Windows: File creation of C:\program.exe enabling unquoted service path execution

Flags creation of C:\program.exe that can be used to hijack unquoted Windows service binary paths.

FreeReviewedSigma · High · v2
Product
windows
Category
file_event
Author
frack113 (SigmaHQ), DRL 1.1
Published
2021-12-30
Updated
2026-07-31

ATT&CK techniques

Persistence → Priv Esc
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Defense Evasion

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule flags creation events where the target filename is exactly C:\program.exe on Windows. Creating an executable at this specific path can support unquoted service path abuse, where Windows may choose an attacker-controlled binary due to missing quotation marks in file path references. The detection relies on Windows file event telemetry capturing the created/observed filename in the filesystem.

Related detections6 linkedT1547.009 — drag to rearrange
URL Shortcut File Created in Startup Folder for Persistence
NTFS Hard Link Creation (via process_creation)
NTFS Symbolic Link Configuration Change (via process_creation)
Windows File Creation: Custom Application Shim Database Files Created
Windows: Remote Network Share Writes to desktop.ini
Windows Desktop.ini Accessed by Uncommon Process
Windows: File creation of C:\program.exe enabling unquoted service path execution
Pivot detection · T1547.009 · 6 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.