Windows Server Update Service Spawning Suspicious Processes

Identifies suspicious processes being spawned by the Windows Server Update Service. This activity may indicate exploitation activity or access to an existing web shell backdoor.

Elastic rule (View on GitHub)

  1[metadata]
  2creation_date = "2025/10/24"
  3integration = ["endpoint", "windows", "m365_defender", "sentinel_one_cloud_funnel"]
  4maturity = "production"
  5updated_date = "2026/09/18"
  6
  7[rule]
  8author = ["Elastic"]
  9description = """
 10Identifies suspicious processes being spawned by the Windows Server Update Service.
 11This activity may indicate exploitation activity or access to an existing web shell backdoor.
 12"""
 13from = "now-9m"
 14index = [
 15    "logs-endpoint.events.process-*",
 16    "winlogbeat-*",
 17    "logs-windows.sysmon_operational-*",
 18    "endgame-*",
 19    "logs-m365_defender.event-*",
 20    "logs-sentinel_one_cloud_funnel.*",
 21]
 22language = "eql"
 23license = "Elastic License v2"
 24name = "Windows Server Update Service Spawning Suspicious Processes"
 25references = [
 26    "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-59287",
 27    "https://hawktrace.com/blog/CVE-2025-59287"
 28]
 29risk_score = 73
 30rule_id = "1ac027c2-8c60-4715-af73-927b9c219e20"
 31severity = "high"
 32tags = [
 33    "Domain: Endpoint",
 34    "OS: Windows",
 35    "Use Case: Threat Detection",
 36    "Tactic: Initial Access",
 37    "Data Source: Elastic Endgame",
 38    "Data Source: Elastic Defend",
 39    "Data Source: Sysmon",
 40    "Data Source: Microsoft Defender XDR",
 41    "Data Source: SentinelOne",
 42    "Resources: Investigation Guide",
 43    "Noise: Low",
 44    "Performance: Normal",
 45    "Profile: Recommended",
 46    "Threat: Living off the Land",
 47    "Threat: Web Shell",
 48    "Rule Type: Event Correlation (EQL)",
 49    "Platform: Windows",
 50]
 51timestamp_override = "event.ingested"
 52type = "eql"
 53
 54query = '''
 55process where host.os.type == "windows" and event.type == "start" and
 56  process.name : ("cmd.exe", "powershell.exe", "pwsh.exe", "powershell_ise.exe", "rundll32.exe", "curl.exe") and
 57  (
 58   (process.parent.name : "w3wp.exe" and process.parent.args : "WsusPool") or
 59   process.parent.name : "WsusService.exe"
 60   )
 61'''
 62
 63note = """## Triage and analysis
 64
 65### Investigating Windows Server Update Service Spawning Suspicious Processes
 66
 67#### Possible investigation steps
 68
 69- What does the alert-local WSUS parent-child path show?
 70  - Focus: child `process.executable` and `process.command_line`, plus `process.parent.name`, `process.parent.executable`, and `process.parent.args`, especially "w3wp.exe" with "WsusPool" or "WsusService.exe".
 71  - Implication: escalate when a WSUS web or service component launches a shell, PowerShell, "rundll32.exe", or "curl.exe" for interpreter, download, or proxy-execution behavior; lower suspicion only when the parent-child pair and arguments match a narrow recognized WSUS setup, cleanup, or repair pattern.
 72- Does the child command and binary identity fit bounded WSUS maintenance?
 73  - Why: WSUS children can inherit service context; visible user fields may not prove human initiation.
 74  - Focus: `process.command_line`, `process.executable`, `process.pe.original_file_name`, `process.code_signature.subject_name`/`trusted`, and child processes. $investigate_1
 75  - Hint: for PowerShell with script-block telemetry, anchor on `host.id` + `process.entity_id` or `host.id` + `process.pid` in a tight alert window. Reconstruct `powershell.file.script_block_id`, `powershell.total`, `powershell.sequence`, and `powershell.file.script_block_text`; missing script-block telemetry is unresolved, not benign.
 76  - Implication: escalate on encoded script content, external retrieval, discovery, archive, remote-admin, temp-path DLL activity, or a renamed/unsigned/mismatched child; lower suspicion only when command scope, path, PE identity, and signer all match the same narrow WSUS task. Identity alone does not clear the launch chain.
 77- Did the child stage payloads or WSUS-content artifacts?
 78  - Focus: process-scoped file `file.path`, `file.Ext.original.path`, `file.origin_url`, and `file.Ext.windows.zone_identifier`; missing file telemetry is unresolved, not benign. $investigate_2
 79  - Hint: scope by `host.id` + `process.entity_id`, or `host.id` + `process.pid` if absent; check later starts where `process.executable` equals the written path.
 80  - Implication: escalate when the child writes scripts, DLLs, EXEs, archives, or renamed content under WSUS, IIS, temp, or user-writable paths, especially if later executed; lower suspicion only when writes stay inside the same narrow WSUS maintenance path.
 81- Did the child retrieve tooling, call back, or reach destinations outside the WSUS role?
 82  - Focus: process-scoped DNS `event.action`, `dns.question.name`, `dns.resolved_ip`, and connection `destination.ip`/`destination.port`; missing network telemetry is unresolved, not benign. $investigate_3
 83  - Hint: scope by `host.id` + `process.entity_id`, or `host.id` + `process.pid` if absent. Compare DNS "lookup_result" `dns.resolved_ip` with later `destination.ip` from the same process.
 84  - Implication: escalate when the child retrieves tools from public infrastructure, connects to rare or unrelated systems, or uses destinations inconsistent with WSUS update distribution; lower suspicion when the same process reaches only recognized internal mirrors, proxies, or vendor services that fit command and parent context.
 85- If local findings are suspicious or unresolved, does same-host scope show broader WSUS compromise?
 86  - Focus: related alerts on the same `host.id`, especially repeated WSUS-spawned tools and complementary webshell, credential-access, discovery, archive, or lateral-movement activity. $investigate_0
 87  - Range: start with the alert window; expand to 48 hours only if parent-child, command, artifact, or destination evidence remains suspicious or incomplete.
 88  - Implication: broaden containment when related alerts corroborate WSUS compromise or post-exploitation; keep scope local when surrounding activity is limited to one fully explained maintenance action.
 89- Escalate for unexplained service-side execution, payload staging, suspicious destinations, or broader WSUS compromise; close only when parent-child path, command intent, service context, binary identity, artifacts, destinations, and same-host scope prove one exact recognized WSUS maintenance or validation workflow; preserve artifacts and escalate when evidence is mixed or optional telemetry is missing.
 90
 91### False positive analysis
 92
 93- WSUS installation, post-install repair, cleanup, health-check, migration, or authorized CVE validation can launch bounded shell or PowerShell children from "WsusPool" or "WsusService.exe". Close only when parent `process.parent.name`/`process.parent.args`, child command, path, hash or signer, `user.id`, and `host.id` prove the same narrow task; artifact and destination telemetry should corroborate when available, and missing recovery that leaves staging or callback unresolved requires confirmation or escalation.
 94- Before creating an exception, validate stability across prior alerts for the same WSUS server: parent context, child path/hash/signer, exact `process.command_line`, `user.id`, `host.id`, and any bounded artifact or destination pattern. Avoid exceptions on "WsusService.exe", "w3wp.exe", `process.name`, or `host.id` alone.
 95
 96### Response and remediation
 97
 98- If confirmed benign, reverse temporary containment and document the parent context, child `process.executable`, `process.command_line`, signer or hash, `user.id`, `host.id`, and bounded artifact or destination evidence that proved the WSUS workflow. Create an exception only from that full stable pattern.
 99- If suspicious but unconfirmed, preserve the case export, process tree, child `process.entity_id`, `process.pid`, `process.command_line`, parent context, `user.id`, `host.id`, recovered staged paths, recovered DNS or destination indicators, and related-alert identifiers before containment. Apply reversible containment first: block confirmed malicious destinations, restrict inbound WSUS exposure on ports 8530/8531, limit external access to the affected service, or increase monitoring. Isolate the host only when artifact, destination, or related-alert evidence shows active compromise and the server role can tolerate disruption.
100- If confirmed malicious, isolate the WSUS host or terminate the malicious child only after preserving process identifiers, command lines, parent context, hashes, staged paths, destination indicators, and related-alert evidence. Then disable the exposed WSUS service path or block inbound 8530/8531 until patched, scope other servers and accounts for confirmed indicators, remove only artifacts identified during triage, restore WSUS/IIS content, rotate exposed credentials if configuration material was accessed, apply the relevant Microsoft WSUS update, and retain case logs.
101"""
102
103setup = """## Setup
104
105This rule is designed for data generated by [Elastic Defend](https://www.elastic.co/security/endpoint-security), which provides native endpoint detection and response, along with event enrichments designed to work with our detection rules.
106
107Setup instructions: https://ela.st/install-elastic-defend
108
109### Additional data sources
110
111This rule also supports the following third-party data sources. For setup instructions, refer to the links below:
112
113- [Microsoft Defender XDR](https://ela.st/m365-defender)
114- [SentinelOne Cloud Funnel](https://ela.st/sentinel-one-cloud-funnel)
115- [Sysmon Event ID 1 - Process Creation](https://ela.st/sysmon-event-1-setup)
116"""
117
118[rule.investigation_fields]
119field_names = [
120    "@timestamp",
121    "host.id",
122    "user.id",
123    "process.entity_id",
124    "process.pid",
125    "process.executable",
126    "process.command_line",
127    "process.args",
128    "process.pe.original_file_name",
129    "process.code_signature.subject_name",
130    "process.code_signature.trusted",
131    "process.parent.name",
132    "process.parent.executable",
133    "process.parent.command_line",
134    "process.parent.args",
135]
136
137[transform]
138
139[[transform.investigate]]
140label = "Alerts associated with the host"
141description = ""
142providers = [
143  [
144    { excluded = false, field = "event.kind", queryType = "phrase", value = "signal", valueType = "string" },
145    { excluded = false, field = "host.id", queryType = "phrase", value = "{{host.id}}", valueType = "string" }
146  ]
147]
148relativeFrom = "now-48h/h"
149relativeTo = "now"
150
151[[transform.investigate]]
152label = "Child processes of the suspicious WSUS child"
153description = ""
154providers = [
155  [
156    { excluded = false, field = "event.category", queryType = "phrase", value = "process", valueType = "string" },
157    { excluded = false, field = "host.id", queryType = "phrase", value = "{{host.id}}", valueType = "string" },
158    { excluded = false, field = "process.parent.entity_id", queryType = "phrase", value = "{{process.entity_id}}", valueType = "string" }
159  ],
160  [
161    { excluded = false, field = "event.category", queryType = "phrase", value = "process", valueType = "string" },
162    { excluded = false, field = "host.id", queryType = "phrase", value = "{{host.id}}", valueType = "string" },
163    { excluded = false, field = "process.parent.pid", queryType = "phrase", value = "{{process.pid}}", valueType = "string" }
164  ]
165]
166relativeFrom = "now-1h"
167relativeTo = "now"
168
169[[transform.investigate]]
170label = "File events for the suspicious child process"
171description = ""
172providers = [
173  [
174    { excluded = false, field = "event.category", queryType = "phrase", value = "file", valueType = "string" },
175    { excluded = false, field = "host.id", queryType = "phrase", value = "{{host.id}}", valueType = "string" },
176    { excluded = false, field = "process.entity_id", queryType = "phrase", value = "{{process.entity_id}}", valueType = "string" }
177  ],
178  [
179    { excluded = false, field = "event.category", queryType = "phrase", value = "file", valueType = "string" },
180    { excluded = false, field = "host.id", queryType = "phrase", value = "{{host.id}}", valueType = "string" },
181    { excluded = false, field = "process.pid", queryType = "phrase", value = "{{process.pid}}", valueType = "string" }
182  ]
183]
184relativeFrom = "now-1h"
185relativeTo = "now"
186
187[[transform.investigate]]
188label = "Network events for the suspicious child process"
189description = ""
190providers = [
191  [
192    { excluded = false, field = "event.category", queryType = "phrase", value = "network", valueType = "string" },
193    { excluded = false, field = "host.id", queryType = "phrase", value = "{{host.id}}", valueType = "string" },
194    { excluded = false, field = "process.entity_id", queryType = "phrase", value = "{{process.entity_id}}", valueType = "string" }
195  ],
196  [
197    { excluded = false, field = "event.category", queryType = "phrase", value = "network", valueType = "string" },
198    { excluded = false, field = "host.id", queryType = "phrase", value = "{{host.id}}", valueType = "string" },
199    { excluded = false, field = "process.pid", queryType = "phrase", value = "{{process.pid}}", valueType = "string" }
200  ]
201]
202relativeFrom = "now-1h"
203relativeTo = "now"
204
205[[rule.threat]]
206framework = "MITRE ATT&CK"
207
208[[rule.threat.technique]]
209id = "T1190"
210name = "Exploit Public-Facing Application"
211reference = "https://attack.mitre.org/techniques/T1190/"
212
213[rule.threat.tactic]
214id = "TA0001"
215name = "Initial Access"
216reference = "https://attack.mitre.org/tactics/TA0001/"
217
218[[rule.threat]]
219framework = "MITRE ATT&CK"
220
221[[rule.threat.technique]]
222id = "T1059"
223name = "Command and Scripting Interpreter"
224reference = "https://attack.mitre.org/techniques/T1059/"
225
226[[rule.threat.technique.subtechnique]]
227id = "T1059.001"
228name = "PowerShell"
229reference = "https://attack.mitre.org/techniques/T1059/001/"
230
231[[rule.threat.technique.subtechnique]]
232id = "T1059.003"
233name = "Windows Command Shell"
234reference = "https://attack.mitre.org/techniques/T1059/003/"
235
236[rule.threat.tactic]
237id = "TA0002"
238name = "Execution"
239reference = "https://attack.mitre.org/tactics/TA0002/"
240
241[[rule.threat]]
242framework = "MITRE ATT&CK"
243
244[[rule.threat.technique]]
245id = "T1218"
246name = "System Binary Proxy Execution"
247reference = "https://attack.mitre.org/techniques/T1218/"
248
249[[rule.threat.technique.subtechnique]]
250id = "T1218.011"
251name = "Rundll32"
252reference = "https://attack.mitre.org/techniques/T1218/011/"
253
254[rule.threat.tactic]
255id = "TA0005"
256name = "Defense Evasion"
257reference = "https://attack.mitre.org/tactics/TA0005/"
258
259[[rule.threat]]
260framework = "MITRE ATT&CK"
261
262[[rule.threat.technique]]
263id = "T1505"
264name = "Server Software Component"
265reference = "https://attack.mitre.org/techniques/T1505/"
266
267[[rule.threat.technique.subtechnique]]
268id = "T1505.003"
269name = "Web Shell"
270reference = "https://attack.mitre.org/techniques/T1505/003/"
271
272[rule.threat.tactic]
273id = "TA0003"
274name = "Persistence"
275reference = "https://attack.mitre.org/tactics/TA0003/"

Triage and analysis

Investigating Windows Server Update Service Spawning Suspicious Processes

Possible investigation steps

  • What does the alert-local WSUS parent-child path show?
    • Focus: child process.executable and process.command_line, plus process.parent.name, process.parent.executable, and process.parent.args, especially "w3wp.exe" with "WsusPool" or "WsusService.exe".
    • Implication: escalate when a WSUS web or service component launches a shell, PowerShell, "rundll32.exe", or "curl.exe" for interpreter, download, or proxy-execution behavior; lower suspicion only when the parent-child pair and arguments match a narrow recognized WSUS setup, cleanup, or repair pattern.
  • Does the child command and binary identity fit bounded WSUS maintenance?
    • Why: WSUS children can inherit service context; visible user fields may not prove human initiation.
    • Focus: process.command_line, process.executable, process.pe.original_file_name, process.code_signature.subject_name/trusted, and child processes. $investigate_1
    • Hint: for PowerShell with script-block telemetry, anchor on host.id + process.entity_id or host.id + process.pid in a tight alert window. Reconstruct powershell.file.script_block_id, powershell.total, powershell.sequence, and powershell.file.script_block_text; missing script-block telemetry is unresolved, not benign.
    • Implication: escalate on encoded script content, external retrieval, discovery, archive, remote-admin, temp-path DLL activity, or a renamed/unsigned/mismatched child; lower suspicion only when command scope, path, PE identity, and signer all match the same narrow WSUS task. Identity alone does not clear the launch chain.
  • Did the child stage payloads or WSUS-content artifacts?
    • Focus: process-scoped file file.path, file.Ext.original.path, file.origin_url, and file.Ext.windows.zone_identifier; missing file telemetry is unresolved, not benign. $investigate_2
    • Hint: scope by host.id + process.entity_id, or host.id + process.pid if absent; check later starts where process.executable equals the written path.
    • Implication: escalate when the child writes scripts, DLLs, EXEs, archives, or renamed content under WSUS, IIS, temp, or user-writable paths, especially if later executed; lower suspicion only when writes stay inside the same narrow WSUS maintenance path.
  • Did the child retrieve tooling, call back, or reach destinations outside the WSUS role?
    • Focus: process-scoped DNS event.action, dns.question.name, dns.resolved_ip, and connection destination.ip/destination.port; missing network telemetry is unresolved, not benign. $investigate_3
    • Hint: scope by host.id + process.entity_id, or host.id + process.pid if absent. Compare DNS "lookup_result" dns.resolved_ip with later destination.ip from the same process.
    • Implication: escalate when the child retrieves tools from public infrastructure, connects to rare or unrelated systems, or uses destinations inconsistent with WSUS update distribution; lower suspicion when the same process reaches only recognized internal mirrors, proxies, or vendor services that fit command and parent context.
  • If local findings are suspicious or unresolved, does same-host scope show broader WSUS compromise?
    • Focus: related alerts on the same host.id, especially repeated WSUS-spawned tools and complementary webshell, credential-access, discovery, archive, or lateral-movement activity. $investigate_0
    • Range: start with the alert window; expand to 48 hours only if parent-child, command, artifact, or destination evidence remains suspicious or incomplete.
    • Implication: broaden containment when related alerts corroborate WSUS compromise or post-exploitation; keep scope local when surrounding activity is limited to one fully explained maintenance action.
  • Escalate for unexplained service-side execution, payload staging, suspicious destinations, or broader WSUS compromise; close only when parent-child path, command intent, service context, binary identity, artifacts, destinations, and same-host scope prove one exact recognized WSUS maintenance or validation workflow; preserve artifacts and escalate when evidence is mixed or optional telemetry is missing.

False positive analysis

  • WSUS installation, post-install repair, cleanup, health-check, migration, or authorized CVE validation can launch bounded shell or PowerShell children from "WsusPool" or "WsusService.exe". Close only when parent process.parent.name/process.parent.args, child command, path, hash or signer, user.id, and host.id prove the same narrow task; artifact and destination telemetry should corroborate when available, and missing recovery that leaves staging or callback unresolved requires confirmation or escalation.
  • Before creating an exception, validate stability across prior alerts for the same WSUS server: parent context, child path/hash/signer, exact process.command_line, user.id, host.id, and any bounded artifact or destination pattern. Avoid exceptions on "WsusService.exe", "w3wp.exe", process.name, or host.id alone.

Response and remediation

  • If confirmed benign, reverse temporary containment and document the parent context, child process.executable, process.command_line, signer or hash, user.id, host.id, and bounded artifact or destination evidence that proved the WSUS workflow. Create an exception only from that full stable pattern.
  • If suspicious but unconfirmed, preserve the case export, process tree, child process.entity_id, process.pid, process.command_line, parent context, user.id, host.id, recovered staged paths, recovered DNS or destination indicators, and related-alert identifiers before containment. Apply reversible containment first: block confirmed malicious destinations, restrict inbound WSUS exposure on ports 8530/8531, limit external access to the affected service, or increase monitoring. Isolate the host only when artifact, destination, or related-alert evidence shows active compromise and the server role can tolerate disruption.
  • If confirmed malicious, isolate the WSUS host or terminate the malicious child only after preserving process identifiers, command lines, parent context, hashes, staged paths, destination indicators, and related-alert evidence. Then disable the exposed WSUS service path or block inbound 8530/8531 until patched, scope other servers and accounts for confirmed indicators, remove only artifacts identified during triage, restore WSUS/IIS content, rotate exposed credentials if configuration material was accessed, apply the relevant Microsoft WSUS update, and retain case logs.

References

Related rules

to-top