← Back to SOC feed Coverage →

IsWindowsGUI

yara LOW Yara-Rules
community
This rule was pulled from an open-source repository and enriched with AI. Validate in a test environment before deploying to production.
View original rule at Yara-Rules →
Retrieved: 2026-09-22T11:00:00Z · Confidence: medium

Hunt Hypothesis

This rule identifies Windows processes that are configured as GUI applications, which may indicate an adversary attempting to interact with the user interface or establish a foothold for lateral movement. Proactively hunting for these instances helps the SOC team distinguish between legitimate interactive sessions and potential malicious activity, ensuring that unexpected GUI processes are investigated for signs of compromise or unauthorized access.

YARA Rule

rule IsWindowsGUI : PECheck
{
	condition:
		// MZ signature at offset 0 and ...
		uint16(0) == 0x5A4D and
		// ... PE signature at offset stored in MZ header at 0x3C
		uint16(uint32(0x3C)+0x5C) == 0x0002
}

Deployment Notes

This YARA rule can be deployed in the following contexts:

False Positive Guidance

Original source: https://github.com/Yara-Rules/rules/blob/main/packers/packer_compiler_signatures.yar