Windows Shell-Core: Installed Application Shortcut Indicators for Known Tools

Flags suspicious installation-style activity in Windows shell-core based on EventID 28115 app resolver cache entries for specific tools.

FreeReviewedSigma · Medium · v2
Product
windows
Service
shell-core
Author
Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2022-08-14
Updated
2026-07-31

What it detects

This rule flags Windows Shell-Core events that indicate a suspicious application installation based on added shortcuts to the app resolver cache. It matches specific application names and process-related AppIDs associated with networking and remote access tools, which are commonly abused by attackers for discovery and remote access. The detection relies on Shell-Core event telemetry with EventID 28115 and the Name/AppID string contents.

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.