Detection rules › Sigma

Uncommon Svchost Parent Process

Status
test
Severity
medium
Log source
product windows, category process_creation
Author
Florian Roth (Nextron Systems)
Source
github.com/SigmaHQ/sigma

Detects an uncommon svchost parent process

MITRE ATT&CK coverage

Event coverage

Rule body yaml

title: Uncommon Svchost Parent Process
id: 01d2e2a1-5f09-44f7-9fc1-24faa7479b6d
status: test
description: Detects an uncommon svchost parent process
references:
    - Internal Research
author: Florian Roth (Nextron Systems)
date: 2017-08-15
modified: 2022-06-28
tags:
    - attack.stealth
    - attack.t1036.005
logsource:
    category: process_creation
    product: windows
detection:
    selection:
        Image|endswith: '\svchost.exe'
    filter_main_generic:
        ParentImage|endswith:
            - '\Mrt.exe'
            - '\MsMpEng.exe'
            - '\ngen.exe'
            - '\rpcnet.exe'
            - '\services.exe'
            - '\TiWorker.exe'
    filter_main_parent_null:
        ParentImage: null
    filter_main_parent_empty:
        ParentImage:
            - '-'
            - ''
    condition: selection and not 1 of filter_main_*
falsepositives:
    - Unknown
level: medium

Stages and Predicates

Stage 0: condition

selection and not 1 of filter_main_*

Stage 1: selection

selection:
    Image|endswith: '\svchost.exe'

Stage 2: not filter_main_*

filter_main_generic:
    ParentImage|endswith:
        - '\Mrt.exe'
        - '\MsMpEng.exe'
        - '\ngen.exe'
        - '\rpcnet.exe'
        - '\services.exe'
        - '\TiWorker.exe'
filter_main_parent_null:
    ParentImage: null
filter_main_parent_empty:
    ParentImage:
        - '-'
        - ''

Exclusions

Top-level NOT(...) conjuncts: predicates this rule actively suppresses.

FieldKindExcluded values
ParentImageends_with\Mrt.exe
ParentImageends_with\MsMpEng.exe
ParentImageends_with\TiWorker.exe
ParentImageends_with\ngen.exe
ParentImageends_with\rpcnet.exe
ParentImageends_with\services.exe
ParentImageeq-
ParentImageis_null(no value, null check)

Indicators

Each row is a field, operator, and value that the rule matches. The corpus column counts how many other rules in the catalog look for the same combination: high numbers point to widely-used, community-vetted indicators. Blank or 1 shows that the indicator is specific to this rule.

FieldKindValues
Imageends_with
  • \svchost.exe corpus 23 (sigma 23)