Conhost Spawned By Uncommon Parent Process
Description
Detects when the Console Window Host (conhost.exe) process is spawned by an uncommon parent process, which could be indicative of potential code injection activity.
Query · sigma
selection: Image|endswith: \conhost.exe ParentImage|endswith: - \explorer.exe - \lsass.exe - \regsvr32.exe - \rundll32.exe - \services.exe - \smss.exe - \spoolsv.exe - \svchost.exe - \userinit.exe - \wininit.exe - \winlogon.exe filter_main_svchost: ParentCommandLine|contains: - -k apphost -s AppHostSvc - -k imgsvc - -k localService -p -s RemoteRegistry - -k LocalSystemNetworkRestricted -p -s NgcSvc - -k NetSvcs -p -s NcaSvc - -k netsvcs -p -s NetSetupSvc - -k netsvcs -p -s wlidsvc - -k NetworkService -p -s DoSvc - -k wsappx -p -s AppXSvc - -k wsappx -p -s ClipSVC - -k wusvcs -p -s WaaSMedicSvc filter_optional_dropbox: ParentCommandLine|contains: - C:\Program Files (x86)\Dropbox\Client\ - C:\Program Files\Dropbox\Client\ condition: selection and not 1 of filter_main_* and not 1 of filter_optional_*
Known false positives
- Unknown