Suspicious Screensaver File Executed as Installer via process_creation

PremiumReviewedSigma · Medium · v1
Product
windows
Category
process_creation
Author
HuntRule
Published
2026-09-30
Updated
2026-09-30

ATT&CK techniques

Initial Access → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Execution

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule detects a .scr screensaver file being executed directly as a program. In the rogue RMM campaign, invite and SSA themed lures were delivered as SCR installers to trick users into running the initial dropper, so execution of an .scr file outside of screensaver preview contexts indicates a masqueraded installer launching malicious payloads.

Related detections9 linkedT1218.007 — drag to rearrange
Suspicious Remote MSI Installation from Amazon S3 via msiexec
Suspicious Remote MSI Install of Dokan Driver via msiexec
Malicious Remote MSI Install of RuntimeBroker via msiexec
Suspicious Remote MSI Installation via msiexec from HTTP URL
Suspicious M365 Device Code Authentication Flow via m365
Malicious GTFire Phishing Credential Exfiltration to All-in-1.php Backend (via proxy)
Suspicious Msiexec Remote MSI Installation via Command Line
Malicious ScreenConnect Client Installation via Msiexec (via process_creation)
Suspicious Remote MSI Installation of RMM Tooling via Msiexec (via process_creation)
Suspicious Screensaver File Executed as Installer via process_creation
Pivot detection · T1218.007 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.