Windows Processes Suspicious Parent Directory

 Original Source: [Sigma source]
Title: Windows Processes Suspicious Parent Directory
Status: test
Description:Detect suspicious parent processes of well-known Windows processes
References:
  -https://web.archive.org/web/20180718061628/https://securitybytes.io/blue-team-fundamentals-part-two-windows-processes-759fe15965e2
  -https://www.carbonblack.com/2014/06/10/screenshot-demo-hunt-evil-faster-than-ever-with-carbon-black/
  -https://www.13cubed.com/downloads/windows_process_genealogy_v2.pdf
Author: vburov
Date: 2019-02-23
modified:2025-03-06
Tags:
  • -'attack.stealth'
  • -'attack.t1036.003'
  • -'attack.t1036.005'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection:
    Image|endswith:
      -'\svchost.exe'
      -'\taskhost.exe'
      -'\lsm.exe'
      -'\lsass.exe'
      -'\services.exe'
      -'\lsaiso.exe'
      -'\csrss.exe'
      -'\wininit.exe'
      -'\winlogon.exe'

  filter_sys:
    - ParentImage|endswith:
      - '\SavService.exe'
      - '\ngen.exe'
    - ParentImage|contains:
      - '\System32\'
      - '\SysWOW64\'
  filter_msmpeng:
    ParentImage|contains:
      -'\Windows Defender\'
      -'\Microsoft Security Client\'

    ParentImage|endswith: '\MsMpEng.exe'
  filter_null:
ParentImage:'None'     - ParentImage:
      - ''
      - '-'
  condition:selection and not 1 of filter_*
Falsepositives:
  -Some security products seem to spawn these
Level: low