Suspicious FileFix TypedPaths Entry Containing PowerShell or URL

PremiumReviewedSigma · High · v1
Product
windows
Category
registry_set
Author
HuntRule
Published
2026-05-16
Updated
2026-08-28

ATT&CK techniques

Execution → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Persistence

  5. Priv Esc

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects an Explorer TypedPaths registry value that records a PowerShell command or HTTP URL, the forensic artifact left when a FileFix lure has the victim paste an obfuscated command into the File Explorer address bar. TypedPaths normally stores browsed folder locations, not scripts or web addresses. A command string or URL in this value indicates the FileFix address-bar execution technique.

Related detections9 linkedT1204.002 — drag to rearrange
Malicious more_eggs LOLBIN Scriptlet Execution via ie4uinit BaseSettings Abuse (via process_creation)
Suspicious VBA Runtime Loaded by Process from OneNote Exported Directory
Windows: Detect Advanced Installer PSF AI_STUBS Executables with OriginalFileName popupwrapper.exe
Suspicious Cabinet Extraction of Masqueraded vstm Archive via extrac32
Suspicious Interlock Fake Updater Executable Execution
Malicious Office Application Loading a User-Path DLL via Regsvr32 or Rundll32 (via process_creation)
Suspicious Program Execution From a Mounted ISO or Disk Image (via process_creation)
SocGholish Fake Browser Update Script Execution (via process_creation)
Malicious DLL Execution via Wuauclt Update Handler (via process_creation)
Suspicious FileFix TypedPaths Entry Containing PowerShell or URL
Pivot detection · T1204.002 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.