Windows Suspicious File Creation in AppData Outside Common Subdirectories

Alerts on new .exe/.dll/.ps1/.lnk and other files created under unusual AppData locations outside Local/LocalLow/Roaming.

FreeReviewedSigma · High · v2
Product
windows
Category
file_event
Author
Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2022-08-05
Updated
2026-07-31

What it detects

This rule flags file events where a new file path is under a user’s AppData directory but not within the commonly used AppData\Local, AppData\LocalLow, or AppData\Roaming subfolders. Attackers may use less typical AppData locations to hide or stage payloads while reducing overlap with analyst-tuned detections. It relies on Windows file event telemetry that captures the full target filename, with detection constrained to specific executable and script-like extensions.

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.