Windows: Executable File Creation Where a Parent Executable Writes Another .exe

Flags .exe-to-.exe executable drops on Windows when a running executable creates another .exe, with exclusions for common system/update paths.

FreeUnreviewedSigmalowv1
title: "Windows: Executable File Creation Where a Parent Executable Writes Another .exe"
id: 816d4ca0-12ca-4986-a379-0ffd9ff06ae9
status: test
description: This rule identifies file creation events where a process image ending in .exe writes a target file that also ends in .exe on Windows. It matters because attackers may drop or stage a secondary executable by launching it from another executable, which can be part of malware installation or payload staging. The detection relies on Windows file event telemetry that provides the creating process path (Image) and the created file path (TargetFilename), while excluding common Windows and software update behaviors to reduce noise.
references:
  - Internal Research
  - https://github.com/SigmaHQ/sigma/blob/master/rules-threat-hunting/windows/file/file_event/file_event_win_susp_binary_dropper.yml
author: frack113, Huntrule Team
date: 2022-03-09
modified: 2025-02-24
tags:
  - attack.resource-development
  - attack.t1587.001
  - detection.threat-hunting
logsource:
  product: windows
  category: file_event
detection:
  selection:
    Image|endswith: .exe
    TargetFilename|endswith: .exe
  filter_main_generic_1:
    Image|endswith:
      - :\Windows\System32\msiexec.exe
      - :\Windows\system32\cleanmgr.exe
      - :\Windows\explorer.exe
      - :\WINDOWS\system32\dxgiadaptercache.exe
      - :\WINDOWS\system32\Dism.exe
      - :\Windows\System32\wuauclt.exe
  filter_main_update:
    Image|endswith: :\WINDOWS\system32\svchost.exe
    TargetFilename|contains: :\Windows\SoftwareDistribution\Download\
  filter_main_upgrade:
    Image|endswith: :\Windows\system32\svchost.exe
    TargetFilename|contains|all:
      - :\WUDownloadCache\
      - \WindowsUpdateBox.exe
  filter_main_windows_update_box:
    Image|contains: :\WINDOWS\SoftwareDistribution\Download\
    Image|endswith: \WindowsUpdateBox.Exe
    TargetFilename|contains: :\$WINDOWS.~BT\Sources\
  filter_main_tiworker:
    Image|contains: :\Windows\WinSxS\
    Image|endswith: \TiWorker.exe
  filter_main_programfiles:
    - Image|contains:
        - :\Program Files\
        - :\Program Files (x86)\
    - TargetFilename|contains:
        - :\Program Files\
        - :\Program Files (x86)\
  filter_main_defender:
    Image|contains:
      - :\ProgramData\Microsoft\Windows Defender\
      - :\Program Files\Windows Defender\
  filter_main_windows_apps:
    TargetFilename|contains: \AppData\Local\Microsoft\WindowsApps\
  filter_main_teams:
    Image|endswith: \AppData\Local\Microsoft\Teams\Update.exe
    TargetFilename|endswith:
      - \AppData\Local\Microsoft\Teams\stage\Teams.exe
      - \AppData\Local\Microsoft\Teams\stage\Squirrel.exe
      - \AppData\Local\Microsoft\SquirrelTemp\tempb\
  filter_main_mscorsvw:
    Image|contains:
      - :\Windows\Microsoft.NET\Framework\
      - :\Windows\Microsoft.NET\Framework64\
      - :\Windows\Microsoft.NET\FrameworkArm\
      - :\Windows\Microsoft.NET\FrameworkArm64\
    Image|endswith: \mscorsvw.exe
    TargetFilename|contains: :\Windows\assembly\NativeImages_
  filter_main_vscode:
    Image|contains: \AppData\Local\
    Image|endswith: \Microsoft VS Code\Code.exe
    TargetFilename|contains: \.vscode\extensions\
  filter_main_githubdesktop:
    Image|endswith: \AppData\Local\GitHubDesktop\Update.exe
    TargetFilename|contains: \AppData\Local\SquirrelTemp\
  filter_main_windows_temp:
    - Image|contains: :\WINDOWS\TEMP\
    - TargetFilename|contains: :\WINDOWS\TEMP\
  filter_optional_python:
    Image|contains: \Python27\python.exe
    TargetFilename|contains:
      - \Python27\Lib\site-packages\
      - \Python27\Scripts\
      - \AppData\Local\Temp\
  filter_optional_squirrel:
    Image|contains: \AppData\Local\SquirrelTemp\Update.exe
    TargetFilename|contains: \AppData\Local
  filter_main_temp_installers:
    - Image|contains: \AppData\Local\Temp\
    - TargetFilename|contains: \AppData\Local\Temp\
  filter_optional_chrome:
    Image|endswith: \ChromeSetup.exe
    TargetFilename|contains: \Google
  filter_main_dot_net:
    Image|contains: :\Windows\Microsoft.NET\Framework
    Image|endswith: \mscorsvw.exe
    TargetFilename|contains: :\Windows\assembly
  condition: selection and not 1 of filter_main_* and not 1 of filter_optional_*
falsepositives:
  - Software installers
  - Update utilities
  - 32bit applications launching their 64bit versions
level: low
license: DRL-1.1
related:
  - id: 297afac9-5d02-4138-8c58-b977bac60556
    type: derived

What it detects

This rule identifies file creation events where a process image ending in .exe writes a target file that also ends in .exe on Windows. It matters because attackers may drop or stage a secondary executable by launching it from another executable, which can be part of malware installation or payload staging. The detection relies on Windows file event telemetry that provides the creating process path (Image) and the created file path (TargetFilename), while excluding common Windows and software update behaviors to reduce noise.

Known false positives

  • Software installers
  • Update utilities
  • 32bit applications launching their 64bit versions

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.