Windows Process Creation: Image contains NTFS 8.3 short filename patterns

Flags process creation events where the Image contains Windows 8.3 short-name patterns (e.g., ~1.exe, ~2.ps1) to evade image-based detections.

FreeReviewedSigma · Medium · v1
Product
windows
Category
process_creation
Author
frack113, Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2022-08-06
Updated
2026-07-30
title: "Windows Process Creation: Image contains NTFS 8.3 short filename patterns"
id: 131b593f-809d-42c1-86c4-792e29504de4
related:
  - id: dd6b39d9-d9be-4a3b-8fe0-fe3c6a5c1795
    type: similar
  - id: 3ef5605c-9eb9-47b0-9a71-b727e6aa5c3b
    type: derived
status: test
description: This rule identifies Windows processes where the recorded Image path contains common NTFS 8.3 short-name patterns (e.g., ~1.exe, ~2.ps1). Attackers may use these short names to reduce the effectiveness of filename-based image detections and complicate asset visibility. It relies on process creation telemetry, specifically the Image field content and ParentImage exclusions for common benign parent processes and known installer paths.
references:
  - https://www.acunetix.com/blog/articles/windows-short-8-3-filenames-web-security-problem/
  - https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-2000-server/cc959352(v=technet.10)
  - https://twitter.com/jonasLyk/status/1555914501802921984
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_susp_ntfs_short_name_use_image.yml
author: frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule Team
date: 2022-08-06
modified: 2023-07-20
tags:
  - attack.stealth
  - attack.t1564.004
logsource:
  category: process_creation
  product: windows
detection:
  selection:
    Image|contains:
      - ~1.bat
      - ~1.dll
      - ~1.exe
      - ~1.hta
      - ~1.js
      - ~1.msi
      - ~1.ps1
      - ~1.tmp
      - ~1.vbe
      - ~1.vbs
      - ~2.bat
      - ~2.dll
      - ~2.exe
      - ~2.hta
      - ~2.js
      - ~2.msi
      - ~2.ps1
      - ~2.tmp
      - ~2.vbe
      - ~2.vbs
  filter_main_generic_parent:
    ParentImage: C:\Windows\explorer.exe
  filter_optional_webex:
    ParentImage|endswith: \WebEx\WebexHost.exe
  filter_optional_thor:
    ParentImage|endswith: \thor\thor64.exe
  filter_optional_winzip:
    Image: C:\PROGRA~1\WinZip\WZPREL~1.EXE
  filter_optional_vcred:
    Image|endswith: \VCREDI~1.EXE
  condition: selection and not 1 of filter_main_* and not 1 of filter_optional_*
falsepositives:
  - Software Installers
level: medium
license: DRL-1.1