{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/tags/file-event/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":[],"_cs_severities":["medium"],"_cs_tags":["stealth","defense-evasion","persistence","windows","file-event"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eThis threat brief focuses on the technique where adversaries create executable files that mimic the names of legitimate Windows system processes, but place them in directories outside of their expected system paths (e.g., System32, SysWOW64). This method is a common tactic for defense evasion and persistence, as it helps attackers blend malicious executables with benign system activity, making them harder to distinguish by security tools and human analysts. While the source does not detail a specific threat actor or campaign, this technique has been observed in various APT attacks, such as by the SideWinder APT, to conceal their malicious operations. The detection capability targets the creation of files like \u003ccode\u003eexplorer.exe\u003c/code\u003e, \u003ccode\u003esvchost.exe\u003c/code\u003e, \u003ccode\u003elsass.exe\u003c/code\u003e, or \u003ccode\u003epowershell.exe\u003c/code\u003e in locations where they should not legitimately reside, indicating a high likelihood of malicious intent.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful deployment of executables masquerading as system processes can lead to various detrimental outcomes for an organization. Adversaries can achieve stealthy persistence, execute malicious code with elevated privileges, or evade detection from security solutions that might be configured to trust standard system process names. The impact can range from data exfiltration and intellectual property theft to system compromise, ransomware deployment, or complete network control, depending on the attacker's ultimate objectives. The inherent challenge in distinguishing these malicious files from legitimate system components significantly increases the attacker's dwell time and ability to conduct further nefarious activities unnoticed.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDeploy the Sigma rule \u0026quot;Files With System Process Name In Unsuspected Locations\u0026quot; to your SIEM and tune for your environment to detect file creations matching system process names in unusual directories.\u003c/li\u003e\n\u003cli\u003eEnsure Sysmon \u003ccode\u003efile_event\u003c/code\u003e logging is enabled to provide the necessary telemetry for the provided Sigma rule.\u003c/li\u003e\n\u003cli\u003ePerform an initial baseline of your environment to identify legitimate third-party software or uncommon system configurations that might trigger false positives for the \u0026quot;Files With System Process Name In Unsuspected Locations\u0026quot; rule.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-28T08:22:37Z","date_published":"2026-07-28T08:22:37Z","id":"https://feed.craftedsignal.io/briefs/2026-07-system-file-locations/","summary":"This brief detects an attacker's attempt to evade detection and maintain persistence by creating executable files with names identical to legitimate Windows system processes in non-standard directories, a tactic associated with stealth and defense evasion.","title":"Suspicious System Process Names in Unusual File Locations","url":"https://feed.craftedsignal.io/briefs/2026-07-system-file-locations/"}],"language":"en","title":"CraftedSignal Threat Feed - File-Event","version":"https://jsonfeed.org/version/1.1"}