Windows ADSI Schema Cache (.sch) File Creation by Uncommon Process

Alerts on .sch cache file creation in the Windows SchCache directory by uncommon executables.

FreeReviewedSigma · Medium · v2
Product
windows
Category
file_event
Author
xknow @xknow_infosec, Tim Shelton (SigmaHQ), DRL 1.1
Published
2019-03-24
Updated
2026-07-31

ATT&CK techniques

C2
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. Exfiltration

  13. Impact

What it detects

This rule flags creation of Active Directory Schema Cache File (.sch) artifacts under the Local\Microsoft\Windows\SchCache path when the creating process is not on a known-allowlist. Attackers may generate these cache files as part of directory/AD-related operations, including tooling used for LDAP/AD interactions. It relies on Windows file creation telemetry that captures the target filename and the creating process image path.

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.