dfsvc.exe Initiated Network Connections to External (Non-Local) IPs on Windows
Alerts on dfsvc.exe initiating outbound connections to IPs outside local/private and link-local ranges.
- Product
- windows
- Category
- network_connection
- Author
- Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
- Published
- 2023-06-12
- Updated
- 2026-07-31
ATT&CK techniques
ExecutionRecon
Resource Dev
Initial Access
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule identifies network connections initiated by dfsvc.exe that target IP addresses outside common local and private ranges. Such activity can indicate misuse of dfsvc.exe to reach external infrastructure after being used for ClickOnce application handling. It relies on Windows network_connection telemetry containing process image path, connection initiation status, and destination IP addresses.
Reporting behind it
Changelog
v5- v5Candidate ingested via manual entry.2026-07-31
- v4Candidate ingested via manual entry.2026-07-31
- v3Candidate ingested via manual entry.2026-07-31
- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: dfsvc.exe Initiated Network Connections to External (Non-Local) IPs on Windows
id: 2804c175-064e-4993-95c0-dfb2b73f101d
status: test
description: This rule identifies network connections initiated by dfsvc.exe that target IP addresses outside common local and private ranges. Such activity can indicate misuse of dfsvc.exe to reach external infrastructure after being used for ClickOnce application handling. It relies on Windows network_connection telemetry containing process image path, connection initiation status, and destination IP addresses.
references:
- https://posts.specterops.io/less-smartscreen-more-caffeine-ab-using-clickonce-for-trusted-code-execution-1446ea8051c5
- https://github.com/SigmaHQ/sigma/blob/master/rules-threat-hunting/windows/network_connection/net_connection_win_dfsvc_non_local_ip.yml
author: Nasreddine Bencherchali (Nextron Systems), Huntrule Team
date: 2023-06-12
modified: 2024-03-12
tags:
- attack.execution
- attack.t1203
- detection.threat-hunting
logsource:
category: network_connection
product: windows
detection:
selection:
Image|endswith: \dfsvc.exe
Initiated: "true"
filter_main_local_ip:
DestinationIp|cidr:
- 127.0.0.0/8
- 10.0.0.0/8
- 169.254.0.0/16
- 172.16.0.0/12
- 192.168.0.0/16
- ::1/128
- fe80::/10
- fc00::/7
condition: selection and not 1 of filter_main_*
falsepositives:
- False positives are expected from ClickOnce manifests hosted on public IPs and domains. Apply additional filters for the accepted IPs in your environement as necessary
level: medium
license: DRL-1.1
related:
- id: 3c21219b-49b5-4268-bce6-c914ed50f09c
type: derived