Title:Windows Network Access Suspicious desktop.ini Action Status:test Description:Detects unusual processes accessing desktop.ini remotely over network share, which can be leveraged to alter how Explorer displays a folder's content (i.e. renaming files) without changing them on disk. References: -https://isc.sans.edu/forums/diary/Desktopini+as+a+postexploitation+tool/25912/ Author: Tim Shelton (HAWK.IO) Date: 2021-12-06 modified:2022-01-16 Tags: