Windows Process Creation: SoundRecorder audio capture using /FILE
Flags SoundRecorder.exe launches that include /FILE, indicating potential audio capture on Windows.
- Product
- windows
- Category
- process_creation
- Author
- E.M. Anhaus (originally from Atomic Blue Detections, Endgame), oscd.community (SigmaHQ), DRL 1.1
- Published
- 2019-10-24
- Updated
- 2026-07-30
ATT&CK techniques
CollectionRecon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule identifies Windows process executions of SoundRecorder.exe where the command line includes the /FILE parameter, which is used to capture and save audio. Audio recording can be used for credential theft, surveillance, or gathering sensitive information from a user’s environment. The detection relies on process creation telemetry, matching the executable name and a specific command-line argument.
Reporting behind it
- github.comhttps://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1123/T1123.md
- eqllib.readthedocs.iohttps://eqllib.readthedocs.io/en/latest/analytics/f72a98cb-7b3d-4100-99c3-a138b6e9ff6e.html
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_soundrecorder_audio_capture.yml
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: "Windows Process Creation: SoundRecorder audio capture using /FILE"
id: a411f82a-5b0a-435c-bd2f-caca26694982
status: test
description: This rule identifies Windows process executions of SoundRecorder.exe where the command line includes the /FILE parameter, which is used to capture and save audio. Audio recording can be used for credential theft, surveillance, or gathering sensitive information from a user’s environment. The detection relies on process creation telemetry, matching the executable name and a specific command-line argument.
references:
- https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1123/T1123.md
- https://eqllib.readthedocs.io/en/latest/analytics/f72a98cb-7b3d-4100-99c3-a138b6e9ff6e.html
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_soundrecorder_audio_capture.yml
author: E.M. Anhaus (originally from Atomic Blue Detections, Endgame), oscd.community, Huntrule Team
date: 2019-10-24
modified: 2021-11-27
tags:
- attack.collection
- attack.t1123
logsource:
category: process_creation
product: windows
detection:
selection:
Image|endswith: \SoundRecorder.exe
CommandLine|contains: /FILE
condition: selection
falsepositives:
- Legitimate audio capture by legitimate user.
level: medium
license: DRL-1.1
related:
- id: 83865853-59aa-449e-9600-74b9d89a6d6e
type: derived