Suspicious Startup Folder Persistence (via file_event)
This rule detects the creation of potentially hostile script and executable files in Windows startup folders, which is a common persistence method used by threat actors. These files (.ps1, .vbs, .js, .bat, etc.) are automatically executed when a user logs in, making the Startup folder an attractive target for attackers. This method is frequently observed in malvertising campaigns and malware distribution where adversaries attempt to maintain long-term access to compromised systems.
Unlock this rule to view and copy it
Rule logic is available with an unlock credit. The public page keeps its context, mappings and implementation details visible.
Sign in to unlockKnown false positives
- Unknown
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.