Windows Shell/Scripting Application File Write to Suspicious Folder

 Original Source: [Sigma source]
Title: Windows Shell/Scripting Application File Write to Suspicious Folder
Status: test
Description:Detects Windows shells and scripting applications that write files to suspicious folders
References:
  -Internal Research
Author: Florian Roth (Nextron Systems)
Date: 2021-11-20
modified:2023-03-29
Tags:
  • -'attack.execution'
  • -'attack.t1059'
Logsource:
  • category: file_event
  • product: windows
Detection:
  selection_1:
    Image|endswith:
      -'\bash.exe'
      -'\cmd.exe'
      -'\cscript.exe'
      -'\msbuild.exe'
      -'\powershell.exe'
      -'\pwsh.exe'
      -'\sh.exe'
      -'\wscript.exe'

    TargetFilename|startswith:
      -'C:\PerfLogs\'
      -'C:\Users\Public\'

  selection_2:
    Image|endswith:
      -'\certutil.exe'
      -'\forfiles.exe'
      -'\mshta.exe'
      -'\schtasks.exe'
      -'\scriptrunner.exe'
      -'\wmic.exe'

    TargetFilename|contains:
      -'C:\PerfLogs\'
      -'C:\Users\Public\'
      -'C:\Windows\Temp\'

  condition:1 of selection_*
Falsepositives:
  -Unknown
Level: high