Windows Suspicious Executable Dropping by Known Apps and LOLBINs

Alerts on Windows processes like Office/LOLBINs writing .exe/.dll and other executable-equivalent files to disk.

FreeUnreviewedSigmahighv1
title: Windows Suspicious Executable Dropping by Known Apps and LOLBINs
id: 820c32fc-87b2-4905-8da0-4bbc42091757
status: test
description: This rule flags Windows file creation events where specific legitimate applications and LOLBINs write an executable-equivalent file to disk. Attackers may use trusted binaries to stage payloads or deliver malware by dropping files with executable extensions during defense evasion and initial execution. It relies on file event telemetry that captures the creating process image path and the target filename written to disk.
references:
  - https://github.com/Neo23x0/sysmon-config/blob/3f808d9c022c507aae21a9346afba4a59dd533b9/sysmonconfig-export-block.xml#L1326
  - https://dmpdump.github.io/posts/TelegramRat/
  - https://www.virustotal.com/gui/file/a0d5b30578acd1df9139e7a8a4bfc659dc2cf48f4dc0c5804b70890adeb9fa21/behavior
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/file/file_event/file_event_win_susp_legitimate_app_dropping_exe.yml
author: frack113, Florian Roth (Nextron Systems), Huntrule Team
date: 2022-08-21
modified: 2026-05-11
tags:
  - attack.stealth
  - attack.t1218
logsource:
  product: windows
  category: file_event
detection:
  selection:
    Image|endswith:
      - \eqnedt32.exe
      - \wordpad.exe
      - \wordview.exe
      - \certutil.exe
      - \certoc.exe
      - \CertReq.exe
      - \Desktopimgdownldr.exe
      - \esentutl.exe
      - \mshta.exe
      - \AcroRd32.exe
      - \RdrCEF.exe
      - \hh.exe
      - \finger.exe
    TargetFilename|endswith:
      - .com
      - .dll
      - .exe
      - .jar
      - .ocx
      - .pyc
  condition: selection
falsepositives:
  - Unknown
level: high
regression_tests_path: regression_data/rules/windows/file/file_event/file_event_win_susp_legitimate_app_dropping_exe/info.yml
license: DRL-1.1
related:
  - id: f0540f7e-2db3-4432-b9e0-3965486744bc
    type: derived

What it detects

This rule flags Windows file creation events where specific legitimate applications and LOLBINs write an executable-equivalent file to disk. Attackers may use trusted binaries to stage payloads or deliver malware by dropping files with executable extensions during defense evasion and initial execution. It relies on file event telemetry that captures the creating process image path and the target filename written to disk.

Known false positives

  • Unknown

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.