Windows Microsoft Sync Center (mobsync.exe) Network Connections to Public IPs

Alerts when mobsync.exe makes outbound connections to destination IPs outside private/local ranges.

FreeReviewedSigma · Medium · v2
Product
windows
Category
network_connection
Author
elhoim (SigmaHQ), DRL 1.1
Published
2022-04-28
Updated
2026-07-31

ATT&CK techniques

Priv Esc → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

Identifies outbound network connections initiated by Microsoft Sync Center’s mobsync.exe to destinations outside commonly defined local/private IP ranges. This matters because attackers may abuse legitimate Windows binaries to establish communications and blend in with normal system activity. The rule relies on Windows network connection telemetry containing the process image path and destination IP for filtering loopback, private, and link-local destinations.

Related detections9 linkedT1055 — drag to rearrange
Malicious aspnet_compiler.exe Injection Host Spawned by PowerShell via process_creation
Suspicious RegAsm or RegSvcs Spawned by Script Host (via process_creation)
Windows Image Load: coregen.exe Potential DLL Sideloading
Windows: Files created by Microsoft Sync Center (mobsync.exe) with .dll/.exe extensions
Suspicious Office Application Spawning Script Or Shell Interpreter
Suspicious Network Connection From wabmig.exe (Turian Injection)
Suspicious Outbound Network Connection from Explorer Process
Suspicious AppLaunch.exe Spawned As Injection Target (via process_creation)
Suspicious BugSleep Marker File in Public Directory
Windows Microsoft Sync Center (mobsync.exe) Network Connections to Public IPs
Pivot detection · T1055 · 9 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.