Uncommon Svchost Command Line Parameter

 Original Source: [Sigma source]
Title: Uncommon Svchost Command Line Parameter
Status: experimental
Description:Detects instances of svchost.exe running with an unusual or uncommon command line parameter by excluding known legitimate or common patterns. This could point at a file masquerading as svchost, a process injection, or hollowing of a legitimate svchost instance.
References:
  -https://cardinalops.com/blog/the-art-of-anomaly-hunting-patterns-detection/
  -https://www.security.com/threat-intelligence/blackbyte-exbyte-ransomware
  -https://cloud.google.com/blog/topics/threat-intelligence/apt41-initiates-global-intrusion-campaign-using-multiple-exploits/
  -https://media.kasperskycontenthub.com/wp-content/uploads/sites/43/2018/03/08064518/Carbanak_APT_eng.pdf
Author: Liran Ravich
Date: 2025-11-14
modified:2026-03-23
Tags:
  • -'attack.privilege-escalation'
  • -'attack.stealth'
  • -'attack.t1036.005'
  • -'attack.t1055'
  • -'attack.t1055.012'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection:
    Image|endswith: '\svchost.exe'
  filter_main_flags:
    CommandLine|re: '-k\s\w{1,64}(?:\s?(?:-p|-s))?'
  filter_main_empty:
    CommandLine: ''
  filter_main_null:
    CommandLine: 'None'
  filter_optional_defender:
    ParentImage|endswith: '\MsMpEng.exe'
    CommandLine|contains: 'svchost.exe'
  filter_optional_mrt:
    ParentImage|endswith: '\MRT.exe'
    CommandLine: 'svchost.exe'
  condition:selection and not 1 of filter_main_* and not 1 of filter_optional_*
Falsepositives:
  -Unlikely
Level: high