Suspicious Spool Service Child Process
Description
Detects suspicious print spool service (spoolsv.exe) child processes.
Query · sigma
spoolsv: ParentImage|endswith: \spoolsv.exe IntegrityLevel: - System - S-1-16-16384 suspicious_unrestricted: Image|endswith: - \gpupdate.exe - \whoami.exe - \nltest.exe - \taskkill.exe - \wmic.exe - \taskmgr.exe - \sc.exe - \findstr.exe - \curl.exe - \wget.exe - \certutil.exe - \bitsadmin.exe - \accesschk.exe - \wevtutil.exe - \bcdedit.exe - \fsutil.exe - \cipher.exe - \schtasks.exe - \write.exe - \wuauclt.exe - \systeminfo.exe - \reg.exe - \query.exe suspicious_net: Image|endswith: - \net.exe - \net1.exe suspicious_net_filter: CommandLine|contains: start suspicious_cmd: Image|endswith: \cmd.exe suspicious_cmd_filter: CommandLine|contains: - .spl - route add - program files suspicious_netsh: Image|endswith: \netsh.exe suspicious_netsh_filter: CommandLine|contains: - add portopening - rule name suspicious_powershell: Image|endswith: - \powershell.exe - \pwsh.exe suspicious_powershell_filter: CommandLine|contains: .spl suspicious_rundll32_img: - Image|endswith: \rundll32.exe - OriginalFileName: RUNDLL32.EXE suspicious_rundll32_cli: CommandLine|endswith: rundll32.exe condition: spoolsv and ( suspicious_unrestricted or (suspicious_net and not suspicious_net_filter) or (suspicious_cmd and not suspicious_cmd_filter) or (suspicious_netsh and not suspicious_netsh_filter) or (suspicious_powershell and not suspicious_powershell_filter) or all of suspicious_rundll32_* )
Known false positives
- Unknown