Windows: OneNote .one/.onepkg File Creation in Suspicious Locations

Flags creation of OneNote attachment files (.one/.onepkg) in temp/public-style paths on Windows.

FreeReviewedSigma · Medium · v2
Product
windows
Category
file_event
Author
Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2023-01-22
Updated
2026-07-31

What it detects

This rule flags creation of files ending in .one or .onepkg within uncommon or potentially risky Windows paths, including temporary and public directories. Attackers can abuse OneNote attachment file types to stage payloads or support malicious delivery workflows, making unexpected drops in these locations noteworthy. The detection relies on file creation telemetry including target file paths and the creating process image path to exclude a common legitimate OneNote process origin.

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.