Windows File Events: Suspicious Executable File Name Creation

Alerts on Windows file creation with suspicious executable filename patterns, including .bat.exe/.sys.exe and deceptive path-based names.

FreeReviewedSigma · High · v2
Product
windows
Category
file_event
Author
frack113 (SigmaHQ), DRL 1.1
Published
2022-09-05
Updated
2026-07-31

ATT&CK techniques

Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. C2

  13. Exfiltration

  14. Impact

What it detects

This rule matches Windows file creation events where the target filename ends with specific suspicious executable-related patterns. Attackers often leverage masquerading or misleading extensions (e.g., .bat.exe, .sys.exe) and may attempt to drop executables into paths associated with common privilege escalation or persistence techniques using crafted filename strings. The detection relies on Windows file event telemetry that includes the target filename for the create operation.

Related detections9 linkedT1564 — drag to rearrange
Suspicious Windows Security Spoofing via pin Executable Writing output.txt via process_creation
Obfuscated Extended Rights Backdoor Obfuscation - Via localizationDisplayId Attribute (via security)
Suspicious Process Execution from Public User Media Folders via process_creation
Suspicious Windows Sandbox Configuration Execution for AsyncRAT via Process Creation
System Informer Execution on Windows Process Creation
Linux mount executed with hidepid=2 option
Windows Process Hacker Execution Identified by Image Metadata and Hashes
Windows: Suspicious Parent Process Execution From \Users\Public Spawning Scripting/Shell Binaries
Windows Registry: Disable CrashDump via CrashControl DWORD value
Windows File Events: Suspicious Executable File Name Creation
Pivot detection · T1564 · 9 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.