Detection rules › Sigma

Sysinternals PsSuspend Suspicious Execution

Status
test
Severity
high
Log source
category process_creation, product windows
Author
Nasreddine Bencherchali (Nextron Systems)
Source
github.com/SigmaHQ/sigma

Detects suspicious execution of Sysinternals PsSuspend, where the utility is used to suspend critical processes such as AV or EDR to bypass defenses

Known false positives

  • Unlikely

MITRE ATT&CK coverage

TacticTechniques
Defense Impairment

Telemetry coverage

ProviderRecord / event type
SysmonEvent ID 1: Process creation

Rule body

title: Sysinternals PsSuspend Suspicious Execution
id: 4beb6ae0-f85b-41e2-8f18-8668abc8af78
related:
    - id: 48bbc537-b652-4b4e-bd1d-281172df448f # Basic Execution
      type: similar
status: test
description: Detects suspicious execution of Sysinternals PsSuspend, where the utility is used to suspend critical processes such as AV or EDR to bypass defenses
references:
    - https://learn.microsoft.com/en-us/sysinternals/downloads/pssuspend
    - https://twitter.com/0gtweet/status/1638069413717975046
author: Nasreddine Bencherchali (Nextron Systems)
date: 2023-03-23
modified: 2026-06-29
tags:
    - attack.defense-impairment
    - attack.t1685
logsource:
    category: process_creation
    product: windows
detection:
    selection_img:
        - OriginalFileName: 'pssuspend.exe'
        - Image|endswith:
              - '\pssuspend.exe'
              - '\pssuspend64.exe'
              - '\pssuspend64a.exe'
    selection_cli:
        # Add more interesting/critical processes
        CommandLine|contains: 'msmpeng.exe'
    condition: all of selection_*
falsepositives:
    - Unlikely
level: high

Stages and Predicates

Stage 0: condition

all of selection_*

Stage 1: selection_img

selection_img:
    - OriginalFileName: 'pssuspend.exe'
    - Image|endswith:
          - '\pssuspend.exe'
          - '\pssuspend64.exe'
          - '\pssuspend64a.exe'

Stage 2: selection_cli

selection_cli:
    CommandLine|contains: 'msmpeng.exe'

Indicators

These rows show field, operator, and value matches.

FieldKindValuesSearch
CommandLinematch
  • msmpeng.exe
field:"CommandLine" kind:match value:"msmpeng.exe"
Imageends_with
  • \pssuspend.exe corpus 3 (sigma 3)
  • \pssuspend64.exe corpus 3 (sigma 3)
  • \pssuspend64a.exe corpus 3 (sigma 3)
field:"Image" kind:ends_with
OriginalFileNameeq
  • pssuspend.exe corpus 2 (sigma 2)
field:"OriginalFileName" kind:eq value:"pssuspend.exe"