Title:
Renamed ProcDump Execution
Status:
test
Description:Detects the execution of a renamed ProcDump executable.
This often done by attackers or malware in order to evade defensive mechanisms.
References:
-https://learn.microsoft.com/en-us/sysinternals/downloads/procdump
Author: Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems)
Date: 2019-11-18
modified:2026-06-29
Tags:
- -'attack.stealth'
- -'attack.t1036.003'
Logsource:
- product: windows
- category: process_creation
Detection:
selection_ofn:
OriginalFileName:
'procdump'
selection_cli_dump_flag:
CommandLine|contains|windash:
-' -ma '
-' -mp '
selection_cli_eula_flag:
CommandLine|contains|windash:
' /accepteula'
filter_main_known_names:
Image|endswith:
-'\procdump.exe'
-'\procdump64.exe'
-'\procdump64a.exe'
condition:
(selection_ofn or all of selection_cli_*) and not 1 of filter_main_*
Falsepositives:
-Procdump illegally bundled with legitimate software.
-Administrators who rename binaries (should be investigated).
Level:
high