Windows: Remote Network Share Writes to desktop.ini

Flags remote network-shared desktop.ini being written to with high-impact permissions in Windows Security logs.

FreeReviewedSigma · Medium · v2
Product
windows
Service
security
Author
Tim Shelton (HAWK.IO) (SigmaHQ), DRL 1.1
Published
2021-12-06
Updated
2026-07-31

ATT&CK techniques

Persistence → Priv Esc
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Defense Evasion

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule flags Security Event 5145 file access events where a process writes or modifies desktop.ini over a network share. Altering desktop.ini can change how Windows Explorer displays folder contents, which attackers may use to mislead users without changing underlying files. It relies on Windows Security audit telemetry for remote file operations, matching events for desktop.ini with access rights indicating write and modification behavior.

Related detections6 linkedT1547.009 — drag to rearrange
URL Shortcut File Created in Startup Folder for Persistence
NTFS Hard Link Creation (via process_creation)
NTFS Symbolic Link Configuration Change (via process_creation)
Windows: File creation of C:\program.exe enabling unquoted service path execution
Windows File Creation: Custom Application Shim Database Files Created
Windows Desktop.ini Accessed by Uncommon Process
Windows: Remote Network Share Writes to desktop.ini
Pivot detection · T1547.009 · 6 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.