Windows File Creation of wermgr.exe in Uncommon Directory (Potential CVE-2023-36874)

Alerts on wermgr.exe creation in atypical Windows directories that may indicate filename spoofing.

FreeReviewedSigma · High · v5
Product
windows
Category
file_event
Author
Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2023-08-23
Updated
2026-07-31

What it detects

This rule flags creation of a Windows file named wermgr.exe when it appears in directories that are not among common system locations. Attackers may place masquerading or payload files using a misleading executable name to blend in or enable subsequent execution. The detection relies on Windows file event telemetry that includes the target filename and its full path.

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.