Copy From Or To Admin Share Or Sysvol Folder

 Original Source: [Sigma source]
Title: Copy From Or To Admin Share Or Sysvol Folder
Status: test
Description:Detects a copy command or a copy utility execution to or from an Admin share or remote
References:
  -https://twitter.com/SBousseaden/status/1211636381086339073
  -https://drive.google.com/file/d/1lKya3_mLnR3UQuCoiYruO3qgu052_iS_/view
  -https://www.elastic.co/guide/en/security/current/remote-file-copy-to-a-hidden-share.html
  -https://www.microsoft.com/en-us/security/blog/2022/10/18/defenders-beware-a-case-for-post-ransomware-investigations/
Author: Florian Roth (Nextron Systems), oscd.community, Teymur Kheirkhabarov @HeirhabarovT, Zach Stanford @svch0st, Nasreddine Bencherchali
Date: 2019-12-30
modified:2025-10-22
Tags:
  • -'attack.lateral-movement'
  • -'attack.collection'
  • -'attack.exfiltration'
  • -'attack.t1039'
  • -'attack.t1048'
  • -'attack.t1021.002'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_target:
    CommandLine|contains:
      -'\\\\*\\*$'
      -'\Sysvol\'

  selection_other_tools:
    - Image|endswith:
      - '\robocopy.exe'
      - '\xcopy.exe'
    - OriginalFileName:
      - 'robocopy.exe'
      - 'XCOPY.EXE'
  selection_cmd_img:
Image|endswith:'\cmd.exe' OriginalFileName:'Cmd.Exe'   selection_cmd_cli:
    CommandLine|contains: 'copy'
  selection_pwsh_img:
    - Image|contains:
      - '\powershell_ise.exe'
      - '\powershell.exe'
      - '\pwsh.exe'
    - OriginalFileName:
      - 'powershell_ise.exe'
      - 'PowerShell.EXE'
      - 'pwsh.dll'
  selection_pwsh_cli:
    CommandLine|contains:
      -'copy-item'
      -'copy '
      -'cpi '
      -' cp '
      -'move '
      -' move-item'
      -' mi '
      -' mv '

  condition:selection_target and (selection_other_tools or all of selection_cmd_* or all of selection_pwsh_*)
Falsepositives:
  -Administrative scripts
Level: medium