Suspicious Startup Folder Persistence (via file_event)

This rule detects the creation of potentially hostile script and executable files in Windows startup folders, which is a common persistence method used by threat actors. These files (.ps1, .vbs, .js, .bat, etc.) are automatically executed when a user logs in, making the Startup folder an attractive target for attackers. This method is frequently observed in malvertising campaigns and malware distribution where adversaries attempt to maintain long-term access to compromised systems.

SigmahighWindowsv1
Full detection rule

Unlock this rule to view and copy it

Rule logic is available with an unlock credit. The public page keeps its context, mappings and implementation details visible.

Sign in to unlock

Known false positives

  • Unknown

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.