This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Suspicious File Created by ArcSOC.exe
Original Source:
[Sigma source]
Title:
Suspicious File Created by ArcSOC.exe
Status:
experimental
Description:
Detects instances where the ArcGIS Server process ArcSOC.exe, which hosts REST services running on an ArcGIS server, creates a file with suspicious file type, indicating that it may be an executable, script file, or otherwise unusual.
References:
-https://reliaquest.com/blog/threat-spotlight-inside-flax-typhoons-arcgis-compromise/
-https://enterprise.arcgis.com/en/server/12.0/administer/windows/inside-an-arcgis-server-site.htm
Author:
Micah Babinski
Date:
2025-11-25
modified:
None
Tags:
-'attack.command-and-control'
-'attack.persistence'
-'attack.initial-access'
-'attack.execution'
-'attack.stealth'
-'attack.t1127'
-'attack.t1105'
-'attack.t1133'
Logsource:
category: file_event
product: windows
Detection:
selection:
Image|endswith
:
'\ArcSOC.exe'
TargetFilename|endswith
:
-'.ahk'
-'.aspx'
-'.au3'
-'.bat'
-'.cmd'
-'.dll'
-'.exe'
-'.hta'
-'.js'
-'.ps1'
-'.py'
-'.vbe'
-'.vbs'
-'.wsf'
condition
:
selection
Falsepositives:
-Unlikely
Level:
high