Windows WebDAV Temporary File Creation with Suspicious Extensions

Flags creation of WebDAV temporary files on Windows in a Tfs_DAV temp path with executable/archive-like extensions.

FreeReviewedSigma · Medium · v5
Product
windows
Category
file_event
Author
Micah Babinski (SigmaHQ), DRL 1.1
Published
2023-08-21
Updated
2026-07-31

ATT&CK techniques

Resource Dev → Initial Access
  1. Recon

  2. Initial Access

  3. Execution

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule flags file creation events targeting the WebDAV temporary local storage path under AppData\Local\Temp\TfsStore\Tfs_DAV\ and ending with potentially risky extensions (e.g., .bat, .ps1, .vbs, .js, .lnk, .zip). Attackers may use WebDAV to stage and transfer executable or scriptable files, leveraging temporary local writes during access. It relies on Windows file event telemetry that includes the created TargetFilename for matching against the specified path and extension suffixes.

Related detections9 linkedT1566 — drag to rearrange
Proxy WebDAV MiniRedir Drives Execution from External Shares
Malicious Office 365 Email Rule Breach - On Behalf (via office365)
Suspicious AWS Console AiTM Phishing Kit API Endpoints
Suspicious PowerShell Download of updserc Archive to AppData via ClickFix
AWS CloudTrail SSM SendCommand Successful Execution for Instance
Okta FastPass blocks phishing authentication attempts via MFA
macOS Script Editor Spawns Suspicious Command-Line Interpreters
Suspicious Process Execution by Microsoft OneNote on Windows Child Programs
Windows DLL Search Order Hijacking: Suspicious DLL Writes to App Dependency Folders
Windows WebDAV Temporary File Creation with Suspicious Extensions
Pivot detection · T1566 · 9 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.