Suspicious Access to Sensitive File Extensions

 Original Source: [Sigma source]
Title: Suspicious Access to Sensitive File Extensions
Status: test
Description:Detects known sensitive file extensions accessed on a network share
References:
  -Internal Research
Author: Samir Bousseaden
Date: 2019-04-03
modified:2025-10-17
Tags:
  • -'attack.collection'
  • -'attack.t1039'
Logsource:
  • product: windows
  • service: security
Detection:
  selection:
    EventID: '5145'
    RelativeTargetName|endswith:
      -'.bak'
      -'.dmp'
      -'.edb'
      -'.kirbi'
      -'.msg'
      -'.nsf'
      -'.nst'
      -'.oab'
      -'.ost'
      -'.pst'
      -'.rdp'

  condition:selection
Falsepositives:
  -Help Desk operator doing backup or re-imaging end user machine or backup software
  -Users working with these data types or exchanging message files
Level: medium