Software deployment agent spawning a script interpreter
Anchors on the parent rather than the payload: AN0623 describes push execution arriving through an endpoint-management suite, so the observable is the deployment agent itself appearing as the parent of a shell or scripting host. The first leg pairs a management-agent parent with an interpreter child; the second leg needs no child gate at all, because `cmtrace.exe` is a log viewer with a menu entry that launches arbitrary programs, and it has no routine reason to be anyone's parent process. MITRE names the `ParentImageList` knob and names cmtrace.exe as its example; the rest of the parent list is authored here — CcmExec.exe is the Configuration Manager client service, and Microsoft.Management.Services.IntuneWindowsAgent.exe with AgentExecutor.exe are the pair that runs assigned scripts on an Intune-managed host. Note the Intune binary name: the *service* is named IntuneManagementExtension and the install folder is "Microsoft Intune Management Extension", but no `IntuneManagementExtension.exe` exists on disk, so matching that name yields a selector that can never fire. The brief offers Security EventID 4688 for this analytic but maps it onto the Sysmon-shaped `process_creation` category, and the rule is written in that vocabulary (`Image`, `ParentImage`); a 4688 feed needs `NewProcessName` mapped onto `Image` and `ParentProcessName` onto `ParentImage` before it can match, and 4688 itself requires *Audit Process Creation*, which no default install and neither the MS nor the CIS baseline enables. Two limits worth stating: agents for other suites — Ansible or Chef over WinRM, AWS Systems Manager, Azure Arc, Tanium, Altiris — spawn under worker-process names that differ by product and version and are not in the list, so a quiet result means the site's tool is unlisted rather than that no push execution happened; and remote execution driven over WinRM or WMI parents under wsmprovhost.exe or WmiPrvSE.exe, which is T1021.006 and T1047 and is out of scope here. MITRE's `TimeWindow` and `UserContext` knobs ask for "outside the maintenance window" and "not the expected service account", both of which are comparisons against a baseline that a single-event rule cannot make. UNVERIFIED AS AUTHORED — derived from MITRE ATT&CK DET0223, not hand-written and not tested by its author. Any lab result is on this rule's own page.Full descriptionShow less
The detection
The 4 SIEM queries below are previews produced by Siemphony’s own translator, not pySigma, and none has been executed against a real backend — review before you deploy.
detection.yml
title: Software deployment agent spawning a script interpreterid: a59e0d54-76dc-46ac-90de-4fc3f2d2055fstatus: experimentaldescription: | Anchors on the parent rather than the payload: AN0623 describes push execution arriving through an endpoint-management suite, so the observable is the deployment agent itself appearing as the parent of a shell or scripting host. The first leg pairs a management-agent parent with an interpreter child; the second leg needs no child gate at all, because `cmtrace.exe` is a log viewer with a menu entry that launches arbitrary programs, and it has no routine reason to be anyone's parent process. MITRE names the `ParentImageList` knob and names cmtrace.exe as its example; the rest of the parent list is authored here — CcmExec.exe is the Configuration Manager client service, and Microsoft.Management.Services.IntuneWindowsAgent.exe with AgentExecutor.exe are the pair that runs assigned scripts on an Intune-managed host. Note the Intune binary name: the *service* is named IntuneManagementExtension and the install folder is "Microsoft Intune Management Extension", but no `IntuneManagementExtension.exe` exists on disk, so matching that name yields a selector that can never fire. The brief offers Security EventID 4688 for this analytic but maps it onto the Sysmon-shaped `process_creation` category, and the rule is written in that vocabulary (`Image`, `ParentImage`); a 4688 feed needs `NewProcessName` mapped onto `Image` and `ParentProcessName` onto `ParentImage` before it can match, and 4688 itself requires *Audit Process Creation*, which no default install and neither the MS nor the CIS baseline enables. Two limits worth stating: agents for other suites — Ansible or Chef over WinRM, AWS Systems Manager, Azure Arc, Tanium, Altiris — spawn under worker-process names that differ by product and version and are not in the list, so a quiet result means the site's tool is unlisted rather than that no push execution happened; and remote execution driven over WinRM or WMI parents under wsmprovhost.exe or WmiPrvSE.exe, which is T1021.006 and T1047 and is out of scope here. MITRE's `TimeWindow` and `UserContext` knobs ask for "outside the maintenance window" and "not the expected service account", both of which are comparisons against a baseline that a single-event rule cannot make. UNVERIFIED AS AUTHORED — derived from MITRE ATT&CK DET0223, not hand-written and not tested by its author. Any lab result is on this rule's own page.references: - https://attack.mitre.org/techniques/T1072 - https://attack.mitre.org/detectionstrategies/DET0223author: Siemphony pipeline (machine-derived from MITRE ATT&CK v19.2)date: 2026-08-16tags: - attack.execution - attack.lateral-movement - attack.t1072logsource: category: process_creation product: windowsdetection: selection_agent: ParentImage|endswith: - '\CcmExec.exe' - '\Microsoft.Management.Services.IntuneWindowsAgent.exe' - '\AgentExecutor.exe' selection_interpreter: Image|endswith: - '\powershell.exe' - '\pwsh.exe' - '\cmd.exe' - '\wscript.exe' - '\cscript.exe' - '\mshta.exe' - '\rundll32.exe' - '\regsvr32.exe' selection_cmtrace: ParentImage|endswith: '\cmtrace.exe' condition: (selection_agent and selection_interpreter) or selection_cmtracefalsepositives: - "Every sanctioned deployment on a managed fleet, because running scripts and installers as SYSTEM is precisely what these agents are for — application installs, script assignments, compliance remediations and detection scripts all match the agent leg, making it the highest-volume match by a wide margin and the reason this is rated low rather than treated as an alert on its own." - "Scheduled patch and compliance cycles firing the same PowerShell or cmd wrapper on every in-scope host within the same maintenance window, producing a fleet-wide burst that has the shape of coordinated remote execution and is simply the monthly cycle." - "An administrator reading deployment logs on a site server and using CMTrace's own menu to open a command prompt or launch a tool, which matches the cmtrace leg with no child gate to soften it." - "Application packagers who wrap an installer in cmd.exe /c or a PowerShell script so one deployment can chain a prerequisite check, the MSI call and a post-install cleanup — a common packaging convention that puts an interpreter directly under the agent by design."level: lowSentinel · KQL
Run this as a search.
DeviceProcessEvents| where (((InitiatingProcessFolderPath endswith "\\CcmExec.exe" or InitiatingProcessFolderPath endswith "\\Microsoft.Management.Services.IntuneWindowsAgent.exe" or InitiatingProcessFolderPath endswith "\\AgentExecutor.exe") and (FolderPath endswith "\\powershell.exe" or FolderPath endswith "\\pwsh.exe" or FolderPath endswith "\\cmd.exe" or FolderPath endswith "\\wscript.exe" or FolderPath endswith "\\cscript.exe" or FolderPath endswith "\\mshta.exe" or FolderPath endswith "\\rundll32.exe" or FolderPath endswith "\\regsvr32.exe")) or InitiatingProcessFolderPath endswith "\\cmtrace.exe")
Splunk · SPL
Run this as a search.
index=* (((ParentImage="*\\CcmExec.exe" OR ParentImage="*\\Microsoft.Management.Services.IntuneWindowsAgent.exe" OR ParentImage="*\\AgentExecutor.exe") AND (Image="*\\powershell.exe" OR Image="*\\pwsh.exe" OR Image="*\\cmd.exe" OR Image="*\\wscript.exe" OR Image="*\\cscript.exe" OR Image="*\\mshta.exe" OR Image="*\\rundll32.exe" OR Image="*\\regsvr32.exe")) OR ParentImage="*\\cmtrace.exe")Elastic · ES|QL
Run this as a search.
FROM logs-*| WHERE (((TO_LOWER(process.parent.executable) LIKE "*\\\\ccmexec.exe" OR TO_LOWER(process.parent.executable) LIKE "*\\\\microsoft.management.services.intunewindowsagent.exe" OR TO_LOWER(process.parent.executable) LIKE "*\\\\agentexecutor.exe") AND (TO_LOWER(process.executable) LIKE "*\\\\powershell.exe" OR TO_LOWER(process.executable) LIKE "*\\\\pwsh.exe" OR TO_LOWER(process.executable) LIKE "*\\\\cmd.exe" OR TO_LOWER(process.executable) LIKE "*\\\\wscript.exe" OR TO_LOWER(process.executable) LIKE "*\\\\cscript.exe" OR TO_LOWER(process.executable) LIKE "*\\\\mshta.exe" OR TO_LOWER(process.executable) LIKE "*\\\\rundll32.exe" OR TO_LOWER(process.executable) LIKE "*\\\\regsvr32.exe")) OR TO_LOWER(process.parent.executable) LIKE "*\\\\cmtrace.exe")
Wazuh · XML rule
Deploy to your manager — this is a rule, not a search.
<group name="sigma,windows,process_creation,"> <!-- Rule ids must be unique on your manager; 100000+ is the user range. --> <!-- 2 rules: the Sigma condition ORs across different fields, which one rule cannot express. Any one matching is a hit. --> <rule id="100000" level="5"> <!-- Set <if_sid> to the decoder/base rule for windows so this only evaluates relevant events. --> <field name="ParentImage" type="pcre2">(?i)(\\CcmExec\.exe$|\\Microsoft\.Management\.Services\.IntuneWindowsAgent\.exe$|\\AgentExecutor\.exe$)</field> <field name="Image" type="pcre2">(?i)(\\powershell\.exe$|\\pwsh\.exe$|\\cmd\.exe$|\\wscript\.exe$|\\cscript\.exe$|\\mshta\.exe$|\\rundll32\.exe$|\\regsvr32\.exe$)</field> <description>Software deployment agent spawning a script interpreter (1/2)</description> <mitre> <id>T1072</id> </mitre> </rule> <rule id="100001" level="5"> <!-- Set <if_sid> to the decoder/base rule for windows so this only evaluates relevant events. --> <field name="ParentImage" type="pcre2">(?i)\\cmtrace\.exe$</field> <description>Software deployment agent spawning a script interpreter (2/2)</description> <mitre> <id>T1072</id> </mitre> </rule></group>
Verdicts · reactions · comments
Community
Verdicts from engineers who actually deployed it, and the conversation around it.
Nobody has run this in a real environment and said what happened.
Verdicts from engineers who deployed it
0 castNo verdicts reported yet. The first one is worth more than the tenth — say what you ran it against.
Log in to report a verdict.
Log in to join the discussion.
No comments yet. Someone who deploys this will have something to say about it.