Windows file events matching SNAKE-related installer filename indicators

Flags Windows file events with target filenames ending in common SNAKE installer indicators like jpsetup.exe and jpinst.exe.

FreeReviewedSigma · Low · v5
Product
windows
Category
file_event
Author
Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2023-05-10
Updated
2026-07-31

What it detects

This rule identifies Windows file creation or execution activity where the target filename ends with either \jpsetup.exe or \jpinst.exe, based on filename indicators reported by CISA for SNAKE malware. Attackers may use these masqueraded installer filenames to stage or run malicious components while blending in with plausible software naming. The detection relies on Windows file event telemetry that records the target filename.

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.