ArcSOC.exe Creates Suspicious Script/Executable Files on Windows

Alerts when ArcSOC.exe creates files with script/executable extensions such as .exe, .ps1, .aspx, or .bat.

FreeReviewedSigma · High · v2
Product
windows
Category
file_event
Author
Micah Babinski (SigmaHQ), DRL 1.1
Published
2025-11-25
Updated
2026-07-31

ATT&CK techniques

Initial Access → C2
  1. Recon

  2. Resource Dev

  3. Priv Esc

  4. Cred Access

  5. Discovery

  6. Lateral Movement

  7. Collection

  8. Exfiltration

  9. Impact

What it detects

This rule flags Windows file creation events where ArcGIS Server’s ArcSOC.exe creates a file with an ending that matches common executable and script types. Attackers may use the web services process to drop payloads or stage persistence via unusual file creation. The detection relies on Windows file event telemetry that includes the creating process path (ending with \ArcSOC.exe) and the created file name suffix.

Related detections9 linkedT1105 — drag to rearrange
Suspicious Remote Script Transfer via Bitsadmin (via process_creation)
Suspicious PowerShell Download Cradle via ClickFix Fake CAPTCHA (via process_creation)
Malicious Curl MSI Download to ProgramData via Process Creation
Suspicious CloudZ RAT Payload Download via curl to ProgramData
Suspicious Velociraptor Agent Deployment via msiexec From Cloud Storage
Suspicious PowerShell Download of lib.zip Archive
Suspicious File Download Via Bitsadmin Transfer
Suspicious PowerShell Download Of Text-Disguised Payload
Explorer WebDAV UNC Download Using At-Port Syntax
ArcSOC.exe Creates Suspicious Script/Executable Files on Windows
Pivot detection · T1105 · 9 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.