Startup Folder File Write

 Original Source: [Sigma source]
Title: Startup Folder File Write
Status: test
Description:A General detection for files being created in the Windows startup directory. This could be an indicator of persistence.
References:
  -https://github.com/OTRF/detection-hackathon-apt29/issues/12
  -https://github.com/OTRF/ThreatHunter-Playbook/blob/2d4257f630f4c9770f78d0c1df059f891ffc3fec/docs/evals/apt29/detections/5.B.1_611FCA99-97D0-4873-9E51-1C1BA2DBB40D.md
Author: Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research)
Date: 2020-05-02
modified:2025-12-03
Tags:
  • -'attack.privilege-escalation'
  • -'attack.persistence'
  • -'attack.t1547.001'
Logsource:
  • product: windows
  • category: file_event
Detection:
  selection:
    TargetFilename|contains: '\Microsoft\Windows\Start Menu\Programs\StartUp'
  filter_main_update:
    - Image:
      - 'C:\Windows\System32\wuauclt.exe'
      - 'C:\Windows\uus\ARM64\wuaucltcore.exe'
    - TargetFilename|startswith:
      - 'C:\$WINDOWS.~BT\NewOS\'
      - 'C:\$WinREAgent\Scratch\Mount\'
  filter_optional_onenote:
    Image|endswith: '\ONENOTE.EXE'
    TargetFilename|endswith: '\Send to OneNote.lnk'
  condition:selection and not 1 of filter_main_* and not 1 of filter_optional_*
Falsepositives:
  -FP could be caused by legitimate application writing shortcuts for example. This folder should always be inspected to make sure that all the files in there are legitimate
Level: medium