Detection rules › Sigma
Creation of WerFault.exe/Wer.dll in Unusual Folder
Detects the creation of a file named "WerFault.exe" or "wer.dll" in an uncommon folder, which could be a sign of WerFault DLL hijacking.
MITRE ATT&CK coverage
| Tactic | Techniques |
|---|---|
| Execution | |
| Stealth |
Telemetry coverage
| Provider | Record / event type |
|---|---|
| Sysmon | Event ID 11: FileCreate |
Rule body
title: Creation of WerFault.exe/Wer.dll in Unusual Folder
id: 28a452f3-786c-4fd8-b8f2-bddbe9d616d1
status: test
description: Detects the creation of a file named "WerFault.exe" or "wer.dll" in an uncommon folder, which could be a sign of WerFault DLL hijacking.
references:
- https://www.bleepingcomputer.com/news/security/hackers-are-now-hiding-malware-in-windows-event-logs/
author: frack113
date: 2022-05-09
modified: 2026-05-18
tags:
- attack.privilege-escalation
- attack.persistence
- attack.execution
- attack.stealth
- attack.t1574.001
logsource:
product: windows
category: file_event
detection:
selection:
TargetFilename|endswith:
- '\WerFault.exe'
- '\wer.dll'
filter_main_known_locations:
TargetFilename|startswith:
- 'C:\Windows\SoftwareDistribution\'
- 'C:\Windows\System32\'
- 'C:\Windows\SysWOW64\'
- 'C:\Windows\WinSxS\'
- 'C:\Windows\UUS\' # covers both C:\Windows\UUS\arm64\ and C:\Windows\UUS\packages\
filter_main_process:
Image|endswith: '\wuaucltcore.exe'
condition: selection and not 1 of filter_main_*
falsepositives:
- Unknown
level: medium
Stages and Predicates
Stage 0: condition
selection and not 1 of filter_main_*Stage 1: selection
selection:
TargetFilename|endswith:
- '\WerFault.exe'
- '\wer.dll'
Stage 2: not filter_main_*
filter_main_known_locations:
TargetFilename|startswith:
- 'C:\Windows\SoftwareDistribution\'
- 'C:\Windows\System32\'
- 'C:\Windows\SysWOW64\'
- 'C:\Windows\WinSxS\'
- 'C:\Windows\UUS\'
filter_main_process:
Image|endswith: '\wuaucltcore.exe'
Exclusions
The rule actively suppresses these predicates.
| Field | Kind | Excluded values | Search |
|---|---|---|---|
Image | ends_with | \wuaucltcore.exe | excludes:Image field:"Image" value:"\wuaucltcore.exe" |
TargetFilename | starts_with | C:\Windows\SoftwareDistribution\ | excludes:TargetFilename field:"TargetFilename" value:"C:\Windows\SoftwareDistribution\" |
TargetFilename | starts_with | C:\Windows\SysWOW64\ | excludes:TargetFilename field:"TargetFilename" value:"C:\Windows\SysWOW64\" |
TargetFilename | starts_with | C:\Windows\System32\ | excludes:TargetFilename field:"TargetFilename" value:"C:\Windows\System32\" |
TargetFilename | starts_with | C:\Windows\UUS\ | excludes:TargetFilename field:"TargetFilename" value:"C:\Windows\UUS\" |
TargetFilename | starts_with | C:\Windows\WinSxS\ | excludes:TargetFilename field:"TargetFilename" value:"C:\Windows\WinSxS\" |
Indicators
These rows show field, operator, and value matches.
| Field | Kind | Values | Search |
|---|---|---|---|
TargetFilename | ends_with |
| field:"TargetFilename" kind:ends_with |