Windows: Deno writes files from remote HTTPS content into AppData

Alerts when Deno writes to user AppData while using remote HTTPS download-style paths.

FreeReviewedSigma · Low · v2
Product
windows
Category
file_event
Author
Josh Nickels, Michael Taggart (SigmaHQ), DRL 1.1
Published
2025-05-22
Updated
2026-07-31

ATT&CK techniques

Execution → C2
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. Exfiltration

  12. Impact

What it detects

This rule matches Windows file events where the target path contains Deno-generated remote HTTPS directories and also includes a user AppData location (e.g., ':\Users\' and '\AppData\'). Attackers may abuse Deno to fetch content over HTTP(s) and place it into writable application data folders to stage execution artifacts. Telemetry relied on is Windows file event data, specifically the TargetFilename path reported by the endpoint.

Related detections9 linkedT1105 — drag to rearrange
Suspicious Inline node.exe Command Executing Network and Process Spawning Code
Suspicious Deno Runtime Execution of Remote JavaScript Payload (via process_creation)
macOS: In-Memory Download and Compile via curl and osacompile in a Single Command
Suspicious Remote Script Transfer via Bitsadmin (via process_creation)
Suspicious PowerShell Download Cradle via ClickFix Fake CAPTCHA (via process_creation)
Malicious Curl MSI Download to ProgramData via Process Creation
Suspicious CloudZ RAT Payload Download via curl to ProgramData
Suspicious npm Postinstall Node Execution From Fixtures Path (BeaverTail OtterCookie)
Suspicious Velociraptor Agent Deployment via msiexec From Cloud Storage
Windows: Deno writes files from remote HTTPS content into AppData
Pivot detection · T1105 · 9 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.