Windows network connection from process running in suspicious or uncommon file paths

Alerts on Windows network connections initiated by processes executing from suspicious or uncommon directories.

FreeReviewedSigma · High · v2
Product
windows
Category
network_connection
Author
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2017-03-19
Updated
2026-07-31
title: Windows network connection from process running in suspicious or uncommon file paths
id: 8c4ee897-ea32-4d6e-b2ae-3168ddf83ac1
related:
  - id: 8b48ad89-10d8-4382-a546-50588c410f0d
    type: similar
  - id: d635249d-86b5-4dad-a8c7-d7272b788586
    type: similar
  - id: 52182dfb-afb7-41db-b4bc-5336cb29b464
    type: similar
  - id: ae02ed70-11aa-4a22-b397-c0d0e8f6ea99
    type: similar
  - id: e0f8ab85-0ac9-423b-a73a-81b3c7b1aa97
    type: similar
  - id: 8518ed3d-f7c9-4601-a26c-f361a4256a0c
    type: similar
  - id: 42a5f1e7-9603-4f6d-97ae-3f37d130d794
    type: similar
  - id: 56454143-524f-49fb-b1c6-3fb8b1ad41fb
    type: similar
  - id: b6e04788-29e1-4557-bb14-77f761848ab8
    type: similar
  - id: a0d7e4d2-bede-4141-8896-bc6e237e977c
    type: similar
  - id: 297ae038-edc2-4b2e-bb3e-7c5fc94dd5c7
    type: similar
  - id: 7b434893-c57d-4f41-908d-6a17bf1ae98f
    type: derived
status: test
description: This rule flags Windows network connections where the initiating process is running from a suspicious or uncommon file system location (for example, recycle bin, temp directories, default/public user folders, and various Windows subpaths). Attackers frequently execute or stage payloads from such locations to evade normal allowlists and blend into transient or user-writable areas before command-and-control communication. It relies on telemetry indicating the network connection was initiated and the process image path, including substring matches against known suspicious directory patterns, while excluding several common destination host domains.
references:
  - https://docs.google.com/spreadsheets/d/17pSTDNpa0sf6pHeRhusvWG6rThciE8CsXTSlDUAZDyo
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/network_connection/net_connection_win_susp_initiated_uncommon_or_suspicious_locations.yml
author: Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule Team
date: 2017-03-19
modified: 2026-03-29
tags:
  - attack.command-and-control
  - attack.t1105
logsource:
  category: network_connection
  product: windows
detection:
  selection:
    Initiated: "true"
    Image|contains:
      - :\$Recycle.bin
      - :\Perflogs\
      - :\Temp\
      - :\Users\Default\
      - :\Users\Public\
      - :\Windows\Fonts\
      - :\Windows\IME\
      - :\Windows\System32\Tasks\
      - :\Windows\Tasks\
      - \config\systemprofile\
      - \Contacts\
      - \Favorites\
      - \Favourites\
      - \Music\
      - \Pictures\
      - \Videos\
      - \Windows\addins\
  filter_main_domains:
    DestinationHostname|endswith:
      - .githubusercontent.com
      - 0x0.st
      - anonfiles.com
      - bashupload.com
      - cdn.discordapp.com
      - chunk.io
      - ddns.net
      - dl.dropboxusercontent.com
      - ghostbin.co
      - github.com
      - glitch.me
      - gofile.io
      - hastebin.com
      - mediafire.com
      - mega.co.nz
      - mega.nz
      - onrender.com
      - pages.dev
      - paste.ee
      - pastebin.com
      - pastebin.pl
      - pastetext.net
      - portmap.io
      - privatlab.com
      - privatlab.net
      - send.exploit.in
      - sendspace.com
      - storage.googleapis.com
      - storjshare.io
      - supabase.co
      - temp.sh
      - transfer.sh
      - trycloudflare.com
      - ufile.io
      - w3spaces.com
      - workers.dev
      - x0.at
  condition: selection and not 1 of filter_main_*
falsepositives:
  - Unknown
level: high
license: DRL-1.1