AN1610
Analytic 1610
Windows
Abuse of JamPlus.exe to launch malicious payloads via crafted .jam files, resulting in abnormal process creation, command execution, or artifact generation outside of standard development workflows.
WinEventLog:Security
EventCode=4688
WinEventLog:Sysmon
EventCode=11
WinEventLog:Sysmon
EventCode=3, 22
WinEventLog:Microsoft-Windows-CodeIntegrity/Operational
Unsigned or untrusted modules loaded during JamPlus.exe runtime
[TimeWindow]
Correlation time window (e.g., 0–30 minutes) for JamPlus.exe execution, child processes, and file/network events.
[AllowedBuildHosts]
Known developer systems where JamPlus.exe usage is expected; alerts are raised if executed elsewhere.
[SuspiciousChildList]
Child processes considered anomalous (e.g., PowerShell, cmd, wscript) when spawned by JamPlus.exe.
[RarePathRegex]
Regex patterns for non-standard or user-writable paths where JamPlus.exe drops artifacts.