Suspicious Child Processes Spawned by AMMYYAdmin

Rule Info

Name
Suspicious Child Processes Spawned by AMMYYAdmin
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects suspicious child processes spawned by AMMYYAdmin process. This could indicate the presence of a remote management tool (RMM) or remote access tool (RAT) on the system. Threat actors may use these tools to gain unauthorized access to systems and networks and perform malicious activities.
Reference
Internal Research
Date
2026-02-11 00:00:00
Modified
None
Id
79efb7b2-c7b0-4f68-9180-26af4ea6a614
Tags
attack.command-and-control attack.t1219.002
Type
Nextron Sigma feed only (private)

Rule History