Log source category
file_event log source Sigma rules
244 Sigma detection rules in the library use the file_event log source, mostly on windows, linux, macos. The file_event category groups related telemetry so you can find detections that consume the same events. Open a rule to read its detection logic, MITRE ATT&CK mapping and original YAML.
Products
Severity
APT29 2018 Phishing Campaign File Indicators
criticalDetects indicators of APT 29 (Cozy Bear) phishing-campaign as reported by mandiant
windows
CVE-2021-1675 Print Spooler Exploitation Filename Pattern
criticalDetects the default filename used in PoC code against print spooler vulnerability CVE-2021-1675
windows
CVE-2021-31979 CVE-2021-33771 Exploits by Sourgum
criticalDetects patterns as noticed in exploitation of Windows CVE-2021-31979 CVE-2021-33771 vulnerability and DevilsTongue malware by threat group Sourgum
windows
HackTool - Dumpert Process Dumper Default File
criticalDetects the creation of the default dump file used by Outflank Dumpert tool. A process dumper, which dumps the lsass process memory
windows
HackTool - Inveigh Execution Artefacts
criticalDetects the presence and execution of Inveigh via dropped artefacts
windows
HackTool - Mimikatz Kirbi File Creation
criticalDetects the creation of files created by mimikatz such as ".kirbi", "mimilsa.log", etc.
windows
HackTool - QuarksPwDump Dump File
criticalDetects a dump file written by QuarksPwDump password dumper
windows
InstallerFileTakeOver LPE CVE-2021-41379 File Create Event
criticalDetects signs of the exploitation of LPE CVE-2021-41379 that include an msiexec process that creates an elevation_service.exe file
windows
Moriya Rootkit File Created
criticalDetects the creation of a file named "MoriyaStreamWatchmen.sys" in a specific location. This filename was reported to be related to the Moriya rootkit as described in the securelist's Operation TunnelSnake report.
windows
Potential DCOM InternetExplorer.Application DLL Hijack
criticalDetects potential DLL hijack of "iertutil.dll" found in the DCOM InternetExplorer.Application Class over the network
windows
Potential SharePoint ToolShell CVE-2025-53770 Exploitation - File Create
criticalDetects the creation of file such as spinstall0.aspx which may indicate successful exploitation of CVE-2025-53770. CVE-2025-53770 is a zero-day vulnerability in SharePoint that allows remote code execution.
windows
RedSun - TieringEngineService.exe Staged in RS-Prefixed Temp Dir
criticalDetects the creation of a file named TieringEngineService.exe inside a directory whose path contains the RS- prefix characteristic of RedSun's staging directory (e.g. %TEMP%\RS-{GUID}\TieringEngineService.exe). RedSun registers a Cloud Files sync root under this RS-prefixed path and drops a masqueraded placeholder there as part of its oplock-based AV bypass and privilege escalation chain. The RS-{GUID} directory name is generated by RedSun itself and has no legitimate system usage, making the combination of this path prefix and the TieringEngineService.exe filename a highly specific indicator of RedSun activity.
windows
SNAKE Malware Kernel Driver File Indicator
criticalDetects SNAKE malware kernel driver file indicator
windows
Wmiexec Default Output File
criticalDetects the creation of the default output filename used by the wmiexec tool
windows
Wmiprvse Wbemcomn DLL Hijack - File
criticalDetects a threat actor creating a file named `wbemcomn.dll` in the `C:\Windows\System32\wbem\` directory over the network and loading it for a WMI DLL Hijack scenario.
windows
.RDP File Created By Uncommon Application
highDetects creation of a file with an ".rdp" extension by an application that doesn't commonly create such files.
windows
Adwind RAT / JRAT File Artifact
highDetects javaw.exe in AppData folder as used by Adwind / JRAT
windows
Atomic MacOS Stealer - Persistence Indicators
highDetects creation of persistence artifacts placed by Atomic MacOS Stealer in macOS systems. Recent Atomic MacOS Stealer variants have been observed dropping these to maintain persistent access after compromise.
macos
Axios NPM Compromise File Creation Indicators - Linux
highDetects file creation events linked to the Axios NPM supply chain compromise. Axios is a popular JavaScript HTTP client. On March 30, 2026, malicious versions (1.14.1, 0.30.4) were published to npm, injecting a dependency (plain-crypto-js@4.2.1) that executed a postinstall script as a cross-platform RAT dropper.
linux
Axios NPM Compromise File Creation Indicators - MacOS
highDetects file creation events linked to the Axios NPM supply chain compromise on macOS devices. Axios is a popular JavaScript HTTP client. On March 30, 2026, malicious versions (1.14.1, 0.30.4) were published to npm, injecting a dependency (plain-crypto-js@4.2.1) that executed a postinstall script as a cross-platform RAT dropper.
macos
Axios NPM Compromise File Creation Indicators - Windows
highDetects file creation events linked to the Axios NPM supply chain compromise. Axios is a popular JavaScript HTTP client. On March 30, 2026, malicious versions (1.14.1, 0.30.4) were published to npm, injecting a dependency (plain-crypto-js@4.2.1) that executed a postinstall script as a cross-platform RAT dropper. The dropper contacted a C2 server, delivered platform-specific payloads, deleted itself, and replaced package.json to evade detection. The attack used cscript.exe (VBScript), curl.exe (C2), and PowerShell masquerading as Windows Terminal.
windows
BloodHound Collection Files
highDetects default file names outputted by the BloodHound collection tool SharpHound
windows
Creation Exe for Service with Unquoted Path
highAdversaries may execute their own malicious payloads by hijacking vulnerable file path references. Adversaries can take advantage of paths that lack surrounding quotations by placing an executable in a higher level directory within the path, so that Windows will choose the adversary's executable to launch.
windows
Cred Dump Tools Dropped Files
highFiles with well-known filenames (parts of credential dump software or files produced by them) creation
windows
CVE-2021-26858 Exchange Exploitation
highDetects possible successful exploitation for vulnerability described in CVE-2021-26858 by looking for creation of non-standard files on disk by Exchange Server’s Unified Messaging service which could indicate dropping web shells or other malicious content
windows
CVE-2021-44077 POC Default Dropped File
highDetects the creation of "msiexec.exe" in the "bin" directory of the ManageEngine SupportCenter Plus (Related to CVE-2021-44077) and public POC available (See references section)
windows
CVE-2022-24527 Microsoft Connected Cache LPE
highDetects files created during the local privilege exploitation of CVE-2022-24527 Microsoft Connected Cache
windows
CVE-2023-38331 Exploitation Attempt - Suspicious Double Extension File
highDetects the creation of a file with a double extension and a space by WinRAR. This could be a sign of exploitation of CVE-2023-38331
windows
Diamond Sleet APT File Creation Indicators
highDetects file creation activity that is related to Diamond Sleet APT activity
windows
DLL Search Order Hijackig Via Additional Space in Path
highDetects when an attacker create a similar folder structure to windows system folders such as (Windows, Program Files...) but with a space in order to trick DLL load search order and perform a "DLL Search Order Hijacking" attack
windows
DPAPI Backup Keys And Certificate Export Activity IOC
highDetects file names with specific patterns seen generated and used by tools such as Mimikatz and DSInternals related to exported or stolen DPAPI backup keys and certificates.
windows
File Creation In Suspicious Directory By Msdt.EXE
highDetects msdt.exe creating files in suspicious directories which could be a sign of exploitation of either Follina or Dogwalk vulnerabilities
windows
File Creation Related To RAT Clients
highFile .conf created related to VenomRAT, AsyncRAT and Lummac samples observed in the wild.
windows
File With Uncommon Extension Created By An Office Application
highDetects the creation of files with an executable or script extension by an Office application.
windows
Forest Blizzard APT - File Creation Activity
highDetects the creation of specific files inside of ProgramData directory. These files were seen being created by Forest Blizzard as described by MSFT.
windows
FunkLocker Ransomware File Creation
highDetects the creation of files with the ".funksec" extension, which is appended to encrypted files by the FunkLocker ransomware.
windows
Goofy Guineapig Backdoor IOC
highDetects malicious indicators seen used by the Goofy Guineapig malware
windows
HackTool - CrackMapExec File Indicators
highDetects file creation events with filename patterns used by CrackMapExec.
windows
HackTool - Impacket File Indicators
highDetects file creation events with filename patterns used by Impacket.
windows
HackTool - NetExec File Indicators
highDetects file creation events indicating NetExec (nxc.exe) execution on the local machine. NetExec is a PyInstaller-bundled binary that extracts its embedded data files to a "_MEI<random>" directory under the Temp folder upon execution. Files dropped under the "\nxc\" sub-directory of that extraction path are unique to NetExec and serve as reliable on-disk indicators of execution. NetExec (formerly CrackMapExec) is a widely used post-exploitation and lateral movement tool used for Active Directory enumeration, credential harvesting, and remote code execution.
windows
HackTool - NPPSpy Hacktool Usage
highDetects the use of NPPSpy hacktool that stores cleartext passwords of users that logged in to a local file
windows
HackTool - Potential Remote Credential Dumping Activity Via CrackMapExec Or Impacket-Secretsdump
highDetects default filenames output from the execution of CrackMapExec and Impacket-secretsdump against an endpoint.
windows
HackTool - Powerup Write Hijack DLL
highPowerup tool's Write Hijack DLL exploits DLL hijacking for privilege escalation. In it's default mode, it builds a self deleting .bat file which executes malicious command. The detection rule relies on creation of the malicious bat file (debug.bat by default).
windows
HackTool - RemoteKrbRelay SMB Relay Secrets Dump Module Indicators
highDetects the creation of file with specific names used by RemoteKrbRelay SMB Relay attack module.
windows
HackTool - SafetyKatz Dump Indicator
highDetects default lsass dump filename generated by SafetyKatz.
windows
HackTool - Typical HiveNightmare SAM File Export
highDetects files written by the different tools that exploit HiveNightmare
windows
Hijack Legit RDP Session to Move Laterally
highDetects the usage of tsclient share to place a backdoor on the RDP source machine's startup folder
windows
ISO File Created Within Temp Folders
highDetects the creation of a ISO file in the Outlook temp folder or in the Appdata temp folder. Typical of Qakbot TTP from end-July 2022.
windows
Lace Tempest File Indicators
highDetects PowerShell script file creation with specific names or suffixes which was seen being used often in PowerShell scripts by FIN7
windows
Legitimate Application Dropped Archive
highDetects programs on a Windows system that should not write an archive to disk
windows
Legitimate Application Dropped Executable
highDetects LOLBINs and applications that should not legitimately drop executable or executable-equivalent files to disk. This may indicate malware staging, process injection, or abuse of a trusted binary for payload delivery.
windows
Legitimate Application Dropped Script
highDetects LOLBINs and applications that should not legitimately drop script files to disk. This may indicate malware staging or abuse of a trusted binary for script-based code execution.
windows
Legitimate Application Writing Files In Uncommon Location
highDetects legitimate applications writing any type of file to uncommon or suspicious locations that are not typical for application data storage or execution. Adversaries may leverage legitimate applications (Living off the Land Binaries - LOLBins) to drop or download malicious files to uncommon locations on the system to evade detection by security solutions.
windows
LiveKD Driver Creation By Uncommon Process
highDetects the creation of the LiveKD driver by a process image other than "livekd.exe".
windows
LiveKD Kernel Memory Dump File Created
highDetects the creation of a file that has the same name as the default LiveKD kernel memory dump.
windows
LSASS Process Dump Artefact In CrashDumps Folder
highDetects the presence of an LSASS dump file in the "CrashDumps" folder. This could be a sign of LSASS credential dumping. Techniques such as the LSASS Shtinkering have been seen abusing the Windows Error Reporting to dump said process.
windows
LSASS Process Memory Dump Creation Via Taskmgr.EXE
highDetects the creation of an "lsass.dmp" file by the taskmgr process. This indicates a manual dumping of the LSASS.exe process memory using Windows Task Manager.
windows
LSASS Process Memory Dump Files
highDetects creation of files with names used by different memory dumping tools to create a memory dump of the LSASS process memory, which contains user credentials.
windows
Malicious DLL File Dropped in the Teams or OneDrive Folder
highDetects creation of a malicious DLL file in the location where the OneDrive or Team applications Upon execution of the Teams or OneDrive application, the dropped malicious DLL file ("iphlpapi.dll") is sideloaded
windows
Malicious PowerShell Scripts - FileCreation
highDetects the creation of known offensive powershell scripts used for exploitation
windows
Non-Standard Nsswitch.Conf Creation - Potential CVE-2025-32463 Exploitation
highDetects the creation of nsswitch.conf files in non-standard directories, which may indicate exploitation of CVE-2025-32463. This vulnerability requires an attacker to create a nsswitch.conf in a directory that will be used during sudo chroot operations. When sudo executes, it loads malicious shared libraries from user-controlled locations within the chroot environment, potentially leading to arbitrary code execution and privilege escalation.
linux
NTDS Exfiltration Filename Patterns
highDetects creation of files with specific name patterns seen used in various tools that export the NTDS.DIT for exfiltration.
windows
NTDS.DIT Creation By Uncommon Parent Process
highDetects creation of a file named "ntds.dit" (Active Directory Database) by an uncommon parent process or directory
windows
NTDS.DIT Creation By Uncommon Process
highDetects creation of a file named "ntds.dit" (Active Directory Database) by an uncommon process or a process located in a suspicious directory
windows
Octopus Scanner Malware
highDetects Octopus Scanner Malware.
windows
Office Macro File Creation From Suspicious Process
highDetects the creation of a office macro file from a a suspicious process
windows
Onyx Sleet APT File Creation Indicators
highDetects file creation activity that is related to Onyx Sleet APT activity
windows
PCRE.NET Package Temp Files
highDetects processes creating temp files related to PCRE.NET package
windows
PDF File Created By RegEdit.EXE
highDetects the creation of a file with the ".pdf" extension by the "RegEdit.exe" process. This indicates that a user is trying to print/save a registry key as a PDF in order to potentially extract sensitive information and bypass defenses.
windows
Pingback Backdoor File Indicators
highDetects the use of Pingback backdoor that creates ICMP tunnel for C2 as described in the trustwave report
windows
Potential APT FIN7 Related PowerShell Script Created
highDetects PowerShell script file creation with specific name or suffix which was seen being used often by FIN7 PowerShell scripts
windows
Potential COLDSTEEL Persistence Service DLL Creation
highDetects the creation of a file in a specific location and with a specific name related to COLDSTEEL RAT
windows
Potential COLDSTEEL RAT File Indicators
highDetects the creation of a file named "dllhost.exe" in the "C:\users\public\Documents\" directory. Seen being used by the COLDSTEEL RAT in some of its variants.
windows
Potential CVE-2023-27363 Exploitation - HTA File Creation By FoxitPDFReader
highDetects suspicious ".hta" file creation in the startup folder by Foxit Reader. This can be an indication of CVE-2023-27363 exploitation.
windows
Potential CVE-2023-36874 Exploitation - Fake Wermgr.Exe Creation
highDetects the creation of a file named "wermgr.exe" being created in an uncommon directory. This could be a sign of potential exploitation of CVE-2023-36874.
windows
Potential Devil Bait Related Indicator
highDetects the creation of ".xml" and ".txt" files in folders of the "\AppData\Roaming\Microsoft" directory by uncommon processes. This behavior was seen common across different Devil Bait samples and stages as described by the NCSC
windows
Potential File Extension Spoofing Using Right-to-Left Override
highDetects suspicious filenames that contain a right-to-left override character and a potentially spoofed file extensions.
windows
Potential Kapeka Decrypted Backdoor Indicator
highDetects the presence of a file that is decrypted backdoor binary dropped by the Kapeka Dropper, which disguises itself as a hidden file under a folder named "Microsoft" within "CSIDL_COMMON_APPDATA" or "CSIDL_LOCAL_APPDATA", depending on the process privileges. The file, typically 5-6 characters long with a random combination of consonants and vowels followed by a ".wll" extension to pose as a legitimate file to evade detection.
windows
Potential MOVEit Transfer CVE-2023-34362 Exploitation - File Activity
highDetects file indicators of potential exploitation of MOVEit CVE-2023-34362.
windows
Potential Persistence Via Microsoft Office Add-In
highDetects potential persistence activity via startup add-ins that load when Microsoft Office starts (.wll/.xll are simply .dll fit for Word or Excel).
windows
Potential Persistence Via Microsoft Office Startup Folder
highDetects creation of Microsoft Office files inside of one of the default startup folders in order to achieve persistence.
windows
Potential Persistence Via Outlook Form
highDetects the creation of a new Outlook form which can contain malicious code
windows
Potential Privilege Escalation Attempt Via .Exe.Local Technique
highDetects potential privilege escalation attempt via the creation of the "*.Exe.Local" folder inside the "System32" directory in order to sideload "comctl32.dll"
windows
Potential RipZip Attack on Startup Folder
highDetects a phishing attack which expands a ZIP file containing a malicious shortcut. If the victim expands the ZIP file via the explorer process, then the explorer process expands the malicious ZIP file and drops a malicious shortcut redirected to a backdoor into the Startup folder. Additionally, the file name of the malicious shortcut in Startup folder contains {0AFACED1-E828-11D1-9187-B532F1E9575D} meaning the folder shortcut operation.
windows
Potential SAM Database Dump
highDetects the creation of files that look like exports of the local SAM (Security Account Manager)
windows
Potential Startup Shortcut Persistence Via PowerShell.EXE
highDetects PowerShell writing startup shortcuts. This procedure was highlighted in Red Canary Intel Insights Oct. 2021, "We frequently observe adversaries using PowerShell to write malicious .lnk files into the startup directory to establish persistence. Accordingly, this detection opportunity is likely to identify persistence mechanisms in multiple threats. In the context of Yellow Cockatoo, this persistence mechanism eventually launches the command-line script that leads to the installation of a malicious DLL"
windows
Potential Winnti Dropper Activity
highDetects files dropped by Winnti as described in RedMimicry Winnti playbook
windows
Process Explorer Driver Creation By Non-Sysinternals Binary
highDetects creation of the Process Explorer drivers by processes other than Process Explorer (procexp) itself. Hack tools or malware may use the Process Explorer driver to elevate privileges, drops it to disk for a few moments, runs a service using that driver and removes it afterwards.
windows
PSEXEC Remote Execution File Artefact
highDetects creation of the PSEXEC key file. Which is created anytime a PsExec command is executed. It gets written to the file system and will be recorded in the USN Journal on the target system
windows
Registry Hive File Staged Outside Standard User Profile Path
highDetects the creation of a registry hive file (UsrClass.dat or NTUSER.DAT) outside of the standard user profile path. These files generally contain various user-specific registry settings and are typically located in the user's profile directory. Staging these files outside of the standard path can be indicative of an attacker attempting to manipulate user registry settings for persistence, privilege escalation, or dump user registry hives for credential harvesting.
windows
Renamed VsCode Code Tunnel Execution - File Indicator
highDetects the creation of a file with the name "code_tunnel.json" which indicate execution and usage of VsCode tunneling utility by an "Image" or "Process" other than VsCode.
windows
ScreenConnect - SlashAndGrab Exploitation Indicators
highDetects indicators of exploitation by threat actors during exploitation of the "SlashAndGrab" vulnerability related to ScreenConnect as reported Team Huntress
windows
Shai-Hulud Malicious GitHub Workflow Creation
highDetects creation of shai-hulud-workflow.yml file associated with Shai Hulud worm targeting NPM supply chain attack that exfiltrates GitHub secrets
linux
Small Sieve Malware File Indicator Creation
highDetects filename indicators that contain a specific typo seen used by the Small Sieve malware.
windows
SNAKE Malware WerFault Persistence File Creation
highDetects the creation of a file named "WerFault.exe" in the WinSxS directory by a non-system process, which can be indicative of potential SNAKE malware activity
windows
Suspicious ASPX File Drop by Exchange
highDetects suspicious file type dropped by an Exchange component in IIS into a suspicious folder
windows
Suspicious Binaries and Scripts in Public Folder
highDetects the creation of a file with a suspicious extension in the public folder, which could indicate potential malicious activity.
windows
Suspicious Binary Writes Via AnyDesk
highDetects AnyDesk writing binary files to disk other than "gcapi.dll". According to RedCanary research it is highly abnormal for AnyDesk to write executable files to disk besides gcapi.dll, which is a legitimate DLL that is part of the Google Chrome web browser used to interact with the Google Cloud API. (See reference section for more details)
windows
Suspicious Creation with Colorcpl
highOnce executed, colorcpl.exe will copy the arbitrary file to c:\windows\system32\spool\drivers\color\
windows
Suspicious Desktopimgdownldr Target File
highDetects a suspicious Microsoft desktopimgdownldr file creation that stores a file to a suspicious location or contains a file with a suspicious extension
windows
Suspicious DotNET CLR Usage Log Artifact
highDetects the creation of Usage Log files by the CLR (clr.dll). These files are named after the executing process once the assembly is finished executing for the first time in the (user) session context.
windows
Suspicious Double Extension Files
highDetects dropped files with double extensions, which is often used by malware as a method to abuse the fact that Windows hide default extensions by default.
windows
Suspicious Executable File Creation
highDetect creation of suspicious executable file names. Some strings look for suspicious file extensions, others look for filenames that exploit unquoted service paths.
windows
Suspicious File Created by ArcSOC.exe
highDetects instances where the ArcGIS Server process ArcSOC.exe, which hosts REST services running on an ArcGIS server, creates a file with suspicious file type, indicating that it may be an executable, script file, or otherwise unusual.
windows
Suspicious File Created in Outlook Temporary Directory
highDetects the creation of files with suspicious file extensions in the temporary directory that Outlook uses when opening attachments. This can be used to detect spear-phishing campaigns that use suspicious files as attachments, which may contain malicious code.
windows
Suspicious File Created Via OneNote Application
highDetects suspicious files created via the OneNote application. This could indicate a potential malicious ".one"/".onepkg" file was executed as seen being used in malware activity in the wild
windows
Suspicious File Creation Activity From Fake Recycle.Bin Folder
highDetects file write event from/to a fake recycle bin folder that is often used as a staging directory for malware
windows
Suspicious File Creation In Uncommon AppData Folder
highDetects the creation of suspicious files and folders inside the user's AppData folder but not inside any of the common and well known directories (Local, Romaing, LocalLow). This method could be used as a method to bypass detection who exclude the AppData folder in fear of FPs
windows
Suspicious File Write to SharePoint Layouts Directory
highDetects suspicious file writes to SharePoint layouts directory which could indicate webshell activity or post-exploitation. This behavior has been observed in the exploitation of SharePoint vulnerabilities such as CVE-2025-49704, CVE-2025-49706 or CVE-2025-53770.
windows
Suspicious Filename with Embedded Base64 Commands
highDetects files with specially crafted filenames that embed Base64-encoded bash payloads designed to execute when processed by shell scripts. These filenames exploit shell interpretation quirks to trigger hidden commands, a technique observed in VShell malware campaigns.
linux
Suspicious Get-Variable.exe Creation
highGet-Variable is a valid PowerShell cmdlet WindowsApps is by default in the path where PowerShell is executed. So when the Get-Variable command is issued on PowerShell execution, the system first looks for the Get-Variable executable in the path and executes the malicious binary instead of looking for the PowerShell cmdlet.
windows
Suspicious Interactive PowerShell as SYSTEM
highDetects the creation of files that indicator an interactive use of PowerShell in the SYSTEM user context
windows
Suspicious MSExchangeMailboxReplication ASPX Write
highDetects suspicious activity in which the MSExchangeMailboxReplication process writes .asp and .apsx files to disk, which could be a sign of ProxyShell exploitation
windows
Suspicious Outlook Macro Created
highDetects the creation of a macro file for Outlook.
windows
Suspicious Scheduled Task Write to System32 Tasks
highDetects the creation of tasks from processes executed from suspicious locations
windows
Suspicious Startup Folder Persistence
highDetects the creation of potentially malicious script and executable files in Windows startup folders, which is a common persistence technique used by threat actors. These files (.ps1, .vbs, .js, .bat, etc.) are automatically executed when a user logs in, making the Startup folder an attractive target for attackers. This technique is frequently observed in malvertising campaigns and malware distribution where attackers attempt to maintain long-term access to compromised systems.
windows
Suspicious Word Cab File Write CVE-2021-40444
highDetects file creation patterns noticeable during the exploitation of CVE-2021-40444
windows
TeamPCP LiteLLM Supply Chain Attack Persistence Indicators
highDetects the creation of specific persistence files as observed in the LiteLLM PyPI supply chain attack. In March 2026, a supply chain attack was discovered involving the popular open-source LLM framework LiteLLM by Threat Actor TeamPCP. The malicious package harvests every credential on the system, encrypts and exfiltrates them, and installs a persistent C2 backdoor.
linux
Triple Cross eBPF Rootkit Default LockFile
highDetects the creation of the file "rootlog" which is used by the TripleCross rootkit as a way to check if the backdoor is already running.
linux
Triple Cross eBPF Rootkit Default Persistence
highDetects the creation of "ebpfbackdoor" files in both "cron.d" and "sudoers.d" directories. Which both are related to the TripleCross persistence method
linux
UAC Bypass Abusing Winsat Path Parsing - File
highDetects the pattern of UAC Bypass using a path parsing issue in winsat.exe (UACMe 52)
windows
UAC Bypass Using .NET Code Profiler on MMC
highDetects the pattern of UAC Bypass using .NET Code Profiler and mmc.exe DLL hijacking (UACMe 39)
windows
UAC Bypass Using Consent and Comctl32 - File
highDetects the pattern of UAC Bypass using consent.exe and comctl32.dll (UACMe 22)
windows
UAC Bypass Using EventVwr
highDetects the pattern of a UAC bypass using Windows Event Viewer
windows
UAC Bypass Using IDiagnostic Profile - File
highDetects the creation of a file by "dllhost.exe" in System32 directory part of "IDiagnosticProfileUAC" UAC bypass technique
windows
UAC Bypass Using IEInstal - File
highDetects the pattern of UAC Bypass using IEInstal.exe (UACMe 64)
windows
UAC Bypass Using MSConfig Token Modification - File
highDetects the pattern of UAC Bypass using a msconfig GUI hack (UACMe 55)
windows
UAC Bypass Using NTFS Reparse Point - File
highDetects the pattern of UAC Bypass using NTFS reparse point and wusa.exe DLL hijacking (UACMe 36)
windows
UAC Bypass Using Windows Media Player - File
highDetects the pattern of UAC Bypass using Windows Media Player osksupport.dll (UACMe 32)
windows
UEFI Persistence Via Wpbbin - FileCreation
highDetects creation of a file named "wpbbin" in the "%systemroot%\system32\" directory. Which could be indicative of UEFI based persistence method
windows
UNC4841 - Barracuda ESG Exploitation Indicators
highDetects file indicators as seen used by UNC4841 during their Barracuda ESG zero day exploitation.
linux
UNC4841 - Email Exfiltration File Pattern
highDetects filename pattern of email related data used by UNC4841 for staging and exfiltration
linux
Uncommon File Created by Notepad++ Updater Gup.EXE
highDetects when the Notepad++ updater (gup.exe) creates files in suspicious or uncommon locations. This could indicate potential exploitation of the updater component to deliver unwanted malware or unwarranted files.
windows
Uncommon File Created In Office Startup Folder
highDetects the creation of a file with an uncommon extension in an Office application startup folder
windows
Uncommon File Creation By Mysql Daemon Process
highDetects the creation of files with scripting or executable extensions by Mysql daemon. Which could be an indicator of "User Defined Functions" abuse to download malware.
windows
WerFault LSASS Process Memory Dump
highDetects WerFault creating a dump file with a name that indicates that the dump file could be an LSASS process memory, which contains user credentials
windows
Windows Binaries Write Suspicious Extensions
highDetects Windows executables that write files with suspicious extensions
windows
Windows Shell/Scripting Application File Write to Suspicious Folder
highDetects Windows shells and scripting applications that write files to suspicious folders
windows
WinRAR Creating Files in Startup Locations
highDetects WinRAR creating files in Windows startup locations, which may indicate an attempt to establish persistence by adding malicious files to the Startup folder. This kind of behaviour has been associated with exploitation of WinRAR path traversal vulnerability CVE-2025-6218 or CVE-2025-8088.
windows
WMI Persistence - Script Event Consumer File Write
highDetects file writes of WMI script event consumer
windows
WScript or CScript Dropper - File
highDetects a file ending in jse, vbe, js, vba, vbs, wsf, wsh written by cscript.exe or wscript.exe
windows
ADExplorer Writing Complete AD Snapshot Into .dat File
mediumDetects the dual use tool ADExplorer writing a complete AD snapshot into a .dat file. This can be used by attackers to extract data for Bloodhound, usernames for password spraying or use the meta data for social engineering. The snapshot doesn't contain password hashes but there have been cases, where administrators put passwords in the comment field.
windows
ADSI-Cache File Creation By Uncommon Tool
mediumDetects the creation of an "Active Directory Schema Cache File" (.sch) file by an uncommon tool.
windows
Advanced IP Scanner - File Event
mediumDetects the use of Advanced IP Scanner. Seems to be a popular tool for ransomware groups.
windows
Anydesk Temporary Artefact
mediumAn adversary may use legitimate desktop support and remote access software, such as Team Viewer, Go2Assist, LogMein, AmmyyAdmin, etc, to establish an interactive command and control channel to target systems within networks. These services are commonly used as legitimate technical support software, and may be allowed by application control within a target environment. Remote access tools like VNC, Ammyy, and Teamviewer are used frequently when compared with other legitimate software commonly used by adversaries. (Citation: Symantec Living off the Land)
windows
Assembly DLL Creation Via AspNetCompiler
mediumDetects the creation of new DLL assembly files by "aspnet_compiler.exe", which could be a sign of "aspnet_compiler" abuse to proxy execution through a build provider.
windows
AWL Bypass with Winrm.vbs and Malicious WsmPty.xsl/WsmTxt.xsl - File
mediumDetects execution of attacker-controlled WsmPty.xsl or WsmTxt.xsl via winrm.vbs and copied cscript.exe (can be renamed)
windows
Created Files by Microsoft Sync Center
mediumThis rule detects suspicious files created by Microsoft Sync Center (mobsync)
windows
Creation of a Diagcab
mediumDetects the creation of diagcab file, which could be caused by some legitimate installer or is a sign of exploitation (review the filename and its location)
windows
Creation Of Non-Existent System DLL
mediumDetects creation of specific system DLL files that are usually not present on the system (or at least not in system directories) but may be loaded by legitimate processes. Phantom DLL hijacking involves placing malicious DLLs with names of non-existent system binaries in locations where legitimate applications may search for them, leading to execution of the malicious DLLs. Thus, the creation of such DLLs may indicate preparation for phantom DLL hijacking attacks.
windows
Creation of WerFault.exe/Wer.dll in Unusual Folder
mediumDetects the creation of a file named "WerFault.exe" or "wer.dll" in an uncommon folder, which could be a sign of WerFault DLL hijacking.
windows
CSExec Service File Creation
mediumDetects default CSExec service filename which indicates CSExec service installation and execution
windows
CVE-2024-1708 - ScreenConnect Path Traversal Exploitation
mediumThis detects file modifications to ASPX and ASHX files within the root of the App_Extensions directory, which is allowed by a ZipSlip vulnerability in versions prior to 23.9.8. This occurs during exploitation of CVE-2024-1708.
windows
DarkGate - Autoit3.EXE File Creation By Uncommon Process
mediumDetects the usage of curl.exe, KeyScramblerLogon, or other non-standard/suspicious processes used to create Autoit3.exe. This activity has been associated with DarkGate malware, which uses Autoit3.exe to execute shellcode that performs process injection and connects to the DarkGate command-and-control server. Curl, KeyScramblerLogon, and these other processes consitute non-standard and suspicious ways to retrieve the Autoit3 executable.
windows
DarkGate - Drop DarkGate Loader In C:\Temp Directory
mediumDetects attackers attempting to save, decrypt and execute the DarkGate Loader in C:\temp folder.
windows
Desktop.INI Created by Uncommon Process
mediumDetects unusual processes accessing desktop.ini, which can be leveraged to alter how Explorer displays a folder's content (i.e. renaming files) without changing them on disk.
windows
Drop Binaries Into Spool Drivers Color Folder
mediumDetects the creation of suspcious binary files inside the "\windows\system32\spool\drivers\color\" as seen in the blog referenced below
windows
EVTX Created In Uncommon Location
mediumDetects the creation of new files with the ".evtx" extension in non-common or non-standard location. This could indicate tampering with default EVTX locations in order to evade security controls or simply exfiltration of event log to search for sensitive information within. Note that backup software and legitimate administrator might perform similar actions during troubleshooting.
windows
Files With System DLL Name In Unsuspected Locations
mediumDetects the creation of a file with the ".dll" extension that has the name of a System DLL in uncommon or unsuspected locations. (Outisde of "System32", "SysWOW64", etc.). It is highly recommended to perform an initial baseline before using this rule in production.
windows
Files With System Process Name In Unsuspected Locations
mediumDetects the creation of an executable with a system process name in folders other than the system ones (System32, SysWOW64, etc.). It is highly recommended to perform an initial baseline before using this rule in production.
windows
Forest Blizzard APT - JavaScript Constrained File Creation
mediumDetects the creation of JavaScript files inside of the DriverStore directory. Forest Blizzard used this to exploit the CVE-2022-38028 vulnerability in Windows Print Spooler service by modifying a JavaScript constraints file and executing it with SYSTEM-level permissions.
windows
GatherNetworkInfo.VBS Reconnaissance Script Output
mediumDetects creation of files which are the results of executing the built-in reconnaissance script "C:\Windows\System32\gatherNetworkInfo.vbs".
windows
GoToAssist Temporary Installation Artefact
mediumAn adversary may use legitimate desktop support and remote access software, such as Team Viewer, Go2Assist, LogMein, AmmyyAdmin, etc, to establish an interactive command and control channel to target systems within networks. These services are commonly used as legitimate technical support software, and may be allowed by application control within a target environment. Remote access tools like VNC, Ammyy, and Teamviewer are used frequently when compared with other legitimate software commonly used by adversaries. (Citation: Symantec Living off the Land)
windows
Installation of TeamViewer Desktop
mediumTeamViewer_Desktop.exe is create during install
windows
ISO or Image Mount Indicator in Recent Files
mediumDetects the creation of recent element file that points to an .ISO, .IMG, .VHD or .VHDX file as often used in phishing attacks. This can be a false positive on server systems but on workstations users should rarely mount .iso or .img files.
windows
Linux Doas Conf File Creation
mediumDetects the creation of doas.conf file in linux host platform.
linux
LiveKD Driver Creation
mediumDetects the creation of the LiveKD driver, which is used for live kernel debugging
windows
MacOS Emond Launch Daemon
mediumDetects additions to the Emond Launch Daemon that adversaries may use to gain persistence and elevate privileges.
macos
New Custom Shim Database Created
mediumAdversaries may establish persistence and/or elevate privileges by executing malicious content triggered by application shims. The Microsoft Windows Application Compatibility Infrastructure/Framework (Application Shim) was created to allow for backward compatibility of software as the operating system codebase changes over time.
windows
New Outlook Macro Created
mediumDetects the creation of a macro file for Outlook.
windows
OneNote Attachment File Dropped In Suspicious Location
mediumDetects creation of files with the ".one"/".onepkg" extension in suspicious or uncommon locations. This could be a sign of attackers abusing OneNote attachments
windows
Persistence Via Sudoers.d Files
mediumDetects the creation or modification of files within the "sudoers.d" directory on Linux systems. Such activity may indicate an attempt to establish or maintain privilege escalation by granting specific users elevated permissions. Unauthorized changes to sudoers files are a common technique used by attackers to persist administrative access.
linux
Potential Binary Or Script Dropper Via PowerShell
mediumDetects PowerShell creating a binary executable or a script file.
windows
Potential CVE-2023-36874 Exploitation - Uncommon Report.Wer Location
mediumDetects the creation of a "Report.wer" file in an uncommon folder structure. This could be a sign of potential exploitation of CVE-2023-36874.
windows
Potential CVE-2023-36884 Exploitation Dropped File
mediumDetects a specific file being created in the recent folder of Office. These files have been seen being dropped during potential exploitations of CVE-2023-36884
windows
Potential CVE-2024-3400 Exploitation - Palo Alto GlobalProtect OS Command Injection - File Creation
mediumDetects suspicious file creations in the Palo Alto Networks PAN-OS' parent telemetry folder, which are processed by the vulnerable 'dt_curl' script if device telemetry is enabled. As said script overrides the shell-subprocess restriction, arbitrary command execution may occur by carefully crafting filenames that are escaped through this function.
paloalto · globalprotect
Potential Hidden Directory Creation Via NTFS INDEX_ALLOCATION Stream
mediumDetects the creation of hidden file/folder with the "::$index_allocation" stream. Which can be used as a technique to prevent access to folder and files from tooling such as "explorer.exe" and "powershell.exe"
windows
Potential Homoglyph Attack Using Lookalike Characters in Filename
mediumDetects the presence of unicode characters which are homoglyphs, or identical in appearance, to ASCII letter characters. This is used as an obfuscation and masquerading techniques. Only "perfect" homoglyphs are included; these are characters that are indistinguishable from ASCII characters and thus may make excellent candidates for homoglyph attack characters.
windows
Potential Initial Access via DLL Search Order Hijacking
mediumDetects attempts to create a DLL file to a known desktop application dependencies folder such as Slack, Teams or OneDrive and by an unusual process. This may indicate an attempt to load a malicious module via DLL search order hijacking.
windows
Potential Persistence Attempt Via ErrorHandler.Cmd
mediumDetects creation of a file named "ErrorHandler.cmd" in the "C:\WINDOWS\Setup\Scripts\" directory which could be used as a method of persistence The content of C:\WINDOWS\Setup\Scripts\ErrorHandler.cmd is read whenever some tools under C:\WINDOWS\System32\oobe\ (e.g. Setup.exe) fail to run for any reason.
windows
Potential Persistence Via Notepad++ Plugins
mediumDetects creation of new ".dll" files inside the plugins directory of a notepad++ installation by a process other than "gup.exe". Which could indicates possible persistence
windows
Potential SAP NetWeaver Webshell Creation
mediumDetects the creation of suspicious files (jsp, java, class) in SAP NetWeaver directories, which may indicate exploitation attempts of vulnerabilities such as CVE-2025-31324.
windows
Potential SAP NetWeaver Webshell Creation - Linux
mediumDetects the creation of suspicious files (jsp, java, class) in SAP NetWeaver directories, which may indicate exploitation attempts of vulnerabilities such as CVE-2025-31324.
linux
Potential Suspicious PowerShell Module File Created
mediumDetects the creation of a new PowerShell module in the first folder of the module directory structure "\WindowsPowerShell\Modules\malware\malware.psm1". This is somewhat an uncommon practice as legitimate modules often includes a version folder.
windows
Potential Webshell Creation On Static Website
mediumDetects the creation of files with certain extensions on a static web site. This can be indicative of potential uploads of a web shell.
windows
Potentially Suspicious DMP/HDMP File Creation
mediumDetects the creation of a file with the ".dmp"/".hdmp" extension by a shell or scripting application such as "cmd", "powershell", etc. Often created by software during a crash. Memory dumps can sometimes contain sensitive information such as credentials. It's best to determine the source of the crash.
windows
Potentially Suspicious File Creation by OpenEDR's ITSMService
mediumDetects the creation of potentially suspicious files by OpenEDR's ITSMService process. The ITSMService is responsible for remote management operations and can create files on the system through the Process Explorer or file management features. While legitimate for IT operations, creation of executable or script files could indicate unauthorized file uploads, data staging, or malicious file deployment.
windows
Potentially Suspicious WDAC Policy File Creation
mediumDetects suspicious Windows Defender Application Control (WDAC) policy file creation from abnormal processes that could be abused by attacker to block EDR/AV components while allowing their own malicious code to run on the system.
windows
PowerShell Module File Created By Non-PowerShell Process
mediumDetects the creation of a new PowerShell module ".psm1", ".psd1", ".dll", ".ps1", etc. by a non-PowerShell process
windows
PowerShell Profile Modification
mediumDetects the creation or modification of a powershell profile which could indicate suspicious activity as the profile can be used as a mean of persistence
windows
Process Monitor Driver Creation By Non-Sysinternals Binary
mediumDetects creation of the Process Monitor driver by processes other than Process Monitor (procmon) itself.
windows
PSScriptPolicyTest Creation By Uncommon Process
mediumDetects the creation of the "PSScriptPolicyTest" PowerShell script by an uncommon process. This file is usually generated by Microsoft Powershell to test against Applocker.
windows
Publisher Attachment File Dropped In Suspicious Location
mediumDetects creation of files with the ".pub" extension in suspicious or uncommon locations. This could be a sign of attackers abusing Publisher documents
windows
Python Path Configuration File Creation - Linux
mediumDetects creation of a Python path configuration file (.pth) in Python library folders, which can be maliciously abused for code execution and persistence. Modules referenced by these files are run at every Python startup (v3.5+), regardless of whether the module is imported by the calling script. Default paths are '\lib\site-packages\*.pth' (Windows) and '/lib/pythonX.Y/site-packages/*.pth' (Unix and macOS).
linux
Python Path Configuration File Creation - MacOS
mediumDetects creation of a Python path configuration file (.pth) in Python library folders, which can be maliciously abused for code execution and persistence. Modules referenced by these files are run at every Python startup (v3.5+), regardless of whether the module is imported by the calling script. Default paths are '\lib\site-packages\*.pth' (Windows) and '/lib/pythonX.Y/site-packages/*.pth' (Unix and macOS).
macos
Python Path Configuration File Creation - Windows
mediumDetects creation of a Python path configuration file (.pth) in Python library folders, which can be maliciously abused for code execution and persistence. Modules referenced by these files are run at every Python startup (v3.5+), regardless of whether the module is imported by the calling script. Default paths are '\lib\site-packages\*.pth' (Windows) and '/lib/pythonX.Y/site-packages/*.pth' (Unix and macOS).
windows
Rclone Config File Creation
mediumDetects Rclone config files being created
windows
RemCom Service File Creation
mediumDetects default RemCom service filename which indicates RemCom service installation and execution
windows
SCR File Write Event
mediumDetects the creation of screensaver files (.scr) outside of system folders. Attackers may execute an application as an ".SCR" file using "rundll32.exe desk.cpl,InstallScreenSaver" for example.
windows
ScreenConnect Temporary Installation Artefact
mediumAn adversary may use legitimate desktop support and remote access software, such as Team Viewer, Go2Assist, LogMein, AmmyyAdmin, etc, to establish an interactive command and control channel to target systems within networks. These services are commonly used as legitimate technical support software, and may be allowed by application control within a target environment. Remote access tools like VNC, Ammyy, and Teamviewer are used frequently when compared with other legitimate software commonly used by adversaries. (Citation: Symantec Living off the Land)
windows
ScreenConnect User Database Modification
mediumDetects file modifications to the temporary xml user database file indicating local user modification in the ScreenConnect server. This will occur during exploitation of the ScreenConnect Authentication Bypass vulnerability (CVE-2024-1709) in versions <23.9.8, but may also be observed when making legitimate modifications to local users or permissions.
windows
Self Extraction Directive File Created In Potentially Suspicious Location
mediumDetects the creation of Self Extraction Directive files (.sed) in a potentially suspicious location. These files are used by the "iexpress.exe" utility in order to create self extracting packages. Attackers were seen abusing this utility and creating PE files with embedded ".sed" entries.
windows
Startup Folder File Write
mediumA General detection for files being created in the Windows startup directory. This could be an indicator of persistence.
windows
Suspicious Creation of .library-ms File — Potential CVE-2025-24054 Exploit
mediumDetects creation of '.library-ms' files, which may indicate exploitation of CVE-2025-24054. This vulnerability allows an attacker to trigger an automatic outbound SMB or WebDAV authentication request to a remote server upon archive extraction. If the system is unpatched, no user interaction is required beyond extracting a malicious archive—potentially exposing the user's NTLMv2-SSP hash to the attacker.
windows
Suspicious Creation TXT File in User Desktop
mediumDetects creation of .txt files in user desktop folders via cmd.exe. This behavior may indicate ransomware deploying ransom notes, but can also occur during legitimate administrative tasks. Analysts should investigate for suspicious filenames (e.g., "RANSOM", "DECRYPT", "READ_ME"), bulk file creation patterns, or concurrent encryption activity to determine if this is part of a ransomware attack.
windows
Suspicious File Created In PerfLogs
mediumDetects suspicious file based on their extension being created in "C:\PerfLogs\". Note that this directory mostly contains ".etl" files
windows
Suspicious File Drop by Exchange
mediumDetects suspicious file type dropped by an Exchange component in IIS
windows
Suspicious File Write to Webapps Root Directory
mediumDetects suspicious file writes to the root directory of web applications, particularly Apache web servers or Tomcat servers. This may indicate an attempt to deploy malicious files such as web shells or other unauthorized scripts.
windows
Suspicious Files in Default GPO Folder
mediumDetects the creation of copy of suspicious files (EXE/DLL) to the default GPO storage folder
windows
Suspicious LNK Double Extension File Created
mediumDetects the creation of files with an "LNK" as a second extension. This is sometimes used by malware as a method to abuse the fact that Windows hides the "LNK" extension by default.
windows
Suspicious PROCEXP152.sys File Created In TMP
mediumDetects the creation of the PROCEXP152.sys file in the application-data local temporary folder. This driver is used by Sysinternals Process Explorer but also by KDU (https://github.com/hfiref0x/KDU) or Ghost-In-The-Logs (https://github.com/bats3c/Ghost-In-The-Logs), which uses KDU.
windows
Suspicious Screensaver Binary File Creation
mediumAdversaries may establish persistence by executing malicious content triggered by user inactivity. Screensavers are programs that execute after a configurable time of user inactivity and consist of Portable Executable (PE) files with a .scr file extension
windows
TanStack Supply-Chain Attack File Creation Indicators - Linux
mediumDetects file creation indicators associated with the Mini Shai-Hulud supply-chain campaign targeting TanStack npm packages and others such as mistralai and uipath reported on early May 2026.
linux
TanStack Supply-Chain Attack File Creation Indicators - Windows
mediumDetects file creation indicators associated with the Mini Shai-Hulud supply-chain campaign targeting TanStack npm packages and others such as mistralai, uipath, etc reported on early May 2026.
windows
TeamViewer Remote Session
mediumDetects the creation of log files during a TeamViewer remote session
windows
VHD Image Download Via Browser
mediumDetects creation of ".vhd"/".vhdx" files by browser processes. Malware can use mountable Virtual Hard Disk ".vhd" files to encapsulate payloads and evade security controls.
windows
Visual Studio Code Tunnel Remote File Creation
mediumDetects the creation of file by the "node.exe" process in the ".vscode-server" directory. Could be a sign of remote file creation via VsCode tunnel feature
windows
VsCode Code Tunnel Execution File Indicator
mediumDetects the creation of a file with the name "code_tunnel.json" which indicate execution and usage of VsCode tunneling utility. Attackers can abuse this functionality to establish a C2 channel
windows
VsCode Powershell Profile Modification
mediumDetects the creation or modification of a vscode related powershell profile which could indicate suspicious activity as the profile can be used as a mean of persistence
windows
WDAC Policy File Creation In CodeIntegrity Folder
mediumAttackers can craft a custom Windows Defender Application Control (WDAC) policy that blocks Endpoint Detection and Response (EDR) components while allowing their own malicious code. The policy is placed in the privileged Windows Code Integrity folder (C:\Windows\System32\CodeIntegrity\). Upon reboot, the policy prevents EDR drivers from loading, effectively bypassing security measures and may further enable undetected lateral movement within an Active Directory environment.
windows
WebDAV Temporary Local File Creation
mediumDetects the creation of WebDAV temporary files with potentially suspicious extensions
windows
Wget Creating Files in Tmp Directory
mediumDetects the use of wget to download content in a temporary directory such as "/tmp" or "/var/tmp"
linux
Windows Terminal Profile Settings Modification By Uncommon Process
mediumDetects the creation or modification of the Windows Terminal Profile settings file "settings.json" by an uncommon process.
windows
WinSxS Executable File Creation By Non-System Process
mediumDetects the creation of binaries in the WinSxS folder by non-system processes
windows
Writing Local Admin Share
mediumAversaries may use to interact with a remote network share using Server Message Block (SMB). This technique is used by post-exploitation frameworks.
windows
Creation of an Executable by an Executable
lowDetects the creation of an executable by another executable.
windows
CVE-2023-40477 Potential Exploitation - .REV File Creation
lowDetects the creation of ".rev" files by WinRAR. Could be indicative of potential exploitation of CVE-2023-40477. Look for a suspicious execution shortly after creation or a WinRAR application crash.
windows
DMP/HDMP File Creation
lowDetects the creation of a file with the ".dmp"/".hdmp" extension. Often created by software during a crash. Memory dumps can sometimes contain sensitive information such as credentials. It's best to determine the source of the crash.
windows
Dynamic CSharp Compile Artefact
lowWhen C# is compiled dynamically, a .cmdline file will be created as a part of the process. Certain processes are not typically observed compiling C# code, but can do so without touching disk. This can be used to unpack a payload for execution
windows
New Cron File Created
lowDetects the creation of cron files in Cron directories, which could indicate potential persistence mechanisms being established by an attacker. Note that not all cron file creations are malicious - legitimate system administration activities and software installations may also create cron files. This detection should be investigated in context, considering factors such as the user creating the file, the timing of creation, and the contents of the cron job. Focus investigation on unexpected cron files created by non-administrative users or during suspicious timeframes. Additionally, it is recommended to review the contents of the newly created cron files to assess their intent. Furthermore, it is suggested to baseline normal cron file creation and apply additional filters to reduce false positives based on the specific environment.
linux
NTDS.DIT Created
lowDetects creation of a file named "ntds.dit" (Active Directory Database)
windows
Office Macro File Creation
lowDetects the creation of a new office macro files on the systems
windows
Office Macro File Download
lowDetects the creation of a new office macro files on the system via an application (browser, mail client). This can help identify potential malicious activity, such as the download of macro-enabled documents that could be used for exploitation.
windows
PFX File Creation
lowDetects the creation of PFX files (Personal Information Exchange format). PFX files contain private keys and certificates bundled together, making them valuable targets for attackers seeking to: - Exfiltrate digital certificates for impersonation or signing malicious code - Establish persistent access through certificate-based authentication - Bypass security controls that rely on certificate validation Analysts should investigate PFX file creation events by examining which process created the PFX file and its parent process chain, as well as unusual locations outside standard certificate stores or development environments.
windows
Potentially Suspicious Long Filename Pattern - Linux
lowDetects the creation of files with unusually long filenames (100 or more characters), which may indicate obfuscation techniques used by malware such as VShell. This is a hunting rule to identify potential threats that use long filenames to evade detection. Keep in mind that on a legitimate system, such long filenames can and are common. Run this detection in the context of threat hunting rather than alerting. Adjust the threshold of filename length as needed based on your environment.
linux
Potentially Suspicious Shell Script Creation in Profile Folder
lowDetects the creation of shell scripts under the "profile.d" path.
linux
PowerShell Module File Created
lowDetects the creation of a new PowerShell module ".psm1", ".psd1", ".dll", ".ps1", etc.
windows
PowerShell Script Dropped Via PowerShell.EXE
lowDetects PowerShell creating a PowerShell file (.ps1). While often times this behavior is benign, sometimes it can be a sign of a dropper script trying to achieve persistence.
windows
PsExec Service File Creation
lowDetects default PsExec service filename which indicates PsExec service installation and execution
windows
Remote Access Tool - ScreenConnect Temporary File
lowDetects the creation of files in a specific location by ScreenConnect RMM. ScreenConnect has feature to remotely execute binaries on a target machine. These binaries will be dropped to ":\Users\<username>\Documents\ConnectWiseControl\Temp\" before execution.
windows
Scheduled Task Created - FileCreation
lowDetects the creation of a scheduled task via file creation.
windows
SNAKE Malware Installer Name Indicators
lowDetects filename indicators associated with the SNAKE malware as reported by CISA in their report
windows
Startup Item File Created - MacOS
lowDetects the creation of a startup item plist file, that automatically get executed at boot initialization to establish persistence. Adversaries may use startup items automatically executed at boot initialization to establish persistence. Startup items execute during the final phase of the boot process and contain shell scripts or other executable files along with configuration information used by the system to determine the execution order for all startup items.
macos
Suspicious Deno File Written from Remote Source
lowDetects Deno writing a file from a direct HTTP(s) call and writing to the appdata folder or bringing it's own malicious DLL. This behavior may indicate an attempt to execute remotely hosted, potentially malicious files through deno.
windows