Skip to content

Commit b242175

Browse files
Merge PR SigmaHQ#5679 from @swachchhanda000 - chore: update evtx baseline to v0.8.2
chore: update evtx baseline to v0.8.2 and fix FPs --------- Co-authored-by: Swachchhanda Shrawan Poudel <87493836+swachchhanda000@users.noreply.github.com>
1 parent 90fe2d9 commit b242175

63 files changed

Lines changed: 839 additions & 371 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

.github/workflows/goodlog-tests.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -39,7 +39,7 @@ on:
3939
workflow_dispatch:
4040

4141
env:
42-
EVTX_BASELINE_VERSION: v0.8.1
42+
EVTX_BASELINE_VERSION: v0.8.2
4343

4444
jobs:
4545
check-baseline-win7:

.github/workflows/known-FPs.csv

Lines changed: 17 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -3,11 +3,10 @@ RuleId;RuleName;MatchString
33
ad1f4bb9-8dfb-4765-adb6-2a7cfb6c0f94;Suspicious WSMAN Provider Image Loads;.*
44
db809f10-56ce-4420-8c86-d6a7d793c79c;Raw Disk Access Using Illegitimate Tools;python-3
55
db809f10-56ce-4420-8c86-d6a7d793c79c;Raw Disk Access Using Illegitimate Tools;target\.exe
6-
96f697b0-b499-4e5d-9908-a67bec11cdb6;Removal of Potential COM Hijacking Registry Keys;sharepointclient
7-
96f697b0-b499-4e5d-9908-a67bec11cdb6;Removal of Potential COM Hijacking Registry Keys;odopen
6+
96f697b0-b499-4e5d-9908-a67bec11cdb6;Removal of Potential COM Hijacking Registry Keys;.*
87
1277f594-a7d1-4f28-a2d3-73af5cbeab43;Windows Shell File Write to Suspicious Folder;Computer: Agamemnon
98
e28a5a99-da44-436d-b7a0-2afc20a5f413;Whoami Execution;WindowsPowerShell
10-
8ac03a65-6c84-4116-acad-dc1558ff7a77;Sysmon Configuration Change;sysmon-intense\.xml
9+
8ac03a65-6c84-4116-acad-dc1558ff7a77;Sysmon Configuration Change;(sysmon-intense\.xml|sysmonconfig-trace\.xml)
1110
8ac03a65-6c84-4116-acad-dc1558ff7a77;Sysmon Configuration Change;Computer: (evtx-PC|Agamemnon)
1211
4358e5a5-7542-4dcb-b9f3-87667371839b;ISO or Image Mount Indicator in Recent Files;_Office_Professional_Plus_
1312
36480ae1-a1cb-4eaa-a0d6-29801d7e9142;Renamed Binary;WinRAR
@@ -17,8 +16,8 @@ e28a5a99-da44-436d-b7a0-2afc20a5f413;Whoami Execution;WindowsPowerShell
1716
162ab1e4-6874-4564-853c-53ec3ab8be01;TeamViewer Remote Session;TeamViewer(_Service)?\.exe
1817
cdc8da7d-c303-42f8-b08c-b4ab47230263;Rundll32 Internet Connection;20\.49\.150\.241
1918
bef0bc5a-b9ae-425d-85c6-7b2d705980c6;Python Initiated Connection;151\.101\.64\.223
19+
bef0bc5a-b9ae-425d-85c6-7b2d705980c6;Python Initiated Connection;146\.75\.117\.55
2020
9711de76-5d4f-4c50-a94f-21e4e8f8384d;Installation of TeamViewer Desktop;TeamViewer_Desktop\.exe
21-
96f697b0-b499-4e5d-9908-a67bec11cdb6;Removal of Potential COM Hijacking Registry Keys;target\.exe
2221
9494479d-d994-40bf-a8b1-eea890237021;Scheduled Task Creation From Potential Suspicious Parent Location;.*
2322
81325ce1-be01-4250-944f-b4789644556f;Suspicius Schtasks From Env Var Folder;TVInstallRestore
2423
6ea3bf32-9680-422d-9f50-e90716b12a66;UAC Bypass Via Wsreset;EventType: DeleteKey
@@ -37,6 +36,7 @@ a96970af-f126-420d-90e1-d37bf25e50e1;Use Short Name Path in Image;unzip\.exe
3736
349d891d-fef0-4fe4-bc53-eee623a15969;Use Short Name Path in Command Line;TeamViewer_\.exe
3837
7a02e22e-b885-4404-b38b-1ddc7e65258a;Suspicious Schtasks Schedule Type;TeamViewer_\.exe
3938
949f1ffb-6e85-4f00-ae1e-c3c5b190d605;Explorer Process Tree Break;Computer: Agamemnon
39+
949f1ffb-6e85-4f00-ae1e-c3c5b190d605;Explorer Process Tree Break;Computer: WinDev2310Eval
4040
fdbf0b9d-0182-4c43-893b-a1eaab92d085;Newly Registered Protocol Handler;.*
4141
100ef69e-3327-481c-8e5c-6d80d9507556;System Eventlog Cleared;.*
4242
52a85084-6989-40c3-8f32-091e12e17692;Suspicious Usage of CVE_2021_34484 or CVE 2022_21919;Computer: Agamemnon
@@ -48,8 +48,8 @@ b69888d4-380c-45ce-9cf9-d9ce46e67821;Executable in ADS;msedge\.exe
4848
b69888d4-380c-45ce-9cf9-d9ce46e67821;Executable in ADS;firefox\.exe
4949
b69888d4-380c-45ce-9cf9-d9ce46e67821;Executable in ADS;7z\.exe
5050
65236ec7-ace0-4f0c-82fd-737b04fd4dcb;EVTX Created In Uncommon Location;powershell\.exe
51-
a62b37e0-45d3-48d9-a517-90c1a1b0186b;Eventlog Cleared;Computer: DESKTOP-A8CALR3
52-
a62b37e0-45d3-48d9-a517-90c1a1b0186b;Eventlog Cleared;Computer: WIN-06FB45IHQ35
51+
65236ec7-ace0-4f0c-82fd-737b04fd4dcb;EVTX Created In Uncommon Location;Computer: WIN-FPV0DSIC9O6.sigma.fr
52+
a62b37e0-45d3-48d9-a517-90c1a1b0186b;Eventlog Cleared;Computer: .*
5353
4eec988f-7bf0-49f1-8675-1e6a510b3a2a;Potential PendingFileRenameOperations Tamper;target\.exe
5454
4eec988f-7bf0-49f1-8675-1e6a510b3a2a;Potential PendingFileRenameOperations Tamper;target\.tmp
5555
48bfd177-7cf2-412b-ad77-baf923489e82;Image Load of VSS Dll by Uncommon Executable;SetupFrontEnd.exe
@@ -59,3 +59,14 @@ e9d4ab66-a532-4ef7-a502-66a9e4a34f5d;NTLMv1 Logon Between Client and Server;.*
5959
ccb5742c-c248-4982-8c5c-5571b9275ad3;Potential Suspicious Findstr.EXE Execution;httpd\.exe
6060
9ae01559-cf7e-4f8e-8e14-4c290a1b4784;CredUI.DLL Load By Uncommon Process;Spotify\.exe
6161
52182dfb-afb7-41db-b4bc-5336cb29b464;Suspicious File Download From File Sharing Websites;objects\.githubusercontent\.com
62+
ce72ef99-22f1-43d4-8695-419dcb5d9330;Suspicious Windows Service Tampering;TeamViewer
63+
dae8171c-5ec6-4396-b210-8466585b53e9;SCM Database Privileged Operation;0x277c6
64+
3ce8e9a4-bc61-4c9b-8e69-d7e2492a8781;OpenSSH Server Listening On Socket;.*
65+
b69888d4-380c-45ce-9cf9-d9ce46e67821;Hidden Executable In NTFS Alternate Data Stream;.*
66+
4a1b6da0-d94f-4fc3-98fc-2d9cb9e5ee76;Potentially Suspicious AccessMask Requested From LSASS;\\setup\.exe
67+
d99b79d2-0a6f-4f46-ad8b-260b6e17f982;Security Eventlog Cleared;Computer: WinDevEval
68+
b28e58e4-2a72-4fae-bdee-0fbe904db642;Windows Defender Real-time Protection Disabled;Computer: WinDev2310Eval
69+
ef9dcfed-690c-4c5d-a9d1-482cd422225c;Browser Execution In Headless Mode;.*
70+
65236ec7-ace0-4f0c-82fd-737b04fd4dcb;EVTX Created In Uncommon Location;Computer: (DESKTOP-6D0DBMB|WinDev2310Eval)
71+
de587dce-915e-4218-aac4-835ca6af6f70;Potential Persistence Attempt Via Run Keys Using Reg.EXE;\\Discord\\
72+
24357373-078f-44ed-9ac4-6d334a668a11;Direct Autorun Keys Modification;Discord\.exe
Lines changed: 68 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,68 @@
1+
title: Use Short Name Path in Command Line
2+
id: 349d891d-fef0-4fe4-bc53-eee623a15969
3+
related:
4+
- id: a96970af-f126-420d-90e1-d37bf25e50e1
5+
type: similar
6+
status: test
7+
description: |
8+
Detects the use of short name paths (8.3 format) in command lines, which can be used to obfuscate paths or access restricted locations.
9+
Windows creates short 8.3 filenames (like PROGRA~1) for compatibility with MS-DOS-based or 16-bit Windows programs.
10+
When investigating, examine:
11+
- Commands using short paths to access sensitive directories or files
12+
- Web servers on Windows (especially Apache) where short filenames could bypass security controls
13+
- Correlation with other suspicious behaviors
14+
- baseline of short name usage in your environment and look for deviations
15+
references:
16+
- https://www.acunetix.com/blog/articles/windows-short-8-3-filenames-web-security-problem/
17+
- https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-2000-server/cc959352(v=technet.10)
18+
- https://twitter.com/frack113/status/1555830623633375232
19+
author: frack113, Nasreddine Bencherchali
20+
date: 2022-08-07
21+
modified: 2025-10-07
22+
tags:
23+
- attack.defense-evasion
24+
- attack.t1564.004
25+
- detection.threat-hunting
26+
logsource:
27+
category: process_creation
28+
product: windows
29+
detection:
30+
selection:
31+
CommandLine|contains:
32+
- '~1\'
33+
- '~2\'
34+
filter_main_system_process:
35+
ParentImage:
36+
- 'C:\Windows\System32\Dism.exe'
37+
- 'C:\Windows\System32\cleanmgr.exe'
38+
filter_main_winget:
39+
- ParentImage|endswith: '\winget.exe'
40+
- ParentImage|contains: '\AppData\Local\Temp\WinGet\'
41+
filter_main_installers:
42+
- Image|contains|all:
43+
- '\AppData\'
44+
- '\Temp\'
45+
- CommandLine|contains: '\AppData\Local\Temp\' # sometimes installers spawn other installers from temp folder
46+
filter_optional_dopus:
47+
ParentImage: 'C:\Program Files\GPSoftware\Directory Opus\dopus.exe'
48+
filter_optional_aurora:
49+
ParentImage|endswith:
50+
- '\aurora-agent-64.exe'
51+
- '\aurora-agent.exe'
52+
filter_optional_thor:
53+
ParentImage|endswith: '\thor\thor64.exe'
54+
filter_optional_git:
55+
CommandLine|contains:
56+
- 'C:\Program Files\Git\post-install.bat'
57+
- 'C:\Program Files\Git\cmd\scalar.exe'
58+
filter_optional_webex:
59+
- ParentImage|endswith: '\WebEx\webexhost.exe'
60+
- CommandLine|contains: '\appdata\local\webex\webex64\meetings\wbxreport.exe'
61+
filter_optional_veeam:
62+
ParentImage|endswith: '\veeam.backup.shell.exe'
63+
filter_optional_everything:
64+
ParentImage|endswith: '\Everything\Everything.exe'
65+
condition: selection and not 1 of filter_main_* and not 1 of filter_optional_*
66+
falsepositives:
67+
- Applications could use this notation occasionally which might generate some false positives. In that case investigate the parent and child process.
68+
level: medium

rules/windows/builtin/appxdeployment_server/win_appxdeployment_server_uncommon_package_locations.yml

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -9,7 +9,7 @@ references:
99
- https://news.sophos.com/en-us/2021/11/11/bazarloader-call-me-back-attack-abuses-windows-10-apps-mechanism/
1010
author: Nasreddine Bencherchali (Nextron Systems)
1111
date: 2023-01-11
12-
modified: 2025-03-07
12+
modified: 2025-10-07
1313
tags:
1414
- attack.defense-evasion
1515
logsource:
@@ -28,6 +28,7 @@ detection:
2828
- 'C:\Windows\ImmersiveControlPanel\'
2929
- 'x-windowsupdate://'
3030
- 'file:///C:/Program%20Files' # Also covers 'file:///C:/Program%20Files%20(x86)/'
31+
- 'AppData/Local/Temp/WinGet/Microsoft.Winget.Source'
3132
filter_main_specific:
3233
Path|contains:
3334
- 'https://statics.teams.cdn.live.net/'

rules/windows/builtin/firewall_as/win_firewall_as_add_rule.yml

Lines changed: 18 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,7 @@ references:
66
- https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2008-r2-and-2008/dd364427(v=ws.10)
77
author: frack113
88
date: 2022-02-19
9-
modified: 2024-08-29
9+
modified: 2025-10-08
1010
tags:
1111
- attack.defense-evasion
1212
- attack.t1562.004
@@ -28,9 +28,6 @@ detection:
2828
- 'C:\Windows\System32\'
2929
- 'C:\Windows\SysWOW64\'
3030
- 'C:\Windows\WinSxS\'
31-
filter_optional_msmpeng:
32-
ModifyingApplication|startswith: 'C:\ProgramData\Microsoft\Windows Defender\Platform\'
33-
ModifyingApplication|endswith: '\MsMpEng.exe'
3431
filter_main_covered_paths:
3532
# This filter is added to avoid duplicate alerting from 9e2575e7-2cb9-4da1-adc8-ed94221dca5e
3633
ApplicationPath|contains:
@@ -41,13 +38,28 @@ detection:
4138
- 'C:\Windows\Tasks\'
4239
- 'C:\Windows\Temp\'
4340
- '\AppData\Local\Temp\'
41+
filter_main_system_dllhost:
42+
ApplicationPath: 'System'
43+
ModifyingApplication: 'C:\Windows\System32\dllhost.exe'
44+
filter_main_tiworker:
45+
ModifyingApplication|startswith: 'C:\Windows\WinSxS\'
46+
ModifyingApplication|endswith: '\TiWorker.exe'
47+
filter_main_null:
48+
ApplicationPath: null
4449
filter_optional_no_path:
4550
# This filter filters a lot of FPs related to Windows Services
4651
ModifyingApplication:
4752
- 'C:\Windows\System32\svchost.exe'
4853
- 'C:\Windows\System32\dllhost.exe'
4954
ApplicationPath: ''
50-
filter_main_null:
51-
ApplicationPath: null
55+
filter_optional_msmpeng:
56+
- ModifyingApplication|startswith:
57+
- 'C:\ProgramData\Microsoft\Windows Defender\Platform\'
58+
- 'C:\Program Files\Windows Defender\'
59+
ModifyingApplication|endswith: '\MsMpEng.exe'
60+
- ApplicationPath|startswith:
61+
- 'C:\ProgramData\Microsoft\Windows Defender\Platform\'
62+
- 'C:\Program Files\Windows Defender\'
63+
ApplicationPath|endswith: '\MsMpEng.exe'
5264
condition: selection and not 1 of filter_main_* and not 1 of filter_optional_*
5365
level: medium

rules/windows/builtin/security/win_security_user_driver_loaded.yml

Lines changed: 10 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -12,7 +12,7 @@ references:
1212
- https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-10/security/threat-protection/auditing/event-4673
1313
author: xknow (@xknow_infosec), xorxes (@xor_xes)
1414
date: 2019-04-08
15-
modified: 2023-01-20
15+
modified: 2025-10-07
1616
tags:
1717
- attack.defense-evasion
1818
- attack.t1562.001
@@ -24,7 +24,7 @@ detection:
2424
EventID: 4673
2525
PrivilegeList: 'SeLoadDriverPrivilege'
2626
Service: '-'
27-
filter_exact:
27+
filter_main_exact:
2828
ProcessName:
2929
- 'C:\Windows\System32\Dism.exe'
3030
- 'C:\Windows\System32\rundll32.exe'
@@ -36,17 +36,22 @@ detection:
3636
- 'C:\Windows\System32\RuntimeBroker.exe'
3737
- 'C:\Windows\System32\SystemSettingsBroker.exe'
3838
- 'C:\Windows\explorer.exe'
39-
filter_endswith:
39+
filter_optional_others:
4040
ProcessName|endswith:
4141
- '\procexp64.exe'
4242
- '\procexp.exe'
4343
- '\procmon64.exe'
4444
- '\procmon.exe'
4545
- '\Google\Chrome\Application\chrome.exe'
4646
- '\AppData\Local\Microsoft\Teams\current\Teams.exe'
47-
filter_startswith:
47+
filter_main_startswith:
4848
ProcessName|startswith: 'C:\Program Files\WindowsApps\Microsoft'
49-
condition: selection_1 and not 1 of filter_*
49+
filter_optional_dropbox:
50+
ProcessName|startswith:
51+
- 'C:\Program Files (x86)\Dropbox\'
52+
- 'C:\Program Files\Dropbox\'
53+
ProcessName|endswith: '\Dropbox.exe'
54+
condition: selection_1 and not 1 of filter_main_* and not 1 of filter_optional_*
5055
falsepositives:
5156
- Other legimate tools loading drivers. Including but not limited to, Sysinternals, CPU-Z, AVs etc. A baseline needs to be created according to the used products and allowed tools. A good thing to do is to try and exclude users who are allowed to load drivers.
5257
level: medium

rules/windows/file/file_event/file_event_win_creation_system_file.yml

Lines changed: 16 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -8,7 +8,7 @@ references:
88
- Internal Research
99
author: Sander Wiebing, Tim Shelton, Nasreddine Bencherchali (Nextron Systems)
1010
date: 2020-05-26
11-
modified: 2024-06-24
11+
modified: 2025-10-07
1212
tags:
1313
- attack.defense-evasion
1414
- attack.t1036.005
@@ -102,19 +102,29 @@ detection:
102102
- 'C:\Windows\WinSxS\'
103103
- 'C:\Windows\uus\'
104104
filter_main_svchost:
105-
Image|endswith: 'C:\Windows\system32\svchost.exe'
106-
TargetFilename|contains: 'C:\Program Files\WindowsApps\'
105+
Image|endswith:
106+
- 'C:\Windows\system32\svchost.exe'
107+
- 'C:\Windows\SysWOW64\svchost.exe'
108+
TargetFilename|contains:
109+
- 'C:\Program Files\WindowsApps\'
110+
- 'C:\Program Files (x86)\WindowsApps\'
111+
- '\AppData\Local\Microsoft\WindowsApps\'
107112
filter_main_wuauclt:
108-
Image|endswith: 'C:\Windows\System32\wuauclt.exe'
113+
Image|endswith:
114+
- 'C:\Windows\System32\wuauclt.exe'
115+
- 'C:\Windows\SysWOW64\wuauclt.exe'
109116
filter_main_explorer:
110117
TargetFilename|endswith: 'C:\Windows\explorer.exe'
111118
filter_main_msiexec:
112119
# This filter handles system processes who are updated/installed using misexec.
113-
Image|endswith: 'C:\WINDOWS\system32\msiexec.exe'
120+
Image|endswith:
121+
- 'C:\WINDOWS\system32\msiexec.exe'
122+
- 'C:\WINDOWS\SysWOW64\msiexec.exe'
114123
# Add more processes if you find them or simply filter msiexec on its own. If the list grows big
115-
TargetFilename|endswith:
124+
TargetFilename|startswith:
116125
- 'C:\Program Files\PowerShell\7\pwsh.exe'
117126
- 'C:\Program Files\PowerShell\7-preview\pwsh.exe'
127+
- 'C:\Program Files\WindowsApps\Microsoft.PowerShellPreview\'
118128
filter_main_healtray:
119129
TargetFilename|contains: 'C:\Windows\System32\SecurityHealth\'
120130
TargetFilename|endswith: '\SecurityHealthSystray.exe'

rules/windows/file/file_event/file_event_win_powershell_module_uncommon_creation.yml

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@ references:
77
- https://learn.microsoft.com/en-us/powershell/scripting/developer/module/understanding-a-windows-powershell-module?view=powershell-7.3
88
author: Nasreddine Bencherchali (Nextron Systems)
99
date: 2023-05-09
10-
modified: 2023-10-18
10+
modified: 2025-10-07
1111
tags:
1212
- attack.persistence
1313
logsource:
@@ -28,6 +28,10 @@ detection:
2828
- ':\Windows\SysWOW64\poqexec.exe' # https://github.com/SigmaHQ/sigma/issues/4448
2929
- ':\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell_ise.exe'
3030
- ':\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe'
31+
filter_main_msiexec:
32+
Image:
33+
- 'C:\Windows\System32\msiexec.exe'
34+
- 'C:\Windows\SysWOW64\msiexec.exe'
3135
condition: selection and not 1 of filter_main_*
3236
falsepositives:
3337
- Unknown

rules/windows/file/file_event/file_event_win_ps_script_policy_test_creation_by_uncommon_process.yml

Lines changed: 20 additions & 13 deletions
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,7 @@ references:
66
- https://www.paloaltonetworks.com/blog/security-operations/stopping-powershell-without-powershell/
77
author: Nasreddine Bencherchali (Nextron Systems)
88
date: 2023-06-01
9-
modified: 2023-12-11
9+
modified: 2025-10-07
1010
tags:
1111
- attack.defense-evasion
1212
logsource:
@@ -15,19 +15,26 @@ logsource:
1515
detection:
1616
selection:
1717
TargetFilename|contains: '__PSScriptPolicyTest_'
18+
filter_main_powershell:
19+
Image:
20+
- 'C:\Program Files\PowerShell\7-preview\pwsh.exe'
21+
- 'C:\Program Files\PowerShell\7\pwsh.exe'
22+
- 'C:\Windows\System32\WindowsPowerShell\v1.0\powershell_ise.exe'
23+
- 'C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe'
24+
- 'C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell_ise.exe'
25+
- 'C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe'
26+
filter_main_pwsh_preview:
27+
Image|contains:
28+
- 'C:\Program Files\WindowsApps\Microsoft.PowerShellPreview'
29+
- '\AppData\Local\Microsoft\WindowsApps\Microsoft.PowerShellPreview'
30+
Image|endswith: '\pwsh.exe'
1831
filter_main_generic:
19-
Image|endswith:
20-
- ':\Program Files\PowerShell\7-preview\pwsh.exe'
21-
- ':\Program Files\PowerShell\7\pwsh.exe'
22-
- ':\Windows\System32\dsac.exe'
23-
- ':\Windows\System32\sdiagnhost.exe'
24-
- ':\Windows\System32\ServerManager.exe'
25-
- ':\Windows\System32\WindowsPowerShell\v1.0\powershell_ise.exe'
26-
- ':\Windows\System32\WindowsPowerShell\v1.0\powershell.exe'
27-
- ':\Windows\System32\wsmprovhost.exe'
28-
- ':\Windows\SysWOW64\sdiagnhost.exe'
29-
- ':\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell_ise.exe'
30-
- ':\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe'
32+
Image:
33+
- 'C:\Windows\System32\dsac.exe'
34+
- 'C:\Windows\System32\sdiagnhost.exe'
35+
- 'C:\Windows\System32\ServerManager.exe'
36+
- 'C:\Windows\System32\wsmprovhost.exe'
37+
- 'C:\Windows\SysWOW64\sdiagnhost.exe'
3138
condition: selection and not 1 of filter_main_*
3239
falsepositives:
3340
- Unknown

rules/windows/file/file_event/file_event_win_shell_write_susp_files_extensions.yml

Lines changed: 9 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -9,7 +9,7 @@ references:
99
- Internal Research
1010
author: Nasreddine Bencherchali (Nextron Systems)
1111
date: 2022-08-12
12-
modified: 2025-08-05
12+
modified: 2025-10-07
1313
tags:
1414
- attack.defense-evasion
1515
- attack.t1036
@@ -69,6 +69,14 @@ detection:
6969
TargetFilename|contains|all:
7070
- 'C:\Program Files\WindowsApps\Clipchamp'
7171
- '.ps1'
72+
filter_main_powershell_preview:
73+
Image:
74+
- 'C:\Windows\system32\svchost.exe'
75+
- 'C:\Windows\SysWOW64\svchost.exe'
76+
TargetFilename|startswith:
77+
- 'C:\Program Files\WindowsApps\Microsoft.PowerShellPreview'
78+
- 'C:\Program Files (x86)\WindowsApps\Microsoft.PowerShellPreview'
79+
TargetFilename|endswith: '.ps1'
7280
condition: 1 of selection_* and not 1 of filter_main_*
7381
falsepositives:
7482
- Unknown

0 commit comments

Comments
 (0)