This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Uncommon Svchost Command Line Parameter
Original Source:
[Sigma source]
Title:
Uncommon Svchost Command Line Parameter
Status:
experimental
Description:
Detects instances of svchost.exe running with an unusual or uncommon command line parameter by excluding known legitimate or common patterns. This could point at a file masquerading as svchost, a process injection, or hollowing of a legitimate svchost instance.
References:
-https://cardinalops.com/blog/the-art-of-anomaly-hunting-patterns-detection/
-https://www.security.com/threat-intelligence/blackbyte-exbyte-ransomware
-https://cloud.google.com/blog/topics/threat-intelligence/apt41-initiates-global-intrusion-campaign-using-multiple-exploits/
-https://media.kasperskycontenthub.com/wp-content/uploads/sites/43/2018/03/08064518/Carbanak_APT_eng.pdf
Author:
Liran Ravich
Date:
2025-11-14
modified:
2026-03-23
Tags:
-'attack.privilege-escalation'
-'attack.stealth'
-'attack.t1036.005'
-'attack.t1055'
-'attack.t1055.012'
Logsource:
category: process_creation
product: windows
Detection:
selection:
Image|endswith
:
'\svchost.exe'
filter_main_flags:
CommandLine|re
:
'-k\s\w{1,64}(?:\s?(?:-p|-s))?'
filter_main_empty:
CommandLine
:
''
filter_main_null:
CommandLine
:
'None'
filter_optional_defender:
ParentImage|endswith
:
'\MsMpEng.exe'
CommandLine|contains
:
'svchost.exe'
filter_optional_mrt:
ParentImage|endswith
:
'\MRT.exe'
CommandLine
:
'svchost.exe'
condition
:
selection and not 1 of filter_main_* and not 1 of filter_optional_*
Falsepositives:
-Unlikely
Level:
high