Windows Process Creation: SoundRecorder audio capture using /FILE

Flags SoundRecorder.exe launches that include /FILE, indicating potential audio capture on Windows.

FreeReviewedSigma · Medium · v1
Product
windows
Category
process_creation
Author
E.M. Anhaus (originally from Atomic Blue Detections, Endgame), oscd.community (SigmaHQ), DRL 1.1
Published
2019-10-24
Updated
2026-07-30

ATT&CK techniques

Collection
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule identifies Windows process executions of SoundRecorder.exe where the command line includes the /FILE parameter, which is used to capture and save audio. Audio recording can be used for credential theft, surveillance, or gathering sensitive information from a user’s environment. The detection relies on process creation telemetry, matching the executable name and a specific command-line argument.

Related detections5 linkedT1123 — drag to rearrange
OpenCanary SIP Request on Honeypot Node
Linux Audio Capture via arecord and ecasound (auditd execve and memfd_create)
Windows Registry Changes Indicating Suspicious Camera/Microphone Capability Access
Windows processes accessing microphone and webcam via CapabilityAccessManager ConsentStore
Windows PowerShell Audio Capture Cmdlets: Toggle/Get/Set/Write AudioDevice
Windows Process Creation: SoundRecorder audio capture using /FILE
Pivot detection · T1123 · 5 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.