Windows: RURAT (Remote Utilities) Executed From Unusual Path

Alerts on Remote Utilities RURAT executables running outside the typical Program Files install paths on Windows.

FreeReviewedSigma · Medium · v1
Product
windows
Category
process_creation
Author
Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2022-09-19
Updated
2026-07-30

What it detects

This rule flags process creation where Remote Utilities client binaries associated with RURAT (rutserv.exe and rfusclient.exe) are launched from locations other than the standard Remote Utilities installation directories under Program Files. Attackers may run RAT components from non-default paths to reduce exposure, blend in with other files, or persist after installation. The detection relies on Windows process creation telemetry, matching executable paths and applying exclusions for the expected installation locations.

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.