endswith: '\conhost.exe'
  selection_child:
    - Image|endswith:
      - '\cmd.exe'
      - '\cscript.exe'
      - '\mshta.exe'
      - '\powershell_ise.exe'
      - '\powershell.exe'
      - '\pwsh.exe'
      - '\regsvr32.exe'
      - '\wscript.exe'
    - OriginalFileName:
      - 'cmd.exe'
      - 'cscript.exe'
      - 'mshta.exe'
      - 'powershell_ise.exe'
      - 'powershell.exe'
      - 'pwsh.dll'
      - 'regsvr32.exe'
      - 'wscript.exe'
  condition:all of selection_*
Falsepositives:
  -Legitimate administrative tasks using `conhost.exe` to spawn child processes such as `cmd.exe`, `powershell.exe`, or `regsvr32.exe`.
Level: high