Windows: Suspicious .SCR Screensaver File Creation

Alerts on creation of new .scr screensaver binaries on Windows, excluding known benign paths and a specific TiWorker case.

FreeReviewedSigma · Medium · v2
Product
windows
Category
file_event
Author
frack113 (SigmaHQ), DRL 1.1
Published
2021-12-29
Updated
2026-07-31

ATT&CK techniques

Persistence → Priv Esc
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Defense Evasion

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule flags file creation events where the target filename ends with a .scr extension, consistent with Windows screensaver binaries. Attackers may use screensavers executed after user inactivity as a persistence mechanism. It relies on Windows file event telemetry that includes the created target filename and, where available, the creating process image path to filter known benign cases.

Related detections2 linkedT1546.002 — drag to rearrange
Windows: Detect reg.exe Changing Screen Saver Registry Settings for .scr Payloads
Windows Registry Screensaver Path Value Modified (SCRNSAVE.EXE)
Windows: Suspicious .SCR Screensaver File Creation
Pivot detection · T1546.002 · 2 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.