Windows File Events: Suspicious .exe.local Path With comctl32.dll in System32

Detects System32 *.exe.local entries that reference comctl32.dll, consistent with DLL sideloading behavior.

FreeReviewedSigma · High · v2
Product
windows
Category
file_event
Author
Nasreddine Bencherchali (Nextron Systems), Subhash P (@pbssubhash) (SigmaHQ), DRL 1.1
Published
2022-12-16
Updated
2026-07-31

What it detects

This rule flags file events where a target path under C:\Windows\System32 matches specific *.exe.local artifacts and ends with \comctl32.dll. Creating or placing DLLs under the System32 .exe.local mechanism can indicate an attempt to sideload a DLL and achieve privilege escalation or stealthy persistence. It relies on Windows file event telemetry capturing the full target filename for the created or modified file path.

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.