Windows File Indicator: SNAKE Malware Kernel Driver Target File Comadmin.dat

Alerts on Windows file events involving C:\Windows\System32\Com\Comadmin.dat, an indicator tied to SNAKE kernel driver activity.

FreeReviewedSigma · Critical · v5
Product
windows
Category
file_event
Author
Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2023-05-10
Updated
2026-07-31

What it detects

This rule matches Windows file events where the target filename is exactly C:\Windows\System32\Com\Comadmin.dat. The presence or creation of this specific file path can indicate installation or staging activity associated with SNAKE malware components. It relies on file event telemetry that includes the target filename field for Windows.

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.