Windows: Report.wer File Created in Uncommon WER ReportArchive Subfolders

Alerts on Report.wer creation under WER ReportArchive paths that don’t match common subfolder patterns.

FreeReviewedSigma · Medium · v5
Product
windows
Category
file_event
Author
Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2023-08-23
Updated
2026-07-31

What it detects

This rule flags creation of a Report.wer file located under the Windows Error Reporting (WER) ReportArchive path, specifically within a target folder structure that is not among common subfolder patterns. An attacker may drop or trigger WER-related artifacts to facilitate exploitation or post-exploitation activity. The detection relies on Windows file event telemetry capturing the full TargetFilename and matching its ending name plus the presence of the expected WER directory prefix.

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.