Windows: Suspicious colorcpl.exe file creation/copy to System32 spool drivers color

Alerts on colorcpl.exe creating files in C:\Windows\System32\spool\drivers\color\ with suspicious target filenames.

FreeReviewedSigma · High · v2
Product
windows
Category
file_event
Author
frack113 (SigmaHQ), DRL 1.1
Published
2022-01-21
Updated
2026-07-31

ATT&CK techniques

Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. C2

  13. Exfiltration

  14. Impact

What it detects

This rule flags executions of colorcpl.exe when it creates or copies files whose target filenames end with .icm, .gmmp, .cdmp, or .camp. Such operations can be used to stage or persist artifacts in sensitive Windows directories, making the targeted filename extensions important for attacker tradecraft. It relies on Windows file event telemetry, matching the process image name ending in \colorcpl.exe and the target filename extension from the file event.

Related detections9 linkedT1564 — drag to rearrange
Suspicious Windows Security Spoofing via pin Executable Writing output.txt via process_creation
Obfuscated Extended Rights Backdoor Obfuscation - Via localizationDisplayId Attribute (via security)
Suspicious Process Execution from Public User Media Folders via process_creation
Suspicious Windows Sandbox Configuration Execution for AsyncRAT via Process Creation
System Informer Execution on Windows Process Creation
Linux mount executed with hidepid=2 option
Windows Process Hacker Execution Identified by Image Metadata and Hashes
Windows File Events: Suspicious Executable File Name Creation
Windows: Suspicious Parent Process Execution From \Users\Public Spawning Scripting/Shell Binaries
Windows: Suspicious colorcpl.exe file creation/copy to System32 spool drivers color
Pivot detection · T1564 · 9 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.