Detection rules › Sigma

Suspicious File Creation In Uncommon AppData Folder

Status
test
Severity
high
Log source
category file_event, product windows
Author
Nasreddine Bencherchali (Nextron Systems)
Source
github.com/SigmaHQ/sigma

Detects the creation of suspicious files and folders inside the user's AppData folder but not inside any of the common and well known directories (Local, Romaing, LocalLow). This method could be used as a method to bypass detection who exclude the AppData folder in fear of FPs

Known false positives

  • Unlikely

MITRE ATT&CK coverage

TacticTechniques
ExecutionNo specific technique
StealthNo specific technique

Telemetry coverage

ProviderRecord / event type
SysmonEvent ID 11: FileCreate

Rule body

title: Suspicious File Creation In Uncommon AppData Folder
id: d7b50671-d1ad-4871-aa60-5aa5b331fe04
status: test
description: Detects the creation of suspicious files and folders inside the user's AppData folder but not inside any of the common and well known directories (Local, Romaing, LocalLow). This method could be used as a method to bypass detection who exclude the AppData folder in fear of FPs
references:
    - Internal Research
author: Nasreddine Bencherchali (Nextron Systems)
date: 2022-08-05
modified: 2023-02-23
tags:
    - attack.execution
    - attack.stealth
logsource:
    product: windows
    category: file_event
detection:
    selection:
        TargetFilename|startswith: 'C:\Users\'
        TargetFilename|contains: '\AppData\'
        TargetFilename|endswith:
            # Add more as needed
            - '.bat'
            - '.cmd'
            - '.cpl'
            - '.dll'
            - '.exe'
            - '.hta'
            - '.iso'
            - '.lnk'
            - '.msi'
            - '.ps1'
            - '.psm1'
            - '.scr'
            - '.vbe'
            - '.vbs'
    filter_main:
        TargetFilename|startswith: 'C:\Users\'
        TargetFilename|contains:
            - '\AppData\Local\'
            - '\AppData\LocalLow\'
            - '\AppData\Roaming\'
    condition: selection and not filter_main
falsepositives:
    - Unlikely
level: high

Stages and Predicates

Stage 0: condition

selection and not filter_main

Stage 1: selection

selection:
    TargetFilename|startswith: 'C:\Users\'
    TargetFilename|contains: '\AppData\'
    TargetFilename|endswith:
        - '.bat'
        - '.cmd'
        - '.cpl'
        - '.dll'
        - '.exe'
        - '.hta'
        - '.iso'
        - '.lnk'
        - '.msi'
        - '.ps1'
        - '.psm1'
        - '.scr'
        - '.vbe'
        - '.vbs'

Stage 2: not filter_main

filter_main:
    TargetFilename|startswith: 'C:\Users\'
    TargetFilename|contains:
        - '\AppData\Local\'
        - '\AppData\LocalLow\'
        - '\AppData\Roaming\'

Exclusions

The rule actively suppresses these predicates.

Indicators

These rows show field, operator, and value matches.

FieldKindValuesSearch
TargetFilenameends_with
  • .bat corpus 17 (sigma 17)
  • .cmd corpus 8 (sigma 8)
  • .cpl corpus 2 (sigma 2)
  • .dll corpus 24 (sigma 24)
  • .exe corpus 21 (sigma 20, splunk 1)
  • .hta corpus 14 (sigma 14)
  • .iso corpus 5 (sigma 5)
  • .lnk corpus 6 (sigma 6)
  • .msi corpus 2 (sigma 2)
  • .ps1 corpus 17 (sigma 17)
  • .psm1 corpus 4 (sigma 4)
  • .scr corpus 8 (sigma 8)
  • .vbe corpus 16 (sigma 16)
  • .vbs corpus 18 (sigma 18)
field:"TargetFilename" kind:ends_with
TargetFilenamematch
  • \AppData\ corpus 4 (sigma 4)
field:"TargetFilename" kind:match value:"\AppData\"
TargetFilenamestarts_with
  • C:\Users\ corpus 13 (sigma 9, elastic 4)
field:"TargetFilename" kind:starts_with value:"C:\Users\"