Skip to content
Threat Feed

Tag

File-Creation

8 briefs RSS
medium advisory

File Creation in World-Writable Directory by Unusual Process

This rule detects the creation of files in world-writable directories on Linux systems by an unusual process, which is a common defense evasion tactic for potential lateral movement or malicious payload staging.

Elastic Defend +2 defense-evasion file-creation linux
2r 1t
high advisory

Suspicious File Creation via Print Spooler Service

The Print Spooler service is being abused to create suspicious files, potentially leading to privilege escalation.

Windows printspooler privilege-escalation file-creation
2r 1t
medium advisory

Suspicious File Creation via OpenEDR ITSMService

OpenEDR's ITSMService process, used for remote management, is being abused to create suspicious files on compromised systems, potentially leading to unauthorized file uploads, data staging, or malicious file deployment.

OpenEDR itsmservice file-creation lateral-movement
3r 4t
medium advisory

Potential Lateral Tool Transfer via SMB Share

This rule identifies the creation or change of a Windows executable file over network shares (SMB), indicating adversaries may transfer tools or other files between systems in a compromised environment.

Windows lateral-movement smb file-creation
3r 2t
medium advisory

System Process Executables Created in Unusual Locations

The creation of executable files masquerading as legitimate Windows system processes in non-standard directories indicates potential malware installation or defense evasion tactics by threat actors.

Windows defense-evasion file-creation masquerading
3r 1t
high advisory

Executable or Script Creation in Temporary Paths

Adversaries may create executables or scripts in temporary directories to evade detection, maintain persistence, and execute unauthorized code on Windows systems.

defense-evasion persistence privilege-escalation execution temp-directory file-creation
2r 1t
high advisory

WScript or CScript Dropper

The WScript or CScript Dropper technique involves using cscript.exe or wscript.exe to write malicious script files (js, jse, vba, vbe, vbs, wsf, wsh) to suspicious locations on a Windows system for later execution.

Windows script-dropper file-creation
2r 2t
high advisory

Suspicious Executable or Script Creation in Uncommon Paths

Detection of executables or scripts being created in unusual directories on Windows systems, which can be indicative of malware installation or persistence attempts.

Windows file-creation persistence
3r 1t