Windows VSSVC Process Accessing Defender Engine: endpointEndpointNoneversion:1
Detects vssvc.exe opening a handle to MsMpEng.exe.
In the RedSun exploit, VSS participates in the cloud-file restore race that directs WD to write through the NTFS junction.
This handle acquisition is observed at the exact moment of exploitation.
vssvc querying MsMpEng is not expected in normal operation.
Windows Suspicious Burst of Password Changes: endpointEndpointNoneversion:1
A regular user account performed rapid, repeated password changes across multiple local accounts within a 2-second window.
This pattern is consistent with automated credential manipulation tools that cycle account passwords to deny access to defenders or escalate privileges The speed and volume of changes indicates scripted or tooled activity rather than manual administration, as legitimate password resets do not occur at machine speed across multiple accounts simultaneously.
Overwriting Accessibility Binaries: endpointEndpointNoneversion:13
The following analytic detects modifications to Windows accessibility binaries such as sethc.exe, utilman.exe, osk.exe, Magnify.exe, Narrator.exe, DisplaySwitch.exe, and AtBroker.exe. It leverages filesystem activity data from the Endpoint.Filesystem data model to identify changes to these specific files. This activity is significant because adversaries can exploit these binaries to gain unauthorized access or execute commands without logging in. If confirmed malicious, this could allow attackers to bypass authentication mechanisms, potentially leading to unauthorized system access and further compromise of the environment.
Print Processor Registry Autostart: endpointEndpointNoneversion:12
The following analytic detects suspicious modifications or new entries in the Print Processor registry path. It leverages registry activity data from the Endpoint data model to identify changes in the specified registry path. This activity is significant because the Print Processor registry is known to be exploited by APT groups like Turla for persistence and privilege escalation. If confirmed malicious, this could allow an attacker to execute a malicious DLL payload by restarting the spoolsv.exe process, leading to potential control over the compromised machine.
Uncommon Processes On Endpoint: endpointEndpoint2024-11-14version:7
This search looks for applications on the endpoint that you have marked as uncommon.
Windows Cloud Files Filter Log Created by Non-System Process: endpointEndpointNoneversion:1
Detects a non-system process causing creation of CldFlt0.etl under C:\Windows\System32\LogFiles\CloudFiles\.
This path is initialised by the CldFlt driver when a process calls CfRegisterSyncRoot() or CfConnectSyncRoot().
In the RedSun exploit this is a side-effect of the DoCloudStuff() function that registers a fake sync provider to create the cloud-tagged bait file.
Legitimate cloud providers (OneDrive etc.) register sync roots from SYSTEM-level service processes, not from user-context executables.
Windows Phantom DLL Created on Disk: endpointEndpointNoneversion:2
The following analytic detects creation of DLL files with names associated with phantom DLL hijacking opportunities.
These DLLs are usually absent from standard Windows installations, but legitimate Windows components or services may attempt to load them when they are present in expected search paths such as System32.
Phantom DLL hijacking involves placing a malicious DLL where a legitimate process will search for a non-existent dependency, allowing the attacker-controlled library to execute in that process context.
ShieldBreak is one example where the exploit redirects a privileged Defender-driven write into C:\Windows\System32\phoneinfo.dll and then triggers Windows Error Reporting so wermgr.exe loads the planted DLL at SYSTEM integrity.
If confirmed malicious, this activity can indicate preparation for code execution, persistence, or local privilege escalation through DLL search order hijacking.
Windows AppCertDLL Modification Via Command Line: endpointEndpointNoneversion:2
This analytic detects attempts to modify AppCertDLL registry keys via some command line utility. Values under this key are used to specify DLLs loaded by the Windows Session Manager.
Such modifications can be abused by attackers to load malicious code early in the system startup process, enabling persistent malware execution with high privileges.
If confirmed malicious, this behavior may lead to system compromise, persistence, and the evasion of security controls.
Windows Suspicious Defender Engine or Signature Files Created: endpointEndpointNoneversion:1
Detects Windows Defender engine (mpengine.dll) or signature database files (*.vdm) being created by any process that is not a Windows Defender component.
BlueHammer extracts these files from the downloaded mpam-fe update package into a UUID-named subdirectory of %TEMP% as part of staging the TOCTOU privilege escalation.
Change Default File Association: endpointEndpoint2025-02-10version:6
The following analytic has been deprecated. The following analytic detects suspicious registry modifications that change the default file association to execute a malicious payload. It leverages data from the Endpoint data model, specifically monitoring registry paths under "*\\shell\\open\\command\\*" and "*HKCR\\*". This activity is significant because altering default file associations can allow attackers to execute arbitrary scripts or payloads when a user opens a file, leading to potential code execution. If confirmed malicious, this technique can enable attackers to persist on the compromised host and execute further malicious commands, posing a severe threat to the environment.
Runas Execution in CommandLine: endpointEndpointNoneversion:10
The following analytic detects the execution of the runas.exe process with administrator user options. It leverages data from Endpoint Detection and Response (EDR) agents, focusing on command-line executions and process details. This activity is significant as it may indicate an attempt to gain elevated privileges, a common tactic in privilege escalation and lateral movement. If confirmed malicious, this could allow an attacker to execute commands with higher privileges, potentially leading to unauthorized access, data exfiltration, or further compromise of the target host.
Logon Script Event Trigger Execution: endpointEndpointNoneversion:12
The following analytic detects the modification of the UserInitMprLogonScript registry entry, which is often used by attackers to establish persistence and gain privilege escalation upon system boot. It leverages data from the Endpoint.Registry data model, focusing on changes to the specified registry path. This activity is significant because it is a common technique used by APT groups and malware to ensure their payloads execute automatically when the system starts. If confirmed malicious, this could allow attackers to maintain persistent access and potentially escalate their privileges on the compromised host.
Windows SCCM Adsource DLL Was Planted In SMS Provider Directory: endpointEndpointNoneversion:1
The following analytic detects the creation or modification of adsource.dll or other staging files with the name adsource_*.dll within the SCCM SMS Provider bin directory, consistent with exploitation of CVE-2026-47301.
This abuses a DLL side-loading vulnerability in the Microsoft Configuration Manager SMS Provider component.
An attacker can plant a malicious adsource.dll in the SCCMProvider bin\X64 path, causing the SMS Provider service to load the attacker-controlled library in a privileged context.
The presence of renamed dlls alongside adsource.dll is a strong indicator of the classic DLL hijacking pattern where the legitimate library has been renamed so the malicious replacement can proxy calls to it.
If confirmed malicious, this activity represents a privilege escalation vector that can result in SYSTEM-level code execution on any host running the SCCM SMS Provider role.
Windows Defender Intermediary Artifact Was Observed: endpointEndpointNoneversion:1
The following analytic detects creation and removal of intermediary remediation artifacts of Windows Defender, during exploitation of ShieldCrash attacks.
Exploit abuses the race condition between file validation and its remediation performed by Windows Defender. In between these steps, ShieldCrash changes the
symbolic link to redirect the remediation process to a staging directory controlled by the attacker. This detection aims to detect creation of defender artifact,
its alternate data stream, and their subsequent removal.
Windows AppCertDLL Modification Via Registry: endpointEndpointNoneversion:1
This analytic detects attempts to modify AppCertDLL registry entries.
Values under this registry entry are used to specify DLLs loaded by the Windows Session Manager.
Such modifications can be abused by attackers to load malicious code early in the system startup process, enabling persistent malware execution with high privileges.
If confirmed malicious, this behavior may lead to system compromise, persistence, and the evasion of security controls.
Screensaver Event Trigger Execution: endpointEndpointNoneversion:11
The following analytic detects modifications to the SCRNSAVE.EXE registry entry, indicating potential event trigger execution via screensaver settings for persistence or privilege escalation. It leverages registry activity data from the Endpoint data model to identify changes to the specified registry path. This activity is significant as it is a known technique used by APT groups and malware to maintain persistence or escalate privileges. If confirmed malicious, this could allow an attacker to execute arbitrary code with elevated privileges, leading to further system compromise and persistent access.
Windows Privilege Escalation System Process Without System Parent: endpointEndpointNoneversion:10
The following analytic detects any system integrity level process spawned by a non-system account. It leverages Sysmon EventID 1, focusing on process integrity and parent user data. This behavior is significant as it often indicates successful privilege escalation to SYSTEM from a user-controlled process or service. If confirmed malicious, this activity could allow an attacker to gain full control over the system, execute arbitrary code, and potentially compromise the entire environment.
Time Provider Persistence Registry: endpointEndpointNoneversion:16
The following analytic detects suspicious modifications to the time provider registry for persistence and autostart. It leverages data from the Endpoint.Registry data model, focusing on changes to the "CurrentControlSet\\Services\\W32Time\\TimeProviders" registry path.
This activity is significant because such modifications are uncommon and can indicate an attempt to establish persistence on a compromised host.
If confirmed malicious, this technique allows an attacker to maintain access and execute code automatically upon system boot, potentially leading to further exploitation and control over the affected system.
Kerberoasting spn request with RC4 encryption: endpointEndpointNoneversion:15
The following analytic detects potential Kerberoasting attacks by identifying Kerberos service ticket requests with RC4 encryption through Event ID 4769. It leverages specific Ticket_Options values commonly used by Kerberoasting tools. This activity is significant as Kerberoasting allows attackers to request service tickets for domain accounts, typically service accounts, and crack them offline to gain privileged access. If confirmed malicious, this could lead to unauthorized access, privilege escalation, and further compromise of the Active Directory environment.
Windows Suspicious Child Process of TieringEngineService.exe: endpointEndpointNoneversion:1
Detects the RedSun privilege escalation exploit delivering a SYSTEM-level shell to the attacker's session.
RedSun replaces the legitimate TieringEngineService.exe with a malicious binary, which launches a process as SYSTEM, usually some sort of shell or shell spawner (conhost.exe, cmd.exe, PowerShell, etc.) in the attacker's active session.
Windows Privilege Escalation Suspicious Process Elevation: endpointEndpointNoneversion:12
The following analytic detects when a process running with low or medium integrity from a user account spawns an elevated process with high or system integrity in suspicious locations.
This behavior is identified using process execution data from Windows process monitoring.
This activity is significant as it may indicate a threat actor successfully elevating privileges, which is a common tactic in advanced attacks.
If confirmed malicious, this could allow the attacker to execute code with higher privileges, potentially leading to full system compromise and persistent access.
Windows Admin Password Changed by Non-Admin: endpointEndpointNoneversion:2
The following analytic detects when a unprivileged user changes an Admin accounts password. This is a common artifact of successful exploitation of the BlueHammer Windows Defender privilege escalation. The attacker's process momentarily changes the passwords of high-value local accounts including the built-in Administrator to spawn an authenticated shell session, then immediately reverts the passwords to avoid detection. This uses EventID 4723 to log this activity.
Windows MSI Rollback Script Deleted By Non-Msiexec Process: endpointEndpointNoneversion:3
Detects deletion of a Rollback Script (.rbs) file under C:\Config.Msi, the critical filesystem manipulation step in an MSI Rollback privilege escalation attack that converts an arbitrary file delete primitive into full SYSTEM code execution.
During a legitimate MSI installation, the Windows Installer service (running as SYSTEM) creates C:\Config.Msi and populates it with a Rollback Script (.rbs) and Rollback File (.rbf).
These files define exactly how to restore the system to its pre-installation state if the install fails.
The folder is protected with a strong DACL specifically to prevent tampering by low-privileged users — because whatever is in these files will be executed by the SYSTEM-level Installer service during rollback.
Windows SCCM Smsexec Spawned a Suspicious Child Process: endpointEndpointNoneversion:1
The following analytic detects shells, scripting engines, and common post-exploitation utilities spawned as child processes of smsexec.exe.
smsexec.exe is the core SCCM SMS Executive service process and has no legitimate reason to launch interactive shells or scripting interpreters.
An attacker who plants a malicious adsource.dll in the SCCMProvider bin\X64 directory will obtain code execution in the SCCM service context, typically resulting in a SYSTEM-level child process being spawned under smsexec.exe.
If confirmed malicious, this activity represents successful exploitation of the SCCM SMS Executive service and should be treated as a full host compromise.
Windows New Default File Association Value Set: endpointEndpointNoneversion:5
The following analytic detects registry changes to the default file association value. It leverages data from the Endpoint data model, specifically monitoring registry paths under "HKCR\\*\\shell\\open\\command\\*". This activity can be significant because, attackers might alter the default file associations in order to execute arbitrary scripts or payloads when a user opens a file, leading to potential code execution. If confirmed malicious, this technique can enable attackers to persist on the compromised host and execute further malicious commands, posing a severe threat to the environment.
Windows Suspicious Child Process of Consent.EXE: endpointEndpointNoneversion:1
The following analytic detects unexpected child processes spawned by consent.exe, the Windows UAC consent dialog binary.
Consent.exe is responsible solely for rendering the UAC elevation prompt and should not spawn child processes under normal operating conditions; child process creation from this parent is a known indicator of UAC bypass and privilege escalation techniques.
The detection identifies any executable launched as a child of consent.exe, excluding the expected WerFault.exe error reporting process, which may legitimately appear in crash scenarios.
This behavior is associated with UAC bypass exploits and has been observed in multiple post-exploitation frameworks as a means of obtaining elevated privileges without triggering a visible UAC prompt.
ETW Registry Disabled: endpointEndpointNoneversion:18
The following analytic detects a registry modification that disables the ETW for the .NET Framework. It leverages data from the Endpoint.Registry data model, specifically monitoring changes to the ETWEnabled registry value under the .NETFramework path. This activity is significant because disabling ETW can allow attackers to evade Endpoint Detection and Response (EDR) tools and hide their execution from audit logs. If confirmed malicious, this action could enable attackers to operate undetected, potentially leading to further compromise and persistent access within the environment.
Windows Non-System Process Querying Definition Update: endpointEndpointNoneversion:1
Detects DNS queries to definitionupdates.microsoft.com or the go.microsoft.com fwlink redirect used for WD update downloads, when the querying process is not a Windows system component. BlueHammer utilizes these definition updates as part of its exploit chain.
Child Processes of Spoolsv exe: endpointEndpointNoneversion:12
The following analytic identifies child processes spawned by spoolsv.exe, the Print Spooler service in Windows, which typically runs with SYSTEM privileges. This detection leverages data from Endpoint Detection and Response (EDR) agents, focusing on process and parent process relationships. Monitoring this activity is crucial as it can indicate exploitation attempts, such as those associated with CVE-2018-8440, which can lead to privilege escalation. If confirmed malicious, attackers could gain SYSTEM-level access, allowing them to execute arbitrary code, escalate privileges, and potentially compromise the entire system.
Windows Error Report Created in ReportQueue Manually: endpointEndpointNoneversion:1
The following analytic detects a .wer file being written into the Windows Error Reporting ReportQueue directory by a process other than the standard error-reporting binaries.
Windows Error Reporting normally populates ReportQueue only through werfault.exe, werfaultsecure.exe, or wermgr.exe following an actual application crash.
In the ShieldBreak exploit, the attacker fabricates a .wer report directly and manually invokes the QueueReporting scheduled task, which causes wermgr.exe to process the report and load an attacker-planted phantom DLL at SYSTEM integrity.
If confirmed malicious, this activity indicates preparation for a local privilege escalation attempt abusing Windows Error Reporting.
Windows Privilege Escalation User Process Spawn System Process: endpointEndpointNoneversion:13
The following analytic detects when a process with low, medium, or high integrity spawns a system integrity process from a user-controlled location.
This behavior is indicative of privilege escalation attempts where attackers elevate their privileges to SYSTEM level from a user-controlled process or service.
The detection leverages Sysmon data, specifically Event ID 15, to identify such transitions.
Monitoring this activity is crucial as it can signify an attacker gaining SYSTEM-level access, potentially leading to full control over the affected system, unauthorized access to sensitive data, and further malicious activities.
Registry Keys Used For Privilege Escalation: endpointEndpointNoneversion:17
The following analytic detects modifications to registry keys under "Image File Execution Options" that can be used for privilege escalation. It leverages data from the Endpoint.Registry data model, specifically monitoring changes to registry paths and values like GlobalFlag and Debugger. This activity is significant because attackers can use these modifications to intercept executable calls and attach malicious binaries to legitimate system binaries. If confirmed malicious, this could allow attackers to execute arbitrary code with elevated privileges, leading to potential system compromise and persistent access.
MSI Module Loaded by Non-System Binary: endpointEndpointNoneversion:10
The following analytic detects the loading of `msi.dll` by a binary not located in `system32`, `syswow64`, `winsxs`, or `windows` directories. This is identified using Sysmon EventCode 7, which logs DLL loads, and filters out legitimate system paths. This activity is significant as it may indicate exploitation of CVE-2021-41379 or DLL side-loading attacks, both of which can lead to unauthorized system modifications. If confirmed malicious, this could allow an attacker to execute arbitrary code, escalate privileges, or persist within the environment.
Windows Potato Privilege Escalation Tool Execution: endpointEndpointNoneversion:2
Detects execution of known Potato-family privilege escalation tools based on original file name, process name, or binary path.
A tool class that has been a dominant post-compromise privilege escalation method for over a decade and remains actively used by ransomware operators, red teams, and nation-state actors alike.
The Potato family exploits Windows token impersonation and privilege abuse to escalate from a service account, IIS worker process, or other restricted context to SYSTEM.
The core abuse chain across most variants involves tricking a SYSTEM-level process into authenticating to an attacker-controlled endpoint, capturing that authentication, and impersonating the resulting SYSTEM token to spawn an elevated process.
Windows Wermgr Spawning System Integrity Process: endpointEndpointNoneversion:1
The following analytic detects WerMgr.exe (Windows Error Reporting) spawning a child process running at SYSTEM integrity level.
WerMgr.exe normally runs at the integrity level of the reporting user or as a background SYSTEM-owned service that does not launch interactive children.
In the ShieldBreak exploit, WerMgr.exe is manually triggered via the QueueReporting scheduled task and loads an attacker-planted phantom DLL (phoneinfo.dll), which then spawns an elevated shell.
If confirmed malicious, this activity indicates successful local privilege escalation to SYSTEM.
Windows MsMpEng Writing to System32: endpointEndpointNoneversion:1
Detects MsMpEng.exe creating a file in C:\\Windows\\System32\\.
This should never happen under normal operation Windows Defender does not install kernel drivers at runtime.
In the BlueHammer exploit, the TOCTOU race causes MsMpEng (SYSTEM) to write the attacker's driver payload directly into the drivers directory.
Windows Mock Trusted Directory MSC File Creation: endpointEndpointNoneversion:2
Detects the creation of MSC files within a "C:\Windows \System32" directory.
Due to how Windows parses paths, the space causes an execution flow hijack and a malicious file will be executed instead of the standard Windows Files.
Windows SymbolicLink-Testing-Tools Utility Execution: endpointEndpointNoneversion:2
Detects the execution of tools from the `symboliclink-testing-tools` toolkit.
This toolkit is often used for exploiting Windows symbolic link, junction, and oplock vulnerabilities to achieve local privilege escalation from a standard user to SYSTEM.
Symbolic link attacks against Windows exploit a class of logical vulnerability where a SYSTEM or administrator-level process performs a file operation on a path that a low-privileged attacker can redirect using a combination of NTFS junctions, object manager symbolic links, and opportunistic locks (oplocks).
By chaining these primitives a standard user can redirect a privileged file write, delete, or read to an arbitrary path, effectively turning a narrow file operation vulnerability into arbitrary write or code execution as SYSTEM.
Windows Privilege Escalation Attempt Via MSI Rollback: endpointEndpointNoneversion:2
Detects an attacker abusing the Windows Installer rollback mechanism to escalate privileges from a standard user to SYSTEM without triggering a UAC prompt, using a technique known as FolderContentsDeleteToFolderDelete.
Windows Installer (msiexec.exe) creates rollback scripts during software installation to undo changes if an installation fails.
These rollback scripts are generated and executed by the Windows Installer service, which runs as SYSTEM.
The FolderContentsDeleteToFolderDelete technique abuses this trusted mechanism by crafting a malicious rollback script that instructs the SYSTEM-level Installer service to delete attacker-chosen files or directories — effectively giving a low-privileged attacker the ability to make SYSTEM-level filesystem modifications without any privilege prompt.
Active Setup Registry Autostart: endpointEndpointNoneversion:14
The following analytic detects suspicious modifications to the Active Setup registry for persistence and privilege escalation. It leverages data from the Endpoint.Registry data model, focusing on changes to the "StubPath" value within the "SOFTWARE\\Microsoft\\Active Setup\\Installed Components" path. This activity is significant as it is commonly used by malware, adware, and APTs to maintain persistence on compromised machines. If confirmed malicious, this could allow attackers to execute code upon system startup, potentially leading to further system compromise and unauthorized access.