Windows Startup Folder File Write for Persistence (T1547.001)
Alerts on file writes into the Windows Startup folder that may indicate user-level persistence.
FreeUnreviewedSigmamediumv1
windows-startup-folder-file-write-for-persistence-t1547-001-2aa0a6b4
title: Windows Startup Folder File Write for Persistence (T1547.001)
id: c1bc8dda-d56b-4d0b-a023-41018f8c5e6b
related:
- id: 28208707-fe31-437f-9a7f-4b1108b94d2e
type: similar
- id: 2aa0a6b4-a865-495b-ab51-c28249537b75
type: derived
status: test
description: This rule flags file creation events where the target path contains the Windows Startup folder location under the Start Menu programs. Attackers use Startup folder writes to establish user-level persistence by placing shortcuts or executables that run at logon. It relies on Windows file event telemetry, specifically the created/target filename path and the creating process image, with exclusions for known update and scratch paths and a limited OneNote shortcut scenario.
references:
- https://github.com/OTRF/detection-hackathon-apt29/issues/12
- https://github.com/OTRF/ThreatHunter-Playbook/blob/2d4257f630f4c9770f78d0c1df059f891ffc3fec/docs/evals/apt29/detections/5.B.1_611FCA99-97D0-4873-9E51-1C1BA2DBB40D.md
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/file/file_event/file_event_win_startup_folder_file_write.yml
author: Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule Team
date: 2020-05-02
modified: 2025-12-03
tags:
- attack.privilege-escalation
- attack.persistence
- attack.t1547.001
logsource:
product: windows
category: file_event
detection:
selection:
TargetFilename|contains: \Microsoft\Windows\Start Menu\Programs\StartUp
filter_main_update:
- Image:
- C:\Windows\System32\wuauclt.exe
- C:\Windows\uus\ARM64\wuaucltcore.exe
- TargetFilename|startswith:
- C:\$WINDOWS.~BT\NewOS\
- C:\$WinREAgent\Scratch\Mount\
filter_optional_onenote:
Image|endswith: \ONENOTE.EXE
TargetFilename|endswith: \Send to OneNote.lnk
condition: selection and not 1 of filter_main_* and not 1 of filter_optional_*
falsepositives:
- FP could be caused by legitimate application writing shortcuts for example. This folder should always be inspected to make sure that all the files in there are legitimate
level: medium
license: DRL-1.1
What it detects
This rule flags file creation events where the target path contains the Windows Startup folder location under the Start Menu programs. Attackers use Startup folder writes to establish user-level persistence by placing shortcuts or executables that run at logon. It relies on Windows file event telemetry, specifically the created/target filename path and the creating process image, with exclusions for known update and scratch paths and a limited OneNote shortcut scenario.
Known false positives
- FP could be caused by legitimate application writing shortcuts for example. This folder should always be inspected to make sure that all the files in there are legitimate
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.