Title:
Potentially Suspicious Child Processes Spawned by ConHost
Status:
experimental
Description:Detects suspicious child processes related to Windows Shell utilities spawned by `conhost.exe`, which could indicate malicious activity using trusted system components.
References:
-https://tria.ge/241015-l98snsyeje/behavioral2
Author: Swachchhanda Shrawan Poudel (Nextron Systems)
Date: 2025-02-05
modified:None
Tags:
- -'attack.stealth'
- -'attack.t1202'
- -'attack.t1218'
Logsource:
- category: process_creation
- product: windows
Detection:
selection_parent:
ParentImage|endswith:
'\conhost.exe'
selection_child:
- Image|endswith:
- '\cmd.exe'
- '\cscript.exe'
- '\mshta.exe'
- '\powershell_ise.exe'
- '\powershell.exe'
- '\pwsh.exe'
- '\regsvr32.exe'
- '\wscript.exe'
- OriginalFileName:
- 'cmd.exe'
- 'cscript.exe'
- 'mshta.exe'
- 'powershell_ise.exe'
- 'powershell.exe'
- 'pwsh.dll'
- 'regsvr32.exe'
- 'wscript.exe'
condition:
all of selection_*
Falsepositives:
-Legitimate administrative tasks using `conhost.exe` to spawn child processes such as `cmd.exe`, `powershell.exe`, or `regsvr32.exe`.
Level:
high