Windows Network Access Suspicious desktop.ini Action

 Original Source: [Sigma source]
Title: Windows Network Access Suspicious desktop.ini Action
Status: test
Description:Detects unusual processes accessing desktop.ini remotely over network share, which can be leveraged to alter how Explorer displays a folder's content (i.e. renaming files) without changing them on disk.
References:
  -https://isc.sans.edu/forums/diary/Desktopini+as+a+postexploitation+tool/25912/
Author: Tim Shelton (HAWK.IO)
Date: 2021-12-06
modified:2022-01-16
Tags:
  • -'attack.privilege-escalation'
  • -'attack.persistence'
  • -'attack.t1547.009'
Logsource:
  • product: windows
  • service: security
Detection:
  selection:
    EventID: '5145'
    ObjectType: 'File'
    RelativeTargetName|endswith: '\desktop.ini'
    AccessList|contains:
      -'WriteData'
      -'DELETE'
      -'WriteDAC'
      -'AppendData'
      -'AddSubdirectory'

  condition:selection
Falsepositives:
  -Read only access list authority
Level: medium