Skip to content

Should generate no alerts on clean system out of the box #570

Description

@dobin

Issue

Operating Fibratus in a clean system, like a freshly installed windows (with commonly installed apps), generates alerts.

Expectation

Operating under a non-infected system should not generate any alerts, as it is not compromised or under attack.

Proposal

Test all the rules regularly against standard non-infected systems, and sensibly whitelist false positives.

This should include:

  • Normal Windows operation of Windows 11, and maybe 1-3 latest Windows server versions
  • Including performing Windows updates
  • Using commonly used applications like Office, Chrome, Firefox, Visual Studio, Teams etc. , and updating them
  • Using commonly used server software like MSSQL, IIS etc. (Windows Server), and updating them

Additional context

Some of alerts i get in the log file attached to #567 by just idling the VM:

source=action/alert.go:37
time=2026-01-14T06:34:06+01:00 level=info msg=sending alert: [Unusual access to Web Browser Credential stores]. Text:  Event(s): 
		Seq: 7549133
		Pid: 11856
		Tid: 4184
		Type: CreateFile
		CPU: 0
		Name: CreateFile
		Category: file
		Description: Creates or opens a file or I/O device
		Host: DESKTOP-C0HF6MF
		Timestamp: 2026-01-14 06:34:05.6893322 +0100 CET
		Kparams: attributes➜ , create_disposition➜ OPEN, create_options➜ OPEN_BY_FILE_ID|OPEN_REPARSE_POINT, file_object➜ ffffb80e07544dc0, file_path➜ C:\Users\hacker\AppData\Local\Microsoft\Windows\WebCache\WebCacheV01.dat, irp➜ ffffb80e0a5e30f8, share_mask➜ , status➜ Success, tid➜ 4184, type➜ File
		Metadata: rule.name: Unusual access to Web Browser Credential stores, tactic.id: TA0006, subtechnique.id: T1555.003, subtechnique.name: Credentials from Web Browsers, subtechnique.ref: https://attack.mitre.org/techniques/T1555/003/, technique.id: T1555, technique.name: Credentials from Password Stores, tactic.name: Credential Access, tactic.ref: https://attack.mitre.org/tactics/TA0006/, technique.ref: https://attack.mitre.org/techniques/T1555/
	    
		Pid:  11856
		Ppid: 792
		Name: svchost.exe
		Parent name: services.exe
		Cmdline: C:\WINDOWS\system32\svchost.exe -k defragsvc
		Parent cmdline: C:\WINDOWS\system32\services.exe
		Exe:  C:\WINDOWS\system32\svchost.exe
		Cwd:  C:\WINDOWS\system32\
		SID:  S-1-5-18
		Username: SYSTEM
		Domain: NT AUTHORITY
		Args: [C:\WINDOWS\system32\svchost.exe -k defragsvc]
		Session ID: 0
 source=action/alert.go:37
time=2026-01-23T15:26:26+01:00 level=info msg=sending alert: [Suspicious object symbolic link creation]. Text: Suspicious object symbolic link \Sessions\1\AppContainerNamedObjects\S-1-15-2-3251537155-1984446955-2931258699-841473695-1938553385-924012159-129201922 � created by process C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
 Event(s): 
		Seq: 71545003
		Pid: 1132
		Tid: 4060
		Type: CreateSymbolicLinkObject
		CPU: 0
		Name: CreateSymbolicLinkObject
		Category: object
		Description: Creates the symbolic link within the object manager directory
		Host: DESKTOP-C0HF6MF
		Timestamp: 2026-01-23 15:26:27.1999612 +0100 CET
		Kparams: desired_access➜ READ_CONTROL|SYNCHRONIZE, source➜ Session, status➜ Success, target➜ \Sessions\1\AppContainerNamedObjects\S-1-15-2-3251537155-1984446955-2931258699-841473695-1938553385-924012159-129201922 �
		Metadata: tactic.name: Defense Evasion, tactic.ref: https://attack.mitre.org/tactics/TA0005/, rule.name: Suspicious object symbolic link creation, technique.id: T1211, technique.name: Exploitation for Defense Evasion, technique.ref: https://attack.mitre.org/techniques/T1211/, tactic.id: TA0005
	    
		Pid:  1132
		Ppid: 4428
		Name: msedge.exe
		Parent name: explorer.exe
		Cmdline: "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" 
		Parent cmdline: C:\WINDOWS\Explorer.EXE
		Exe:  C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
		Cwd:  C:\Program Files (x86)\Microsoft\Edge\Application\144.0.3719.82\
		SID:  S-1-5-21-937184543-179303868-2836477951-1002
		Username: rededr
		Domain: DESKTOP-C0HF6MF
		Args: ["C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe"]
		Session ID: 1
 source=action/alert.go:37
time=2026-01-23T11:42:42+01:00 level=info msg=sending alert: [Suspicious Vault client DLL load]. Text: Suspicious process C:\WINDOWS\system32\UCConfigTask.exe loaded the Credential Vault Client DLL for potential credentials harvesting
 Event(s): 
		Seq: 67393279
		Pid: 1428
		Tid: 7308
		Type: CreateProcess
		CPU: 0
		Name: CreateProcess
		Category: process
		Description: Creates a new process and its primary thread
		Host: DESKTOP-C0HF6MF
		Timestamp: 2026-01-23 11:42:43.4801179 +0100 CET
		Kparams: cmdline➜ "C:\WINDOWS\system32\UCConfigTask.exe", directory_table_base➜ 1d2047000, domain➜ NT AUTHORITY, exe➜ C:\WINDOWS\system32\UCConfigTask.exe, exit_status➜ Success, flags➜ , kproc➜ ffff9e86a78f0080, name➜ UCConfigTask.exe, pid➜ 8144, ppid➜ 1428, real_ppid➜ 1428, session_id➜ 0, sid➜ S-1-5-18, start_time➜ 2026-01-23 11:42:42.4538046 +0100 CET, username➜ SYSTEM
		Metadata: technique.ref: https://attack.mitre.org/techniques/T1555/, subtechnique.ref: https://attack.mitre.org/techniques/T1555/004/, tactic.id: TA0006, tactic.name: Credential Access, rule.name: Suspicious Vault client DLL load, tactic.ref: https://attack.mitre.org/tactics/TA0006/, subtechnique.name: Windows Credential Manager, technique.name: Credentials from Password Stores, technique.id: T1555, rule.seq.link: 7281757657168347136, subtechnique.id: T1555.004
	    
		Pid:  1428
		Ppid: 788
		Name: svchost.exe
		Parent name: services.exe
		Cmdline: C:\WINDOWS\system32\svchost.exe -k netsvcs -p -s Schedule
		Parent cmdline: C:\WINDOWS\system32\services.exe
		Exe:  C:\WINDOWS\system32\svchost.exe
		Cwd:  C:\WINDOWS\system32\
		SID:  S-1-5-18
		Username: SYSTEM
		Domain: NT AUTHORITY
		Args: [C:\WINDOWS\system32\svchost.exe -k netsvcs -p -s Schedule]
		Session ID: 0

Activity

  1. rabbitstack commented on Jan 25, 2026

    @rabbitstack
    Owner

    Hi @dobin,

    I saw those alerts in the log file you attached in the previous issue. Definitely, false positives. We'll tune the respective rules to prevent triggering alerts by legitimate processes.

  2. rabbitstack commented on Mar 1, 2026

    @rabbitstack
    Owner

    @dobin just a heads up. We've mitigated most of the FPs and rearranged some rules. Interestingly, most of the rules were triggered by the disk defrag process accessing sensitive files

  3. dobin commented on Mar 9, 2026

    @dobin
    Author

    Nice. Looking forward to 3.0.

  4. dobin commented on Apr 25, 2026

    @dobin
    Author

    I installed 3.0.0 on a Win 11 24H2 26100.8246

    Got 3 Alerts:

    {
      "id": "f7b2c9d3-99e7-41d5-bb4a-6ea1a5f7f9e2",
      "title": "Suspicious access to the hosts file",
      "severity": "medium",
      "text": "Suspicious process C:\\Program Files (x86)\\Microsoft\\Copilot\\Application\\mscopilot.exe accessed the hosts file for potential tampering\n",
      "description": "Identifies suspicious process accessing the Windows hosts file for potential tampering. Adversaries can hijack the hosts files to block traffic to download/update servers or redirect the traffic to arbitrary servers under their control.\n",
      "labels": {
        "tactic.id": "TA0005",
        "tactic.name": "Defense Evasion",
        "tactic.ref": "https://attack.mitre.org/tactics/TA0005/",
        "technique.id": "T1562.001",
        "technique.name": "Impair Defenses - Disable or Modify Tools",
        "technique.ref": "https://attack.mitre.org/techniques/T1562/001/"
      },
      "events": [
        {
          "name": "CreateProcess",
          "category": "process",
          "timestamp": "2026-04-25T11:16:36.4203138+02:00",
          "params": {
            "cmdline": "\"C:\\Program Files (x86)\\Microsoft\\Copilot\\Application\\mscopilot.exe\" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --startup-read-main-dll --metrics-shmem-handle=2168,i,16137477505722183975,15207443675505419548,524288 --field-trial-handle=2384,i,7610424500120643741,16916732855647471630,262144 --variations-seed-version --pseudonymization-salt-handle=2388,i,5597598084624652117,5575474375030741751,4 --trace-process-track-uuid=3190708989122997041 --mojo-platform-channel-handle=3288 /prefetch:11",
            "directory_table_base": "65d8d000",
            "domain": "DESKTOP-C0HF6MF",
            "exe": "C:\\Program Files (x86)\\Microsoft\\Copilot\\Application\\mscopilot.exe",
            "exit_status": "Success",
            "flags": "",
            "kproc": "ffffb20ebd6240c0",
            "name": "mscopilot.exe",
            "pid": 5540,
            "ppid": 9992,
            "real_ppid": 9992,
            "session_id": 2,
            "sid": "S-1-5-21-937184543-179303868-2836477951-1001",
            "start_time": "2026-04-25 11:16:36.4203138 +0200 CEST",
            "token_elevation_type": "LIMITED",
            "token_integrity_level": "MEDIUM",
            "token_is_elevated": false,
            "username": "hacker"
          },
          "callstack": [
            "fffff8068ebe0c94 unbacked!",
            "fffff8068ea589af unbacked!",
            "fffff8068eb991c2 unbacked!",
            "fffff8068f1458ee unbacked!",
            "fffff8068f145624 unbacked!",
            "fffff8068f0a0a21 unbacked!",
            "fffff8068f2c956e unbacked!",
            "fffff8068eebd955 unbacked!",
            "7ffa53823514 C:\\WINDOWS\\SYSTEM32\\ntdll.dll!ZwCreateUserProcess",
            "7ffa50e50c3a C:\\Windows\\System32\\KernelBase.dll!CreateProcessInternalW",
            "7ffa50e4e296 C:\\Windows\\System32\\KernelBase.dll!CreateProcessW",
            "7ffa526ac6e4 C:\\Windows\\System32\\kernel32.dll!CreateProcessW",
            "7ff9d9e204f3 C:\\Program Files (x86)\\Microsoft\\Copilot\\Application\\147.0.3912.84\\msedge.dll!?",
            "7ff9d9e200a5 C:\\Program Files (x86)\\Microsoft\\Copilot\\Application\\147.0.3912.84\\msedge.dll!?",
            "7ff9d9e3c36b C:\\Program Files (x86)\\Microsoft\\Copilot\\Application\\147.0.3912.84\\msedge.dll!?",
            "7ff9d9e3adeb C:\\Program Files (x86)\\Microsoft\\Copilot\\Application\\147.0.3912.84\\msedge.dll!?",
            "7ff9d9e3a1fb C:\\Program Files (x86)\\Microsoft\\Copilot\\Application\\147.0.3912.84\\msedge.dll!?",
            "7ff9d90e026c C:\\Program Files (x86)\\Microsoft\\Copilot\\Application\\147.0.3912.84\\msedge.dll!?",
            "7ff9d90e0092 C:\\Program Files (x86)\\Microsoft\\Copilot\\Application\\147.0.3912.84\\msedge.dll!?",
            "7ff9d90dfed4 C:\\Program Files (x86)\\Microsoft\\Copilot\\Application\\147.0.3912.84\\msedge.dll!?",
            "7ff9d90df6b0 C:\\Program Files (x86)\\Microsoft\\Copilot\\Application\\147.0.3912.84\\msedge.dll!?",
            "7ff9d9dda23a C:\\Program Files (x86)\\Microsoft\\Copilot\\Application\\147.0.3912.84\\msedge.dll!?",
            "7ff9d9e16978 C:\\Program Files (x86)\\Microsoft\\Copilot\\Application\\147.0.3912.84\\msedge.dll!?",
            "7ff9d9e31138 C:\\Program Files (x86)\\Microsoft\\Copilot\\Application\\147.0.3912.84\\msedge.dll!?",
            "7ffa5269e8d7 C:\\Windows\\System32\\kernel32.dll!BaseThreadInitThunk",
            "7ffa5374c3fc C:\\Windows\\System32\\ntdll.dll!RtlUserThreadStart"
          ],
          "proc": {
            "pid": 5540,
            "tid": 7912,
            "ppid": 9992,
            "name": "mscopilot.exe",
            "exe": "C:\\Program Files (x86)\\Microsoft\\Copilot\\Application\\mscopilot.exe",
            "cmdline": "\"C:\\Program Files (x86)\\Microsoft\\Copilot\\Application\\mscopilot.exe\" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --startup-read-main-dll --metrics-shmem-handle=2168,i,16137477505722183975,15207443675505419548,524288 --field-trial-handle=2384,i,7610424500120643741,16916732855647471630,262144 --variations-seed-version --pseudonymization-salt-handle=2388,i,5597598084624652117,5575474375030741751,4 --trace-process-track-uuid=3190708989122997041 --mojo-platform-channel-handle=3288 /prefetch:11",
            "parent_name": "mscopilot.exe",
            "parent_cmdline": "\"C:\\Program Files (x86)\\Microsoft\\Copilot\\Application\\mscopilot.exe\" --no-startup-window --win-session-start",
            "sid": "S-1-5-21-937184543-179303868-2836477951-1001",
            "username": "hacker",
            "domain": "DESKTOP-C0HF6MF",
            "session_id": 2,
            "integrity_level": "MEDIUM",
            "is_wow64": false,
            "is_packaged": false,
            "is_protected": false,
            "ancestors": [
              "mscopilot.exe (9992)",
              "explorer.exe (7592)",
              "userinit.exe (7264)",
              "winlogon.exe (7888)"
            ]
          }
        },
        {
          "name": "CreateFile",
          "category": "file",
          "timestamp": "2026-04-25T11:16:36.5717914+02:00",
          "params": {
            "attributes": "",
            "create_disposition": "OPEN",
            "create_options": "OPEN_REPARSE_POINT",
            "file_object": "ffffb20ebd836590",
            "file_path": "C:\\WINDOWS\\system32\\drivers\\etc\\hosts",
            "irp": "ffffb20ebd447648",
            "share_mask": "READ|WRITE|DELETE",
            "status": "Success",
            "tid": 12348,
            "type": "Directory"
          },
          "callstack": [
            "fffff8068ebe0c94 unbacked!",
            "fffff8068ea589af unbacked!",
            "fffff8068eb22f86 unbacked!",
            "fffff80621c06d24 unbacked!",
            "fffff8062048baaf unbacked!",
            "fffff8062048b1a0 unbacked!",
            "fffff806204f68e0 unbacked!",
            "fffff8068eba953b unbacked!",
            "fffff8068eba94b3 unbacked!",
            "fffff8068f09a83b unbacked!",
            "fffff8068f0988da unbacked!",
            "fffff8068f0965e3 unbacked!",
            "fffff8068f09cac4 unbacked!",
            "fffff8068eebd955 unbacked!",
            "7ffa53824514 C:\\Windows\\System32\\ntdll.dll!ZwQueryFullAttributesFile",
            "7ffa50de331f C:\\Windows\\System32\\KernelBase.dll!GetFileAttributesExW",
            "7ff9da8f67cc C:\\Program Files (x86)\\Microsoft\\Copilot\\Application\\147.0.3912.84\\msedge.dll!IsSandboxedProcess",
            "7ff9dad6ada2 C:\\Program Files (x86)\\Microsoft\\Copilot\\Application\\147.0.3912.84\\msedge.dll!IsSandboxedProcess",
            "7ff9dad6abd7 C:\\Program Files (x86)\\Microsoft\\Copilot\\Application\\147.0.3912.84\\msedge.dll!IsSandboxedProcess",
            "7ff9dacc4f8a C:\\Program Files (x86)\\Microsoft\\Copilot\\Application\\147.0.3912.84\\msedge.dll!IsSandboxedProcess",
            "7ff9dadb8caf C:\\Program Files (x86)\\Microsoft\\Copilot\\Application\\147.0.3912.84\\msedge.dll!IsSandboxedProcess",
            "7ff9dadb8c47 C:\\Program Files (x86)\\Microsoft\\Copilot\\Application\\147.0.3912.84\\msedge.dll!IsSandboxedProcess",
            "7ff9daabd670 C:\\Program Files (x86)\\Microsoft\\Copilot\\Application\\147.0.3912.84\\msedge.dll!IsSandboxedProcess",
            "7ff9d90dfd61 C:\\Program Files (x86)\\Microsoft\\Copilot\\Application\\147.0.3912.84\\msedge.dll!?",
            "7ff9d90dea3c C:\\Program Files (x86)\\Microsoft\\Copilot\\Application\\147.0.3912.84\\msedge.dll!?",
            "7ff9d9dda23a C:\\Program Files (x86)\\Microsoft\\Copilot\\Application\\147.0.3912.84\\msedge.dll!?",
            "7ff9d9e167e8 C:\\Program Files (x86)\\Microsoft\\Copilot\\Application\\147.0.3912.84\\msedge.dll!?",
            "7ff9d9e31138 C:\\Program Files (x86)\\Microsoft\\Copilot\\Application\\147.0.3912.84\\msedge.dll!?",
            "7ffa5269e8d7 C:\\Windows\\System32\\kernel32.dll!BaseThreadInitThunk",
            "7ffa5374c3fc C:\\Windows\\System32\\ntdll.dll!RtlUserThreadStart"
          ],
          "proc": {
            "pid": 5540,
            "tid": 12348,
            "ppid": 9992,
            "name": "mscopilot.exe",
            "exe": "C:\\Program Files (x86)\\Microsoft\\Copilot\\Application\\mscopilot.exe",
            "cmdline": "\"C:\\Program Files (x86)\\Microsoft\\Copilot\\Application\\mscopilot.exe\" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --startup-read-main-dll --metrics-shmem-handle=2168,i,16137477505722183975,15207443675505419548,524288 --field-trial-handle=2384,i,7610424500120643741,16916732855647471630,262144 --variations-seed-version --pseudonymization-salt-handle=2388,i,5597598084624652117,5575474375030741751,4 --trace-process-track-uuid=3190708989122997041 --mojo-platform-channel-handle=3288 /prefetch:11",
            "parent_name": "mscopilot.exe",
            "parent_cmdline": "\"C:\\Program Files (x86)\\Microsoft\\Copilot\\Application\\mscopilot.exe\" --no-startup-window --win-session-start",
            "sid": "S-1-5-21-937184543-179303868-2836477951-1001",
            "username": "hacker",
            "domain": "DESKTOP-C0HF6MF",
            "session_id": 2,
            "integrity_level": "MEDIUM",
            "is_wow64": false,
            "is_packaged": false,
            "is_protected": false,
            "ancestors": [
              "mscopilot.exe (9992)",
              "explorer.exe (7592)",
              "userinit.exe (7264)",
              "winlogon.exe (7888)"
            ]
          }
        }
      ]
    }
    {
      "id": "a778295a-02f1-42d9-9c20-78346a7bc2c6",
      "title": "Suspicious protected process execution",
      "severity": "high",
      "text": "Suspicious protected process C:\\WINDOWS\\system32\\csrss.exe spawned by process C:\\WINDOWS\\System32\\smss.exe\n",
      "description": "Identifies unprivileged process spawning a child with protected integrity level. This \nindicates an unusual behavior that is often associated with attempts to tamper with or \nfreeze endpoint protection components.\n",
      "labels": {
        "subtechnique.id": "T1562.001",
        "subtechnique.name": "Disable or Modify Tools",
        "subtechnique.ref": "https://attack.mitre.org/techniques/T1562/001",
        "tactic.id": "TA0005",
        "tactic.name": "Defense Evasion",
        "tactic.ref": "https://attack.mitre.org/tactics/TA0005/",
        "technique.id": "T1562",
        "technique.name": "Impair Defenses",
        "technique.ref": "https://attack.mitre.org/techniques/T1562/"
      },
      "events": [
        {
          "name": "CreateProcess",
          "category": "process",
          "timestamp": "2026-04-25T11:16:16.3391192+02:00",
          "params": {
            "cmdline": "\\SystemRoot\\System32\\smss.exe 00000124 000000b8 winlogon.exe {F481D527-E8FA-457D-87F9-084B51C10000}",
            "directory_table_base": "1271de000",
            "domain": "NT AUTHORITY",
            "exe": "C:\\WINDOWS\\System32\\smss.exe",
            "exit_status": "Success",
            "flags": "PROTECTED",
            "kproc": "ffffb20ebb014080",
            "name": "smss.exe",
            "pid": 4936,
            "ppid": 440,
            "real_ppid": 440,
            "session_id": 3,
            "sid": "S-1-5-18",
            "start_time": "2026-04-25 11:16:16.3391025 +0200 CEST",
            "username": "SYSTEM"
          },
          "callstack": [
            "fffff8068ebe0c94 unbacked!",
            "fffff8068ea589af unbacked!",
            "fffff8068eb991c2 unbacked!",
            "fffff8068f1458ee unbacked!",
            "fffff8068f145624 unbacked!",
            "fffff8068f0a0a21 unbacked!",
            "fffff8068f2c956e unbacked!",
            "fffff8068eebd955 unbacked!",
            "7ffa53823514 C:\\Windows\\System32\\ntdll.dll!ZwCreateUserProcess",
            "7ffa537bd0ad C:\\Windows\\System32\\ntdll.dll!RtlNormalizeProcessParams",
            "7ffa537bcc54 C:\\Windows\\System32\\ntdll.dll!RtlCreateUserProcessEx",
            "7ff7e09c325d C:\\Windows\\System32\\smss.exe!?",
            "7ff7e09c4b19 C:\\Windows\\System32\\smss.exe!?",
            "7ff7e09c5d72 C:\\Windows\\System32\\smss.exe!?",
            "7ffa53738255 C:\\Windows\\System32\\ntdll.dll!RtlSetThreadSubProcessTag",
            "7ffa53735fe3 C:\\Windows\\System32\\ntdll.dll!RtlSetThreadSubProcessTag",
            "7ffa5374c412 C:\\Windows\\System32\\ntdll.dll!RtlUserThreadStart"
          ],
          "proc": {
            "pid": 4936,
            "tid": 464,
            "ppid": 440,
            "name": "smss.exe",
            "exe": "C:\\WINDOWS\\System32\\smss.exe",
            "cmdline": "\\SystemRoot\\System32\\smss.exe 00000124 000000b8 winlogon.exe {F481D527-E8FA-457D-87F9-084B51C10000}",
            "parent_name": "smss.exe",
            "parent_cmdline": "\\SystemRoot\\System32\\smss.exe",
            "sid": "S-1-5-18",
            "username": "SYSTEM",
            "domain": "NT AUTHORITY",
            "session_id": 3,
            "integrity_level": "SYSTEM",
            "is_wow64": false,
            "is_packaged": false,
            "is_protected": true,
            "ancestors": [
              "smss.exe (440)",
              "System (4)",
              "Idle (0)",
              "Idle (0)"
            ]
          }
        },
        {
          "name": "CreateProcess",
          "category": "process",
          "timestamp": "2026-04-25T11:16:16.3715241+02:00",
          "params": {
            "cmdline": "%SystemRoot%\\system32\\csrss.exe ObjectDirectory=\\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16",
            "directory_table_base": "1f837b000",
            "domain": "NT AUTHORITY",
            "exe": "C:\\WINDOWS\\system32\\csrss.exe",
            "exit_status": "Success",
            "flags": "PROTECTED",
            "kproc": "ffffb20eb60c6080",
            "name": "csrss.exe",
            "pid": 7032,
            "ppid": 4936,
            "real_ppid": 4936,
            "session_id": 3,
            "sid": "S-1-5-18",
            "start_time": "2026-04-25 11:16:16.3715037 +0200 CEST",
            "token_elevation_type": "DEFAULT",
            "token_integrity_level": "SYSTEM",
            "token_is_elevated": true,
            "username": "SYSTEM"
          },
          "callstack": [
            "fffff8068ebe0c94 unbacked!",
            "fffff8068ea589af unbacked!",
            "fffff8068eb991c2 unbacked!",
            "fffff8068f1458ee unbacked!",
            "fffff8068f145624 unbacked!",
            "fffff8068f0a0a21 unbacked!",
            "fffff8068f2c956e unbacked!",
            "fffff8068eebd955 unbacked!",
            "7ffa53823514 C:\\Windows\\System32\\ntdll.dll!ZwCreateUserProcess",
            "7ffa537bd0ad C:\\Windows\\System32\\ntdll.dll!RtlNormalizeProcessParams",
            "7ffa537bcc54 C:\\Windows\\System32\\ntdll.dll!RtlCreateUserProcessEx",
            "7ff7e09c325d C:\\Windows\\System32\\smss.exe!?",
            "7ff7e09c2e6c C:\\Windows\\System32\\smss.exe!?",
            "7ff7e09c29f5 C:\\Windows\\System32\\smss.exe!?",
            "7ff7e09c194a C:\\Windows\\System32\\smss.exe!?",
            "7ff7e09c1316 C:\\Windows\\System32\\smss.exe!?",
            "7ff7e09c11a6 C:\\Windows\\System32\\smss.exe!?",
            "7ffa5374c412 C:\\Windows\\System32\\ntdll.dll!RtlUserThreadStart"
          ],
          "proc": {
            "pid": 7032,
            "tid": 3480,
            "ppid": 4936,
            "name": "csrss.exe",
            "exe": "C:\\WINDOWS\\system32\\csrss.exe",
            "cmdline": "%SystemRoot%\\system32\\csrss.exe ObjectDirectory=\\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16",
            "parent_name": "smss.exe",
            "parent_cmdline": "\\SystemRoot\\System32\\smss.exe 00000124 000000b8 winlogon.exe {F481D527-E8FA-457D-87F9-084B51C10000}",
            "sid": "S-1-5-18",
            "username": "SYSTEM",
            "domain": "NT AUTHORITY",
            "session_id": 3,
            "integrity_level": "SYSTEM",
            "is_wow64": false,
            "is_packaged": false,
            "is_protected": true,
            "ancestors": [
              "smss.exe (4936)",
              "smss.exe (440)",
              "System (4)",
              "Idle (0)",
              "Idle (0)"
            ]
          }
        }
      ]
    }
    {
      "id": "4ab688f7-94e2-481b-9c7f-c49f3a79a379",
      "title": "Suspicious access to Windows Credential Manager files",
      "severity": "low",
      "description": "Identifies suspicious processes trying to acquire credentials from the Windows Credential Manager.\n",
      "labels": {
        "subtechnique.id": "T1555.004",
        "subtechnique.name": "Windows Credential Manager",
        "subtechnique.ref": "https://attack.mitre.org/techniques/T1555/004/",
        "tactic.id": "TA0006",
        "tactic.name": "Credential Access",
        "tactic.ref": "https://attack.mitre.org/tactics/TA0006/",
        "technique.id": "T1555",
        "technique.name": "Credentials from Password Stores",
        "technique.ref": "https://attack.mitre.org/techniques/T1555/"
      },
      "events": [
        {
          "name": "CreateFile",
          "category": "file",
          "timestamp": "2026-04-25T11:09:46.5522279+02:00",
          "params": {
            "attributes": "",
            "create_disposition": "OPEN",
            "create_options": "SYNCHRONOUS_IO_NONALERT",
            "file_object": "ffffb20eb8391c10",
            "file_path": "C:\\Users\\rededr\\AppData\\Local\\Microsoft\\Credentials\\DFBE70A7E5CC19A398EBF1B96859CE5D",
            "irp": "ffffb20ebb361428",
            "share_mask": "READ|WRITE|DELETE",
            "status": "Success",
            "tid": 9208,
            "type": "Directory"
          },
          "callstack": [
            "fffff8068ebe0c94 unbacked!",
            "fffff8068ea589af unbacked!",
            "fffff8068eb22f86 unbacked!",
            "fffff80621c06d24 unbacked!",
            "fffff8062048baaf unbacked!",
            "fffff8062048b1a0 unbacked!",
            "fffff806204f68e0 unbacked!",
            "fffff8068eba953b unbacked!",
            "fffff8068eba94b3 unbacked!",
            "fffff8068f09a83b unbacked!",
            "fffff8068f098812 unbacked!",
            "fffff8068f0965e3 unbacked!",
            "fffff8068f1664bf unbacked!",
            "fffff8068f165699 unbacked!",
            "fffff8068eebd955 unbacked!",
            "7ffa538225a4 C:\\Windows\\System32\\ntdll.dll!ZwCreateFile",
            "7ffa50de5537 C:\\Windows\\System32\\KernelBase.dll!GetDriveTypeW",
            "7ffa50de6e27 C:\\Windows\\System32\\KernelBase.dll!CreateFileW",
            "7ffa47f7a623 C:\\Windows\\System32\\sysmain.dll!?",
            "7ffa47f7877e C:\\Windows\\System32\\sysmain.dll!?",
            "7ffa47f781e7 C:\\Windows\\System32\\sysmain.dll!?",
            "7ffa47f738d0 C:\\Windows\\System32\\sysmain.dll!?",
            "7ffa47f7474c C:\\Windows\\System32\\sysmain.dll!?",
            "7ffa47f74fe1 C:\\Windows\\System32\\sysmain.dll!?",
            "7ffa47fddcb5 C:\\Windows\\System32\\sysmain.dll!PfSvUnattendCallback",
            "7ffa5269e8d7 C:\\Windows\\System32\\kernel32.dll!BaseThreadInitThunk",
            "7ffa5374c3fc C:\\Windows\\System32\\ntdll.dll!RtlUserThreadStart"
          ],
          "proc": {
            "pid": 1044,
            "tid": 9208,
            "ppid": 824,
            "name": "svchost.exe",
            "exe": "C:\\WINDOWS\\system32\\svchost.exe",
            "cmdline": "C:\\WINDOWS\\system32\\svchost.exe -k LocalSystemNetworkRestricted -p -s SysMain",
            "parent_name": "services.exe",
            "parent_cmdline": "C:\\WINDOWS\\system32\\services.exe",
            "cwd": "C:\\WINDOWS\\system32\\",
            "sid": "S-1-5-18",
            "username": "SYSTEM",
            "domain": "NT AUTHORITY",
            "session_id": 0,
            "integrity_level": "",
            "is_wow64": false,
            "is_packaged": false,
            "is_protected": false,
            "ancestors": [
              "services.exe (824)",
              "wininit.exe (680)"
            ]
          }
        }
      ]
    }
  5. rabbitstack commented on Apr 25, 2026

    @rabbitstack
    Owner

    Thanks for posting those. We'll reduce the noise

  6. rabbitstack commented on Apr 26, 2026

    @rabbitstack
    Owner

    @dobin Feel free to consume the exceptions from this pull request.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions