ADS Zone.Identifier Deleted By Uncommon Application

 Original Source: [Sigma source]
Title: ADS Zone.Identifier Deleted By Uncommon Application
Status: test
Description:Detects the deletion of the "Zone.Identifier" ADS by an uncommon process. Attackers can leverage this in order to bypass security restrictions that make use of the ADS such as Microsoft Office apps.
References:
  -https://securityliterate.com/how-malware-abuses-the-zone-identifier-to-circumvent-detection-and-analysis/
  -Internal Research
Author: Nasreddine Bencherchali (Nextron Systems)
Date: 2023-09-04
modified:2025-07-04
Tags:
  • -'attack.stealth'
  • -'attack.t1070.004'
Logsource:
  • product: windows
  • category: file_delete
Detection:
  selection:
    TargetFilename|endswith: ':Zone.Identifier'
  filter_main_generic:
    Image:
      -'C:\Program Files\PowerShell\7-preview\pwsh.exe'
      -'C:\Program Files\PowerShell\7\pwsh.exe'
      -'C:\Windows\explorer.exe'
      -'C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe'
      -'C:\Windows\SysWOW64\explorer.exe'
      -'C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe'

  filter_optional_browsers_chrome:
    Image:
      -'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe'
      -'C:\Program Files\Google\Chrome\Application\chrome.exe'

  filter_optional_browsers_firefox:
    Image:
      -'C:\Program Files (x86)\Mozilla Firefox\firefox.exe'
      -'C:\Program Files\Mozilla Firefox\firefox.exe'

  filter_optional_browsers_msedge:
    Image:
      -'C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe'
      -'C:\Program Files\Microsoft\Edge\Application\msedge.exe'

  condition:selection and not 1 of filter_main_* and not 1 of filter_optional_*
Falsepositives:
  -Other third party applications not listed.
Level: medium