Windows File Events: Executables Writing Files with Suspicious Extensions

Alerts when common Windows system executables write files ending in suspicious extensions like .ps1, .bat, .vbs, or .hta.

FreeUnreviewedSigmahighv1
title: "Windows File Events: Executables Writing Files with Suspicious Extensions"
id: e5dac084-2ce0-415a-96f1-81bccf8d7fb6
related:
  - id: 1277f594-a7d1-4f28-a2d3-73af5cbeab43
    type: derived
  - id: b8fd0e93-ff58-4cbd-8f48-1c114e342e62
    type: derived
status: test
description: This rule flags Windows file write events where the writing process is one of several system executables (for example csrss.exe, lsass.exe, rundll32.exe) and the target filename ends with potentially suspicious extensions such as .ps1, .bat, .vbs, .hta, .dll, or .exe. Attackers often use script and executable payloads dropped to disk to establish persistence or execute code, so unexpected writes with these extensions from core process image names are a notable stealth indicator. The detection relies on Windows file event telemetry that provides the Image path/name and the TargetFilename written.
references:
  - Internal Research
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/file/file_event/file_event_win_shell_write_susp_files_extensions.yml
author: Nasreddine Bencherchali (Nextron Systems), Huntrule Team
date: 2022-08-12
modified: 2025-10-07
tags:
  - attack.stealth
  - attack.t1036
logsource:
  category: file_event
  product: windows
detection:
  selection_generic:
    Image|endswith:
      - \csrss.exe
      - \lsass.exe
      - \RuntimeBroker.exe
      - \sihost.exe
      - \smss.exe
      - \wininit.exe
      - \winlogon.exe
    TargetFilename|endswith:
      - .bat
      - .dll
      - .exe
      - .hta
      - .iso
      - .ps1
      - .txt
      - .vbe
      - .vbs
  selection_special:
    Image|endswith:
      - \dllhost.exe
      - \rundll32.exe
      - \svchost.exe
    TargetFilename|endswith:
      - .bat
      - .hta
      - .iso
      - .ps1
      - .vbe
      - .vbs
  filter_main_AppLockerPolicyTest:
    Image: C:\Windows\System32\dllhost.exe
    TargetFilename|contains|all:
      - :\Users\
      - \AppData\Local\Temp\__PSScriptPolicyTest_
    TargetFilename|endswith: .ps1
  filter_main_script_gpo_machine:
    Image: C:\Windows\system32\svchost.exe
    TargetFilename|contains|all:
      - C:\Windows\System32\GroupPolicy\DataStore\
      - \sysvol\
      - \Policies\
      - \Machine\Scripts\Startup\
    TargetFilename|endswith:
      - .ps1
      - .bat
  filter_main_clipchamp:
    Image: C:\Windows\system32\svchost.exe
    TargetFilename|contains|all:
      - C:\Program Files\WindowsApps\Clipchamp
      - .ps1
  filter_main_powershell_preview:
    Image:
      - C:\Windows\system32\svchost.exe
      - C:\Windows\SysWOW64\svchost.exe
    TargetFilename|startswith:
      - C:\Program Files\WindowsApps\Microsoft.PowerShellPreview
      - C:\Program Files (x86)\WindowsApps\Microsoft.PowerShellPreview
    TargetFilename|endswith: .ps1
  condition: 1 of selection_* and not 1 of filter_main_*
falsepositives:
  - Unknown
level: high
license: DRL-1.1

What it detects

This rule flags Windows file write events where the writing process is one of several system executables (for example csrss.exe, lsass.exe, rundll32.exe) and the target filename ends with potentially suspicious extensions such as .ps1, .bat, .vbs, .hta, .dll, or .exe. Attackers often use script and executable payloads dropped to disk to establish persistence or execute code, so unexpected writes with these extensions from core process image names are a notable stealth indicator. The detection relies on Windows file event telemetry that provides the Image path/name and the TargetFilename written.

Known false positives

  • Unknown

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.