SCR File Write Event

 Original Source: [Sigma source]
Title: SCR File Write Event
Status: test
Description:Detects the creation of screensaver files (.scr) outside of system folders. Attackers may execute an application as an ".SCR" file using "rundll32.exe desk.cpl,InstallScreenSaver" for example.
References:
  -https://lolbas-project.github.io/lolbas/Libraries/Desk/
Author: Christopher Peacock @securepeacock, SCYTHE @scythe_io
Date: 2022-04-27
modified:2023-08-23
Tags:
  • -'attack.stealth'
  • -'attack.t1218.011'
Logsource:
  • category: file_event
  • product: windows
Detection:
  selection:
    TargetFilename|endswith: '.scr'
  filter:
    TargetFilename|contains:
      -':\$WINDOWS.~BT\NewOS\'
      -':\Windows\System32\'
      -':\Windows\SysWOW64\'
      -':\Windows\WinSxS\'
      -':\WUDownloadCache\'

  condition:selection and not filter
Falsepositives:
  -The installation of new screen savers by third party software
Level: medium