Windows File Events: Executables Writing Files with Suspicious Extensions
Alerts when common Windows system executables write files ending in suspicious extensions like .ps1, .bat, .vbs, or .hta.
FreeUnreviewedSigmahighv1
windows-file-events-executables-writing-files-with-suspicious-extensions-b8fd0e93
title: "Windows File Events: Executables Writing Files with Suspicious Extensions"
id: e5dac084-2ce0-415a-96f1-81bccf8d7fb6
related:
- id: 1277f594-a7d1-4f28-a2d3-73af5cbeab43
type: derived
- id: b8fd0e93-ff58-4cbd-8f48-1c114e342e62
type: derived
status: test
description: This rule flags Windows file write events where the writing process is one of several system executables (for example csrss.exe, lsass.exe, rundll32.exe) and the target filename ends with potentially suspicious extensions such as .ps1, .bat, .vbs, .hta, .dll, or .exe. Attackers often use script and executable payloads dropped to disk to establish persistence or execute code, so unexpected writes with these extensions from core process image names are a notable stealth indicator. The detection relies on Windows file event telemetry that provides the Image path/name and the TargetFilename written.
references:
- Internal Research
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/file/file_event/file_event_win_shell_write_susp_files_extensions.yml
author: Nasreddine Bencherchali (Nextron Systems), Huntrule Team
date: 2022-08-12
modified: 2025-10-07
tags:
- attack.stealth
- attack.t1036
logsource:
category: file_event
product: windows
detection:
selection_generic:
Image|endswith:
- \csrss.exe
- \lsass.exe
- \RuntimeBroker.exe
- \sihost.exe
- \smss.exe
- \wininit.exe
- \winlogon.exe
TargetFilename|endswith:
- .bat
- .dll
- .exe
- .hta
- .iso
- .ps1
- .txt
- .vbe
- .vbs
selection_special:
Image|endswith:
- \dllhost.exe
- \rundll32.exe
- \svchost.exe
TargetFilename|endswith:
- .bat
- .hta
- .iso
- .ps1
- .vbe
- .vbs
filter_main_AppLockerPolicyTest:
Image: C:\Windows\System32\dllhost.exe
TargetFilename|contains|all:
- :\Users\
- \AppData\Local\Temp\__PSScriptPolicyTest_
TargetFilename|endswith: .ps1
filter_main_script_gpo_machine:
Image: C:\Windows\system32\svchost.exe
TargetFilename|contains|all:
- C:\Windows\System32\GroupPolicy\DataStore\
- \sysvol\
- \Policies\
- \Machine\Scripts\Startup\
TargetFilename|endswith:
- .ps1
- .bat
filter_main_clipchamp:
Image: C:\Windows\system32\svchost.exe
TargetFilename|contains|all:
- C:\Program Files\WindowsApps\Clipchamp
- .ps1
filter_main_powershell_preview:
Image:
- C:\Windows\system32\svchost.exe
- C:\Windows\SysWOW64\svchost.exe
TargetFilename|startswith:
- C:\Program Files\WindowsApps\Microsoft.PowerShellPreview
- C:\Program Files (x86)\WindowsApps\Microsoft.PowerShellPreview
TargetFilename|endswith: .ps1
condition: 1 of selection_* and not 1 of filter_main_*
falsepositives:
- Unknown
level: high
license: DRL-1.1
What it detects
This rule flags Windows file write events where the writing process is one of several system executables (for example csrss.exe, lsass.exe, rundll32.exe) and the target filename ends with potentially suspicious extensions such as .ps1, .bat, .vbs, .hta, .dll, or .exe. Attackers often use script and executable payloads dropped to disk to establish persistence or execute code, so unexpected writes with these extensions from core process image names are a notable stealth indicator. The detection relies on Windows file event telemetry that provides the Image path/name and the TargetFilename written.
Known false positives
- Unknown
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.