Suspicious Startup Folder Persistence

 Original Source: [Sigma source]
Title: Suspicious Startup Folder Persistence
Status: test
Description:Detects the creation of potentially malicious script and executable files in Windows startup folders, which is a common persistence technique used by threat actors. These files (.ps1, .vbs, .js, .bat, etc.) are automatically executed when a user logs in, making the Startup folder an attractive target for attackers. This technique is frequently observed in malvertising campaigns and malware distribution where attackers attempt to maintain long-term access to compromised systems.
References:
  -https://github.com/last-byte/PersistenceSniper
  -https://www.microsoft.com/en-us/security/blog/2025/03/06/malvertising-campaign-leads-to-info-stealers-hosted-on-github/
  -https://github.com/redcanaryco/atomic-red-team/blob/5ede8f21e42ebe37e0a6eff757dba60bcfa85859/atomics/T1547.001/T1547.001.md
Author: Nasreddine Bencherchali (Nextron Systems), Swachchhanda Shrawan Poudel (Nextron Systems)
Date: 2022-08-10
modified:2025-10-12
Tags:
  • -'attack.privilege-escalation'
  • -'attack.execution'
  • -'attack.t1204.002'
  • -'attack.persistence'
  • -'attack.t1547.001'
Logsource:
  • product: windows
  • category: file_event
Detection:
  selection:
    TargetFilename|contains: '\Windows\Start Menu\Programs\Startup\'
    TargetFilename|endswith:
      -'.bat'
      -'.cmd'
      -'.dll'
      -'.hta'
      -'.jar'
      -'.js'
      -'.jse'
      -'.msi'
      -'.ps1'
      -'.psd1'
      -'.psm1'
      -'.scr'
      -'.url'
      -'.vba'
      -'.vbe'
      -'.vbs'
      -'.wsf'

  condition:selection
Falsepositives:
  -Rare legitimate usage of some of the extensions mentioned in the rule
Level: high