Windows: Uncommon format.com File System Load via /fs parameter

Alerts on format.com executions with atypical /fs: parameters, which may indicate defense-evasion use of Windows utilities.

FreeReviewedSigma · High · v2
Product
windows
Category
process_creation
Author
Florian Roth (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2022-01-04
Updated
2026-07-31

What it detects

This rule identifies process creation where format.com is launched with a /fs: argument using a filesystem value other than common defaults. Adversaries may use format.com to load external or auxiliary components in a less typical way to reduce detection and complicate analysis. It relies on Windows process creation telemetry, specifically the image path ending with \format.com and the command line containing /fs: with uncommon filesystem selections.

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.