Process Creation Using Sysnative Folder

 Original Source: [Sigma source]
Title: Process Creation Using Sysnative Folder
Status: test
Description:Detects process creation events that use the Sysnative folder (common for CobaltStrike spawns)
References:
  -https://thedfirreport.com/2021/08/29/cobalt-strike-a-defenders-guide/
Author: Max Altgelt (Nextron Systems)
Date: 2022-08-23
modified:2025-10-08
Tags:
  • -'attack.privilege-escalation'
  • -'attack.stealth'
  • -'attack.t1055'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection:
CommandLine|contains:':\Windows\Sysnative\' Image|contains:':\Windows\Sysnative\'   filter_main_ngen:
    Image|contains:
      -'C:\Windows\Microsoft.NET\Framework64\v'
      -'C:\Windows\Microsoft.NET\Framework\v'
      -'C:\Windows\Microsoft.NET\FrameworkArm\v'
      -'C:\Windows\Microsoft.NET\FrameworkArm64\v'

    Image|endswith: '\ngen.exe'
    CommandLine|contains: 'install'
  filter_optional_xampp:
    CommandLine|contains|all:
      -'"C:\Windows\sysnative\cmd.exe"'
      -'\xampp\'
      -'\catalina_start.bat'

  condition:selection and not 1 of filter_main_* and not 1 of filter_optional_*
Falsepositives:
  -Unknown
Level: medium