{"id":"66d31e5f-52d6-40a4-9615-002d3789a119","title":"Remote Thread Creation By Uncommon Source Image","description":"Detects uncommon processes creating remote threads.","author":"Perez Diego (@darkquassar), oscd.community","status":"test","level":"medium","date":"2019-10-27","modified":"2025-07-08","tags":["attack.privilege-escalation","attack.stealth","attack.t1055"],"technique_ids":["T1055"],"logsource":{"product":"windows","category":"create_remote_thread"},"falsepositives":["This rule is best put in testing first in order to create a baseline that reflects the data in your environment."],"references":["Personal research, statistical analysis","https://lolbas-project.github.io"],"source_path":"rules/windows/create_remote_thread/create_remote_thread_win_susp_uncommon_source_image.yml","source_sha256":"4c8698c874eb4d9efad1fa20ce8df7bb99f5410295517e00b04a274eb236d6a2","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/windows/create_remote_thread/create_remote_thread_win_susp_uncommon_source_image.yml","license":"Detection Rule License 1.1","license_url":"https://github.com/SigmaHQ/Detection-Rule-License/blob/main/LICENSE.Detection.Rules.md","yaml":"title: Remote Thread Creation By Uncommon Source Image\nid: 66d31e5f-52d6-40a4-9615-002d3789a119\nrelated:\n    - id: 02d1d718-dd13-41af-989d-ea85c7fab93f\n      type: derived\nstatus: test\ndescription: Detects uncommon processes creating remote threads.\nreferences:\n    - Personal research, statistical analysis\n    - https://lolbas-project.github.io\nauthor: Perez Diego (@darkquassar), oscd.community\ndate: 2019-10-27\nmodified: 2025-07-08\ntags:\n    - attack.privilege-escalation\n    - attack.stealth\n    - attack.t1055\nlogsource:\n    product: windows\n    category: create_remote_thread\ndetection:\n    selection:\n        SourceImage|endswith:\n            - '\\explorer.exe'\n            - '\\iexplore.exe'\n            - '\\msiexec.exe'\n            - '\\powerpnt.exe'\n            - '\\schtasks.exe'\n            - '\\winlogon.exe'\n    filter_main_winlogon_1:\n        SourceImage: 'C:\\Windows\\System32\\winlogon.exe'\n        TargetImage:\n            - 'C:\\Windows\\System32\\services.exe' # happens on Windows 7\n            - 'C:\\Windows\\System32\\wininit.exe' # happens on Windows 7\n            - 'C:\\Windows\\System32\\csrss.exe' # multiple OS\n            - 'C:\\Windows\\System32\\LogonUI.exe' # multiple OS\n            - 'C:\\Windows\\System32\\wlrmdr.exe'\n            - 'C:\\Windows\\System32\\AtBroker.exe'\n            - 'C:\\Windows\\System32\\dwm.exe'\n            - 'C:\\Windows\\System32\\fontdrvhost.exe'\n            - 'C:\\Windows\\System32\\userinit.exe'\n    filter_main_winlogon_2:\n        SourceImage: 'C:\\Windows\\System32\\winlogon.exe'\n        TargetParentProcessId: 4\n    filter_main_schtasks_conhost:\n        SourceImage:\n            - 'C:\\Windows\\System32\\schtasks.exe'\n            - 'C:\\Windows\\SysWOW64\\schtasks.exe'\n        TargetImage: 'C:\\Windows\\System32\\conhost.exe'\n    filter_main_explorer:\n        SourceImage: 'C:\\Windows\\explorer.exe'\n        TargetImage|startswith:\n            - 'C:\\Program Files (x86)\\'\n            - 'C:\\Program Files\\'\n            - 'C:\\Windows\\System32\\'\n            - 'C:\\Windows\\SysWOW64\\'\n    filter_main_system:\n        TargetImage: 'System'\n    filter_main_msiexec_1:\n        # Note: MSI installers will trigger this\n        SourceImage|endswith: '\\msiexec.exe'\n        TargetImage|contains:\n            - '\\AppData\\Local\\'\n            - 'C:\\Program Files (x86)\\'\n            - 'C:\\Program Files\\'\n            - 'C:\\Windows\\Microsoft.NET\\Framework64\\' # C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\n    filter_main_msiexec_2:\n        SourceImage|endswith: '\\msiexec.exe'\n        TargetImage:\n            - 'C:\\Windows\\System32\\msiexec.exe'\n            - 'C:\\Windows\\SysWOW64\\msiexec.exe'\n    filter_main_iexplore:\n        SourceImage: 'C:\\Program Files\\Internet Explorer\\iexplore.exe'\n        TargetImage:\n            - 'C:\\Program Files (x86)\\Internet Explorer\\iexplore.exe'\n            - 'C:\\Windows\\System32\\rundll32.exe'\n    filter_main_powerpnt:\n        SourceImage|endswith: '\\POWERPNT.EXE'\n        TargetImage|contains:\n            - 'C:\\Program Files\\Microsoft Office\\' # C:\\Program Files\\Microsoft Office\\root\\vfs\\ProgramFilesCommonX64\\Microsoft Shared\\Office16\\AI\\ai.exe\n            - 'C:\\Program Files (x86)\\Microsoft Office\\'\n    filter_optional_aurora_smartconsole1:\n        SourceImage: 'C:\\Program Files\\internet explorer\\iexplore.exe'\n        SourceCommandLine|contains|all:\n            - 'https://'\n            - '.checkpoint.com/documents/'\n            - 'SmartConsole_OLH/'\n            - 'default.htm#cshid='\n    filter_optional_aurora_smartconsole2:\n        SourceImage: 'C:\\Program Files\\internet explorer\\iexplore.exe'\n        SourceParentImage|startswith:\n            - 'C:\\Program Files\\'\n            - 'C:\\Program Files (x86)\\'\n        SourceParentImage|contains|all:\n            - '\\CheckPoint\\SmartConsole\\'\n            - '\\SmartConsole.exe'\n    filter_optional_powerpnt:\n        # Raised by the following issue: https://github.com/SigmaHQ/sigma/issues/2479\n        SourceImage|contains: '\\Microsoft Office\\'\n        SourceImage|endswith: '\\POWERPNT.EXE'\n        TargetImage: 'C:\\Windows\\System32\\csrss.exe'\n    filter_main_null:\n        TargetImage: null\n    filter_main_empty:\n        TargetImage: ''\n    filter_optional_onedrive:\n        SourceImage: 'C:\\Windows\\explorer.exe'\n        TargetImage|endswith: '\\AppData\\Local\\Microsoft\\OneDrive\\OneDrive.exe'\n    filter_optional_aurora:\n        SourceImage: 'C:\\Windows\\explorer.exe'\n        TargetImage|endswith: '\\aurora-dashboard.exe'\n    filter_optional_officesetup:\n        SourceImage: 'C:\\Windows\\explorer.exe'\n        TargetImage|endswith: '\\OfficeSetup.exe'\n    condition: selection and not 1 of filter_main_* and not 1 of filter_optional_*\nfalsepositives:\n    - This rule is best put in testing first in order to create a baseline that reflects the data in your environment.\nlevel: medium\n","validation":"yaml_parsed_not_backend_compiled_or_live_validated","techniques":[{"key":"enterprise/T1055","id":"T1055","name":"Process Injection","page":"techniques/enterprise/T1055/"}],"data_path":"data/detection-rules/66d31e5f-52d6-40a4-9615-002d3789a119.json","kind":"sigma"}
