Suspect Child Process to IIS Worker Process (w3wp.exe) - Potential Exploitation

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Content Index


Identifies abnormal child processes of the Microsoft IIS Worker Process (w3wp.exe), which runs Web applications and handles requests for an application pool. Children such as cmd.exe or powershell.exe can indicate an exploit attempt.

Attribute Value
Type Hunting Query
Solution Intel471
ID 667c9f6c-8e41-4309-80a8-55fc3c5769bf
Tactics InitialAccess, LateralMovement
Techniques T1190, T1210
Required Connectors SecurityEvents, WindowsSecurityEvents
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Selection Criteria Transformations Ingestion API Lake-Only
SecurityEvent NewProcessName has_any "cmd.exe"
ParentProcessName endswith "w3wp.exe"
✓ ✓ ✓

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Hunting Queries · Back to Intel471