Title:
Desktop.INI Created by Uncommon Process
Status:
test
Description:Detects unusual processes accessing desktop.ini, which can be leveraged to alter how Explorer displays a folder's content (i.e. renaming files) without changing them on disk.
References:
-https://isc.sans.edu/forums/diary/Desktopini+as+a+postexploitation+tool/25912/
Author: Maxime Thiebaut (@0xThiebaut), Tim Shelton (HAWK.IO)
Date: 2020-03-19
modified:2025-12-09
Tags:
- -'attack.privilege-escalation'
- -'attack.persistence'
- -'attack.t1547.009'
Logsource:
- product: windows
- category: file_event
Detection:
selection:
TargetFilename|endswith:
'\desktop.ini'
filter_main_generic:
Image|startswith:
-'C:\Windows\'
-'C:\Program Files\'
-'C:\Program Files (x86)\'
filter_main_upgrade:
TargetFilename|startswith:
'C:\$WINDOWS.~BT\NewOS\'
filter_optional_jetbrains:
Image|startswith:
'C:\Users\'
Image|endswith:
'\AppData\Local\JetBrains\Toolbox\bin\7z.exe'
TargetFilename|contains:
'\JetBrains\apps\'
filter_optional_onedrive:
Image|startswith:
'C:\Users\'
Image|contains:
'\AppData\Local\Microsoft\OneDrive\'
condition:
selection and not 1 of filter_main_* and not 1 of filter_optional_*
Falsepositives:
-Operations performed through Windows SCCM or equivalent
-Read only access list authority
Level:
medium