Monitoring Anomalous Child Processes Spawned by Zoom
Detection of previously unseen child processes spawned by Zoom clients may indicate exploitation of the application for code execution or unauthorized system access.
This detection focuses on identifying the first-time execution of child processes spawned by legitimate Zoom client binaries (zoom.exe or zoom.us). Communication software is a frequent target for attackers looking to leverage legitimate application trust to execute secondary payloads, conduct reconnaissance, or facilitate data exfiltration. By establishing a behavioral baseline of known child processes for Zoom on a per-host basis, security teams can alert on deviations that may indicate malicious activity. Monitoring this parent-child process relationship is critical, as Zoom should rarely spawn system-level binaries, shells, or unusual utilities during normal operation. This analytic helps defenders identify potentially compromised endpoints where the Zoom client has been subverted to perform unauthorized actions.
Impact
Successful exploitation of this vector can lead to unauthorized code execution with the permissions of the Zoom process, potentially resulting in full endpoint compromise, lateral movement, or data exfiltration. Because this detection identifies anomalous activity, it serves as an early indicator of potential intrusion rather than confirmation of breach, requiring timely investigation to distinguish between benign software updates/plugins and malicious activity.
Recommendation
Deploy the provided Sigma rule to your SIEM environment to monitor for unknown Zoom child processes. Ensure that Endpoint Detection and Response (EDR) telemetry is correctly mapped to the process_creation log source and that command-line logging is enabled to facilitate the inspection of arguments passed to child processes. Given the experimental nature of this detection, it is recommended to tune the alerts by reviewing initial baselines for common legitimate child processes and suppressing them accordingly. Use the identified suspicious process parent-child relationships to initiate threat hunting activities focused on verifying the legitimacy of the spawned process and its associated command-line arguments.
Threat Hunt
Analyze all child processes of Zoom for the last 30 days to identify baseline behavior.
Data: Process creation logs with parent-child relationships.
Mitigations
Maintain strict application control policies to ensure only authorized binaries can be executed, even if spawned by legitimate software.
General exploitation risk of application subversion
Detection coverage 1
Detect Previously Unseen Child Processes of Zoom
mediumDetects the initiation of a child process by Zoom that has not been observed on the specific host previously.
Detection queries are available on the platform. Get full rules →