Suspicious Modification of Windows Hosts File

PremiumReviewedSigma · Medium · v1
Product
windows
Category
file_event
Author
HuntRule
Published
2026-09-20
Updated
2026-09-20

ATT&CK techniques

C2 → Impact
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. Exfiltration

What it detects

This rule detects writes to the Windows hosts file, which Cyber Stealer manipulates to poison DNS resolution and redirect or block traffic such as security-vendor domains. Because the hosts file is rarely changed on managed endpoints, modifications outside of controlled administration are a meaningful sign of network defense tampering.

Related detections9 linkedT1071.001 — drag to rearrange
Malicious FakeBat Distribution Domain Lookup (via dns_query)
Malicious Fenix Botnet C2 Communication via QuantumService Domain (via dns_query)
Malicious AMSI and ETW Bypass via In-Memory Patching (via ps_script)
Suspicious PowerShell AMSI or ETW Tampering
Suspicious BLOODALCHEMY Command and Control URI Pattern via Proxy
Malicious MIMICRAT C2 HTTP Request Pattern (via proxy)
Suspicious Contagious Interview Exfiltration via Axios Upload User Agent
Malicious NANOREMOTE C2 Beacon by User-Agent
Suspicious Malformed DONNECT HTTP Method in Proxy Logs via Proxy
Suspicious Modification of Windows Hosts File
Pivot detection · T1071.001 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.