Windows Terminal settings.json modified by uncommon process

Alerts on Windows Terminal settings.json changes made by an uncommon command-line or script host process.

FreeReviewedSigma · Medium · v2
Product
windows
Category
file_event
Author
frack113, Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2023-07-22
Updated
2026-07-31

ATT&CK techniques

Persistence → Priv Esc
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Defense Evasion

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule flags file creation or modification of the Windows Terminal user settings file (settings.json) when the writing process is not among common shell/script interpreters. Attackers may use changes to Windows Terminal profile settings to persist or stage activity under a user context. It relies on Windows file event telemetry capturing the process image and the target settings.json path under the WindowsTerminal package directory.

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.