Skip to content

Siemphony is in beta and still being built. How a rule earns its badge.

Siemphony’s repertoire

Process enumeration via tasklist, WMI process class or PowerShell cmdlets

Matches AN0095's "commands or invokes APIs to enumerate active processes (e.g., tasklist.exe, Get-Process, or CreateToolhelp32Snapshot)" using the three command-line forms that surface it: tasklist.exe itself, the PowerShell Get-Process/Get-CimInstance/Get-WmiObject process cmdlets, and wmic.exe invoked against the process class. CreateToolhelp32Snapshot is a bare API call with no command-line footprint and is not covered here. Sysmon EventID 10 (process_access) was considered and dropped: tasklist.exe opens a handle to every enumerated process, but that produces one process_access event per running process rather than one event for the enumeration itself, and the field this technique would key on (GrantedAccess) is already the anchor for unrelated credential-access rules, so reusing it here would be noise, not signal. MITRE's ParentProcessName and TimeWindow knobs (non-interactive callers, bursty discovery) have no equivalent in a single event and are not encoded. The brief's only process_creation source for this analytic is Security EventID 4688, which needs the Audit Process Creation subcategory enabled and the separate Include command line in process creation events policy — neither is on by default, and without the second policy specifically the CommandLine-based arms of this rule match nothing at all. UNVERIFIED AS AUTHORED — derived from MITRE ATT&CK DET0034, not hand-written and not tested by its author. Any lab result is on this rule's own page.Full description

The detection

The 4 SIEM queries below are previews produced by Siemphony’s own translator, not pySigma, and none has been executed against a real backend — review before you deploy.

detection.yml

title: Process enumeration via tasklist, WMI process class or PowerShell cmdletsid: a665cc17-d3fe-4041-a108-7fc9e00d2377status: experimentaldescription: |  Matches AN0095's "commands or invokes APIs to enumerate active processes  (e.g., tasklist.exe, Get-Process, or CreateToolhelp32Snapshot)" using the  three command-line forms that surface it: tasklist.exe itself, the  PowerShell Get-Process/Get-CimInstance/Get-WmiObject process cmdlets, and  wmic.exe invoked against the process class. CreateToolhelp32Snapshot is a  bare API call with no command-line footprint and is not covered here.  Sysmon EventID 10 (process_access) was considered and dropped: tasklist.exe  opens a handle to every enumerated process, but that produces one  process_access event per running process rather than one event for the  enumeration itself, and the field this technique would key on  (GrantedAccess) is already the anchor for unrelated credential-access  rules, so reusing it here would be noise, not signal. MITRE's  ParentProcessName and TimeWindow knobs (non-interactive callers, bursty  discovery) have no equivalent in a single event and are not encoded. The  brief's only process_creation source for this analytic is Security EventID  4688, which needs the Audit Process Creation subcategory enabled and the  separate Include command line in process creation events policy — neither  is on by default, and without the second policy specifically the  CommandLine-based arms of this rule match nothing at all.  UNVERIFIED AS AUTHORED — derived from MITRE ATT&CK DET0034, not hand-written and not tested by its author. Any lab result is on this rule's own page.references:  - https://attack.mitre.org/techniques/T1057  - https://attack.mitre.org/detectionstrategies/DET0034author: Siemphony pipeline (machine-derived from MITRE ATT&CK v19.2)date: 2026-08-16tags:  - attack.discovery  - attack.t1057logsource:  category: process_creation  product: windowsdetection:  selection_tasklist:    Image|endswith: '\tasklist.exe'  selection_ps_cmdlet:    CommandLine|contains:      - 'Get-Process'      - 'Get-CimInstance -ClassName Win32_Process'      - 'Get-CimInstance Win32_Process'      - 'Get-WmiObject -Class Win32_Process'      - 'Get-WmiObject Win32_Process'  selection_wmic:    Image|endswith: '\wmic.exe'    CommandLine|contains: 'process'  condition: 1 of selection*falsepositives:  - "Remote monitoring and management (RMM) agents and performance-dashboard tools that poll Get-Process, Get-CimInstance Win32_Process or wmic process on a fixed schedule across the whole managed fleet — on a monitored estate this is the loudest and most routine source of matches."  - "Helpdesk and support staff running tasklist.exe interactively to confirm whether a specific service or application process is running, a standard first troubleshooting step."  - "Installers and application launchers that call tasklist or Get-Process to check whether an instance of the target application is already running before proceeding."  - "The wmic arm also matches process-management commands that are not discovery, such as `wmic process where name=... delete` or `wmic process call terminate`, because both share the bare word 'process' with the enumeration form `wmic process list`."level: low

Sentinel · KQL

Run this as a search.

DeviceProcessEvents| where (FolderPath endswith "\\tasklist.exe" or (ProcessCommandLine contains "Get-Process" or ProcessCommandLine contains "Get-CimInstance -ClassName Win32_Process" or ProcessCommandLine contains "Get-CimInstance Win32_Process" or ProcessCommandLine contains "Get-WmiObject -Class Win32_Process" or ProcessCommandLine contains "Get-WmiObject Win32_Process") or (FolderPath endswith "\\wmic.exe" and ProcessCommandLine contains "process"))

Splunk · SPL

Run this as a search.

index=* (Image="*\\tasklist.exe" OR (CommandLine="*Get-Process*" OR CommandLine="*Get-CimInstance -ClassName Win32_Process*" OR CommandLine="*Get-CimInstance Win32_Process*" OR CommandLine="*Get-WmiObject -Class Win32_Process*" OR CommandLine="*Get-WmiObject Win32_Process*") OR (Image="*\\wmic.exe" AND CommandLine="*process*"))

Elastic · ES|QL

Run this as a search.

FROM logs-*| WHERE (TO_LOWER(process.executable) LIKE "*\\\\tasklist.exe" OR (TO_LOWER(process.command_line) LIKE "*get-process*" OR TO_LOWER(process.command_line) LIKE "*get-ciminstance -classname win32_process*" OR TO_LOWER(process.command_line) LIKE "*get-ciminstance win32_process*" OR TO_LOWER(process.command_line) LIKE "*get-wmiobject -class win32_process*" OR TO_LOWER(process.command_line) LIKE "*get-wmiobject win32_process*") OR (TO_LOWER(process.executable) LIKE "*\\\\wmic.exe" AND TO_LOWER(process.command_line) LIKE "*process*"))

Wazuh · XML rule

Deploy to your manager — this is a rule, not a search.

<group name="sigma,windows,process_creation,">  <!-- Rule ids must be unique on your manager; 100000+ is the user range. -->  <!-- 3 rules: the Sigma condition ORs across different fields,       which one rule cannot express. Any one matching is a hit. -->  <rule id="100000" level="5">    <!-- Set <if_sid> to the decoder/base rule for windows so this only evaluates relevant events. -->    <field name="Image" type="pcre2">(?i)\\tasklist\.exe$</field>    <description>Process enumeration via tasklist, WMI process class or PowerShell cmdlets (1/3)</description>    <mitre>      <id>T1057</id>    </mitre>  </rule>   <rule id="100001" level="5">    <!-- Set <if_sid> to the decoder/base rule for windows so this only evaluates relevant events. -->    <field name="CommandLine" type="pcre2">(?i)(Get-Process|Get-CimInstance -ClassName Win32_Process|Get-CimInstance Win32_Process|Get-WmiObject -Class Win32_Process|Get-WmiObject Win32_Process)</field>    <description>Process enumeration via tasklist, WMI process class or PowerShell cmdlets (2/3)</description>    <mitre>      <id>T1057</id>    </mitre>  </rule>   <rule id="100002" level="5">    <!-- Set <if_sid> to the decoder/base rule for windows so this only evaluates relevant events. -->    <field name="Image" type="pcre2">(?i)\\wmic\.exe$</field>    <field name="CommandLine" type="pcre2">(?i)process</field>    <description>Process enumeration via tasklist, WMI process class or PowerShell cmdlets (3/3)</description>    <mitre>      <id>T1057</id>    </mitre>  </rule></group>

Verdicts · reactions · comments

Community

Verdicts from engineers who actually deployed it, and the conversation around it.

Log in to react
Not yet reported on

Nobody has run this in a real environment and said what happened.

Verdicts from engineers who deployed it

0 cast

No verdicts reported yet. The first one is worth more than the tenth — say what you ran it against.

Log in to report a verdict.

Log in to join the discussion.

No comments yet. Someone who deploys this will have something to say about it.