Windows File Events Indicative of SlashAndGrab ScreenConnect Post-Exploitation

Alerts on Windows file activity writing known SlashAndGrab-related ScreenConnect artifact paths and executables.

FreeReviewedSigma · High · v5
Product
windows
Category
file_event
Author
Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2024-02-23
Updated
2026-07-31

What it detects

This rule flags Windows file creation or access events that match a set of specific file paths and filenames associated with post-exploitation activity following the SlashAndGrab vulnerability against ScreenConnect. Attackers may drop executables, MSI packages, and other components into predictable directories to stage payloads and establish persistence. It relies on telemetry that reports file events with a populated TargetFilename field, allowing matching on the enumerated path indicators.

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.