Windows: Files created by Microsoft Sync Center (mobsync.exe) with .dll/.exe extensions

Flags .dll and .exe files created by mobsync.exe on Windows.

FreeReviewedSigma · Medium · v2
Product
windows
Category
file_event
Author
elhoim (SigmaHQ), DRL 1.1
Published
2022-04-28
Updated
2026-07-31

ATT&CK techniques

Priv Esc → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule flags file creation events where the creating process is Microsoft Sync Center (mobsync.exe) and the created file ends with .dll or .exe. Attackers can abuse legitimate sync functionality to drop or stage executable payloads while blending in with normal system activity. It relies on Windows file event telemetry that records the process image path and the target filename for the creation event.

Related detections9 linkedT1055 — drag to rearrange
Malicious aspnet_compiler.exe Injection Host Spawned by PowerShell via process_creation
Suspicious RegAsm or RegSvcs Spawned by Script Host (via process_creation)
Windows Image Load: coregen.exe Potential DLL Sideloading
Windows Microsoft Sync Center (mobsync.exe) Network Connections to Public IPs
Suspicious Office Application Spawning Script Or Shell Interpreter
Suspicious Network Connection From wabmig.exe (Turian Injection)
Suspicious Outbound Network Connection from Explorer Process
Suspicious AppLaunch.exe Spawned As Injection Target (via process_creation)
Suspicious BugSleep Marker File in Public Directory
Windows: Files created by Microsoft Sync Center (mobsync.exe) with .dll/.exe extensions
Pivot detection · T1055 · 9 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.