Windows Desktop.ini Accessed by Uncommon Process

Alerts when unexpected processes create or access Desktop.ini, which can be abused to change how Explorer displays folder contents.

FreeReviewedSigma · Medium · v2
Product
windows
Category
file_event
Author
Maxime Thiebaut (@0xThiebaut), Tim Shelton (HAWK.IO) (SigmaHQ), DRL 1.1
Published
2020-03-19
Updated
2026-07-31

ATT&CK techniques

Persistence → Priv Esc
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Defense Evasion

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule flags file events where a process other than common system and installer paths accesses or targets a Desktop.ini file (ending with \desktop.ini). Attackers can use Desktop.ini to influence how Windows Explorer presents folder contents, which can support deceptive file renaming without modifying the underlying files. It relies on Windows file event telemetry that includes the process image path (Image) and the targeted filename (TargetFilename).

Related detections6 linkedT1547.009 — drag to rearrange
URL Shortcut File Created in Startup Folder for Persistence
NTFS Hard Link Creation (via process_creation)
NTFS Symbolic Link Configuration Change (via process_creation)
Windows: File creation of C:\program.exe enabling unquoted service path execution
Windows File Creation: Custom Application Shim Database Files Created
Windows: Remote Network Share Writes to desktop.ini
Windows Desktop.ini Accessed by Uncommon Process
Pivot detection · T1547.009 · 6 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.