Skip to content
Threat Feed

Tag

Process-Creation

6 briefs RSS
medium advisory

Suspicious Rundll32 Proxy Execution Patterns

This brief documents common LOLBIN usage of rundll32.exe to execute arbitrary code or bypass security controls through legitimate Windows DLLs.

stealth lolbin windows process-creation
1r 1t
medium advisory

Suspicious Cross-User Process Spawning Behavior

Detection of common user-space applications being spawned under different user contexts, which often indicates privilege escalation testing or sacrificial process execution.

privilege-escalation stealth windows process-creation
1r 2t
medium advisory

Registry Manipulation via WMI Stdregprov for Evasion

Attackers are leveraging `wmic.exe` to modify the Windows registry through the WMI `StdRegProv` class, specifically using methods like `CreateKey` and `SetStringValue`, to evade detection and bypass traditional security monitoring focused on `reg.exe` or `regedit.exe`.

registry-modification defense-evasion wmi windows process-creation
1r 3t
high advisory

Potential Defense Evasion Via Rename Of Highly Relevant Binaries

This brief details a defense evasion technique where attackers rename legitimate Windows system binaries to mask malicious activity, bypassing security solutions that rely on process names for detection.

defense-evasion windows process-creation
1r 1t
high advisory

HTML Help Executable Spawning Child Processes

The execution of hh.exe (HTML Help) spawning a child process indicates the use of a Compiled HTML Help (CHM) file to execute potentially malicious Windows script code.

Microsoft Windows html-help chm lolbas process-creation
2r 1t
high advisory

Suspicious Microsoft HTML Application Child Process

Mshta.exe spawning a suspicious child process, such as cmd.exe or powershell.exe, indicates potential adversarial activity leveraging Mshta to execute malicious scripts and evade detection on Windows systems.

Windows +2 defense-evasion mshta process-creation
2r 1t