Windows Startup Folder File Creation with Suspicious Script/Executable Extensions

Alerts on creation of startup-folder files with script/executable extensions commonly used for logon persistence on Windows.

FreeReviewedSigma · High · v2
Product
windows
Category
file_event
Author
Nasreddine Bencherchali (Nextron Systems), Swachchhanda Shrawan Poudel (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2022-08-10
Updated
2026-07-31

ATT&CK techniques

Execution → Priv Esc
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Defense Evasion

  5. Cred Access

  6. Discovery

  7. Lateral Movement

  8. Collection

  9. C2

  10. Exfiltration

  11. Impact

What it detects

This rule flags file events where the target path is within the Windows Startup folder and the filename ends with extensions commonly used for scripts or executable content (such as .ps1, .vbs, .js, .bat, .cmd, .hta, .scr, and others). Startup folder writes can enable persistence because items placed there may run automatically when the user logs in. It relies on Windows file event telemetry capturing the TargetFilename path and extension.

Related detections9 linkedT1547.001 — drag to rearrange
Uncommon Executable Written to Startup Folder by WinRAR via CVE-2025-8088 Path Traversal (via file_event)
Suspicious Autorun Registry Persistence via sausageLoop Run Key
Malicious BabyLockerKZ Run Key Persistence
Suspicious Run Key Persistence Pointing To User-Writable Path
Malicious Ctrlpanel Run Key Autostart Persistence (via registry_set)
Persistence Run Key Pointing to svchost.exe in AppData Roaming
Suspicious n8n Campaign RMM Installer Masquerading as OneDrive Document
Suspicious NFe-Themed Brazilian Lure Executable Execution
Suspicious Executable Dropped in Public Users Directory Named Ctrlpanel (via file_event)
Windows Startup Folder File Creation with Suspicious Script/Executable Extensions
Pivot detection · T1547.001 · 9 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.