Antivirus alerts for suspicious file paths and web/script file extensions

Alerts on AV hits involving suspicious file locations and web/script-related extensions.

FreeReviewedSigma · High · v5
Category
antivirus
Author
Florian Roth (Nextron Systems), Arnim Rupp (SigmaHQ), DRL 1.1
Published
2018-09-09
Updated
2026-07-31

ATT&CK techniques

Resource Dev
  1. Recon

  2. Initial Access

  3. Execution

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule flags Antivirus detections where the alerted Filename matches a set of highly relevant path patterns (e.g., Windows, Temp/PerfLogs, default/public user directories, inetpub, tsclient, and common web server directories) and/or ends with specific executable or web/script-related file extensions. Attackers often stage or execute payloads from these locations and use common script/web file types to gain execution or persistence. Telemetry relies on Antivirus events that include a Filename field containing the matched path fragments and/or extension suffixes.

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.