Antivirus - Relevant File Paths Alerts Signature

 Original Source: [Sigma source]
Title: Antivirus - Relevant File Paths Alerts Signature
Status: test
Description:Detects an Antivirus alert in a highly relevant file path or with a relevant file name. This event must not be ignored just because the AV has blocked the malware but investigate, how it came there in the first place.
References:
  -https://www.nextron-systems.com/?s=antivirus
Author: Florian Roth (Nextron Systems), Arnim Rupp
Date: 2018-09-09
modified:2026-06-29
Tags:
  • -'attack.resource-development'
  • -'attack.t1588'
Logsource:
  • category: antivirus
Detection:
  selection_path:
    Filename|contains:
      -':\PerfLogs\'
      -':\Temp\'
      -':\Users\Default\'
      -':\Users\Public\'
      -':\Windows\'
      -'/www/'
      -'\inetpub\'
      -'\tsclient\'
      -'apache'
      -'nginx'
      -'tomcat'
      -'weblogic'

  selection_ext:
    Filename|endswith:
      -'.asax'
      -'.ashx'
      -'.asmx'
      -'.asp'
      -'.aspx'
      -'.bat'
      -'.cfm'
      -'.cgi'
      -'.chm'
      -'.cmd'
      -'.dat'
      -'.ear'
      -'.gif'
      -'.hta'
      -'.jpeg'
      -'.jpg'
      -'.jsp'
      -'.jspx'
      -'.lnk'
      -'.msc'
      -'.php'
      -'.pl'
      -'.png'
      -'.ps1'
      -'.psm1'
      -'.py'
      -'.pyc'
      -'.rb'
      -'.scf'
      -'.sct'
      -'.sh'
      -'.svg'
      -'.txt'
      -'.vbe'
      -'.vbs'
      -'.war'
      -'.wll'
      -'.wsf'
      -'.wsh'
      -'.xll'
      -'.xml'

  condition:1 of selection_*
Falsepositives:
  -Unlikely
Level: high