Uncommon Child Process Of AddinUtil.EXE
Description
Detects uncommon child processes of the Add-In deployment cache updating utility (AddInutil.exe) which could be a sign of potential abuse of the binary to proxy execution via a custom Addins.Store payload.
Query · sigma
selection: ParentImage|endswith: \addinutil.exe filter_main_werfault: Image|endswith: - :\Windows\System32\conhost.exe - :\Windows\System32\werfault.exe - :\Windows\SysWOW64\werfault.exe condition: selection and not 1 of filter_main_*
Known false positives
- Unknown