Name:MCP Filesystem Server Suspicious Extension Write id:fc2a024a-18c1-4d31-9480-7f04cf3ff293 version:2 date:None author:Rod Soto status:production type:Hunting Description:This detection identifies attempts to create executable or script files through MCP filesystem server connections. Threat actors leveraging LLM-based tools may attempt to write malicious executables, scripts, or batch files to disk for persistence or code execution. The detection prioritizes files written to system directories or startup locations which indicate higher likelihood of malicious intent. Data_source:
how_to_implement:Install the MCP Technology Add-on from Splunkbase and ensure MCP filesystem server logging is enabled with proper field extraction for params.path and params.content. Schedule the search to run every 5-15 minutes and tune alerting based on whether system or startup paths are targeted. known_false_positives:Legitimate developers using LLM assistants to generate scripts or automation tools, DevOps engineers creating deployment scripts, and system administrators generating batch files for maintenance tasks. References: -https://splunkbase.splunk.com/app/8377 -https://cymulate.com/blog/cve-2025-53109-53110-escaperoute-anthropic/ -https://www.splunk.com/en_us/blog/security/securing-ai-agents-model-context-protocol.html drilldown_searches:
: analytic_story:['Suspicious MCP Activities']