currently serving 24560 YARA rules and 4714 Sigma rules
API Key
New Rules per Day
Newest YARA Rules
This table shows the newest additions to the YARA rule set
Rule
Description
Date
Ref
SUSP_VBS_Hide_Zip_Archive_Extraction_Sep26
Detects suspicious VBS scripts that hide ZIP archive extraction, commonly used by malware to conceal payload delivery
02.09.2026
HKTL_HackBrowserData_Sep26
Detects HackBrowserData, a tool used to extract credentials from browsers
01.09.2026
MAL_LNX_SSHHijack_Sep26
Detects Linux binaries that attempt to hijack SSH sessions and steal credentials
01.09.2026
MAL_LNX_CS_Beacon_Sep26
Detects Cobalt Strike beacon for Linux. Cobalt Strike is a commercial C2 framework used by redteams and abused by threat actors. Its features include covert data exfiltration and persistent remote access among others.
01.09.2026
HKTL_PrettyPrague_Sep26
Detects PrettyPrague hacktool used for LPE (Local-Privilege-Escalation) and credential dumping. The tool exploits the sandbox component of Avast to gain system permissions and dump LSA credentials.
01.09.2026
HKTL_NightmareEclipse_Indicators_Sep26
Detects specific code used in hacktools written by NightmareEclipse (MSNightmare). Tooling includes Windows Defender exploits and Local-Privilege-Escalation.
01.09.2026
HKTL_KeyTheft_Aug26
Detects KeyTheft, a hacktool to dump the SAM via RemoteRegistry handle
31.08.2026
SUSP_PNG_Additional_Data_Aug26
Detects 1x1 pixel PNG files which contain additional data e.g. the output of the KeyTheft hacktool
31.08.2026
APT_Virtualizor_Compromise_ForensicArtifacts_Aug26
Detects forensic artifacts found in a campaign against compromised hosting providers using Virtualizor software
31.08.2026
APT_Virtualizor_Compromise_Payload_Aug26
Detects java based payload used in a campaign against compromised hosting providers using Virtualizor software
31.08.2026
SUSP_PY_Object_Graph_Traversal_Aug26
Detects Python code traversing the object graph to locate Python functions which may be detected by security products or hidden by sandbox engines
31.08.2026
SUSP_PY_Import_Encoding_Aug26
Detects suspicious encodings of Python's import keyword
31.08.2026
SUSP_JS_XOR_Dropper_Aug26
Detects suspicious XOR-decoding in JavaScript code seen being used to execute further malicious payload
31.08.2026
SUSP_JS_XOR_Dropper_Aug26_2
Detects suspicious XOR-decoding in JavaScript code seen being used to execute further malicious payload
31.08.2026
MAL_Loader_Aug26
Detects a loader being used to load AcrStealer and other malware
31.08.2026
MAL_Toxnet_Aug26
Detects Toxnet, a modern, decentralized Command and Control (C2) framework built on the Tox encrypted messaging protocol. ToxNetV2 operates on a peer-to-peer network where every node acts as both a potential relay and endpoint.
27.08.2026
SUSP_LNX_Persistance_Aug26
Detects Linux binaries referencing multiple persistence locations, a technique commonly used by malware to survive reboots and retain access to a compromised host. Further investigation is recommended
27.08.2026
MAL_EDR_Killer_Aug26_2
Detects an EDR Killer that abuses vulnerable driver to terminate security and EDR processes
26.08.2026
MAL_OxideHarvest_Stealer_Aug26
Detects OxideHarvest, an Info stealer that exfiltrates sensitive information from infected systems, including credentials and personal data, seen being used by GentleMen ransomware operators
25.08.2026
HKTL_AD_Assessment_Aug26
Detects AD-Assessment-PowerShell-Script, a standalone PowerShell scripts that generate interactive, self-contained HTML reports for Active Directory health and security
24.08.2026
MAL_SleepWalker_Aug26
Detects the SLEEPWALKER passive Windows backdoor, which executes encrypted bytecode tasks received via covert network triggers.
24.08.2026
SUSP_HKTL_LPE_Indicators_Aug26
Detects suspicious strings often found in LPE (local privilege escalation exploits) and post-exploitation tools for the Windows platform
24.08.2026
SUSP_Beacon_Indicator_Aug26
Detects suspicious indicators often found in implants and C2 beacons
24.08.2026
SUSP_Implant_Bypass_Indicators_Aug26
Detects indicators of bypass functions found in malicious implants
24.08.2026
SUSP_Go_LibP2P_Library_Aug26
Detects Go binaries using the libp2p library - a peer-to-peer networking library seen being used in implants and C2 frameworks
24.08.2026
SUSP_HostsFile_AV_Vendor_Blocklist_Aug26
Detects hosts files or binary that redirect antivirus/security vendor domains to localhost/null, a technique used by malware to block updates from security products
24.08.2026
SUSP_PE_PARSING_Aug26
Detects PE parsing, which is often used in shellcode and malware to locate modules via the PEB
24.08.2026
Successful YARA Rules in Set
This table shows statistics of the best rules with lowest AV detection rates (rules created in the last 12 months, matches of the last 14 days)
Rule
Average AV Detection Rate
Sample Count
Info
VT
Latest YARA Matches with Low AV Detection Rate
This table lists the last matches with low AV detection rates (between 0 and 15 AV engines matched)
Rule
AVs
Hash
VT
SUSP_ENV_Folder_Root_File_Jan23_1
4
b3917d46f4ba2873eac1b492b943aa420282b35f515291421206455d6073afa1
SUSP_Base64_Encoded_Hex_Encoded_Code
7
58a9aab2baf4cf11fd67fec89e3d4463b7dfa5e2a6facf31ba739389143dad40
SUSP_Go_Bypass_Indicators_Jan23_1
4
c244b834876a69636da04c1a7f60025f469b2aaee8ddb286b0687f677460d6d5
PUA_ConnectWise_ScreenConnect_Mar23
13
708209a2d4be22f226da5821aaf16cf32b01af124693be6ee6e484e17d87cada
SUSP_Base64_Encoded_Hex_Encoded_Code
7
94760e1796e3a4ee6e5edd84739353235c6dd6e7c4e533aa325a2564d0ccb865
MAL_Driver_Basil_Windivertsys_Windivertdriver_8DA0
2
fd7850d1d26a88b43dc60b5cd15263562514e6492ba78a1ae1ca240f615bcacb
MAL_Driver_Basil_Windivertsys_Windivertdriver_2F43
2
fd7850d1d26a88b43dc60b5cd15263562514e6492ba78a1ae1ca240f615bcacb
SUSP_Base64_Encoded_Hex_Encoded_Code
7
719eaee513fd17de97d97ad66411a1f8f54b5a064a5de6791f3ec15a0f81e4db
SUSP_PS1_IEX_From_Download_Dec22_1
11
55a2bc9895415fa957b39734493d60e7232cba8622f292f64a67c649e88c21a1
HKTL_PS1_Villain_C2_Implant_Apr23_1
11
55a2bc9895415fa957b39734493d60e7232cba8622f292f64a67c649e88c21a1
APT_PlugX_SFX_Chinese_Chars_Jan14
12
86fa63b4ab0f4c6684e045e9df793867c5e02e2e28ec066099af2139d92d4e60
PUA_ConnectWise_ScreenConnect_Mar23
10
d5171d8645bcaf12893e9825a972f269735b2ed931aca9cbbe256e69482891f7
SUSP_Base64_Encoded_Hex_Encoded_Code
7
1cd0edeb4a18ba01192c529c436377f3c05393229b2b00aab1ce3490f0c8b116
SUSP_Base64_Encoded_Hex_Encoded_Code
7
58a1d5527ff36e67a6062630d10c974139bfb06e03824b753da5cb429ad329b2
PUA_ConnectWise_ScreenConnect_Mar23
11
972f0e2e509b453652f1ab135e54e0f453dae180dcaed4dd84cb6895acaec7ba
YARA Rules Per Category
This list shows the number of YARA rules in the subscribable categories (categories overlap as a rule can be in 'n' categories)
Tag
Count
Malware
7865
Threat Hunting (not subscribable, only in THOR scanner)
6045
APT
5094
Hacktools
4912
Webshells
2405
Exploits
749
Newest Sigma Rules
This table shows the newest additions to the Sigma rule set
Rule
Description
Date
Ref
Info
Remote PDF Opened via Explorer with HTTP URL
Detects explorer.exe being invoked with an HTTP URL pointing to a remote PDF file.
Attackers use this technique to display a decoy document while a malicious payload
executes in the background, distracting the victim after LNK-based initial access.
explorer.exe is not normally launched from the command line with a remote HTTP path;
its appearance in such a context is a strong indicator of a scripted attack chain.
31.08.2026
EventLog Metadata Inspection Via Wevtutil
Detects the eventlog metadata inspection attempt via wevtutil.exe.
Threat actors use these to verify whether security logging is active and gauge
how much time they have before entries are overwritten, before performing intrusive actions.
27.08.2026
Email Protocol Access Via Curl
Detects curl.exe being used to access email servers over IMAP or SMTP protocols.
Curl natively supports IMAP/IMAPS and SMTP/SMTPS, allowing attackers to interact with
mailboxes directly from the command line - reading inbox contents, selecting folders,
or sending messages - without deploying a dedicated mail client. This technique is used
for C2 communication via corporate mail infrastructure and for data exfiltration, blending
with legitimate email traffic.
27.08.2026
Renamed Node.js Binary Execution
Detects the execution of a renamed Node.js JavaScript runtime, normally named "node.exe".
Node.exe is the executable file for the Node.js JavaScript runtime and is typically used
to execute JavaScript code outside a web browser environment. Threat actors may
rename the Node.js executable to a random name to run malicious scripts stealthily.
26.08.2026
Senstitive File Access via Cmd Utility
Detects the usage of windows inbuilt cmd.exe utility to access sensitive files such as configuration files,
certificate files, and password files. It might indicate an adversary attempting to access sensitive files
for credential access or collection purposes via reverse shell or cli interaction.
26.08.2026
SSH Known Hosts File Deleted
Detects deletion of SSH known_hosts files via file deletion events.
Complements the proc_creation variant by catching cases where the shell handles
the operation directly (e.g. bare redirects, unlink syscalls) without spawning
a traceable child process.
Attackers remove known_hosts to erase lateral movement destinations and suppress
SSH host key mismatch warnings.
19.08.2026
Linux Log File Content Cleared or Deleted via CLI Utilities
Detects unusual CLI-based methods to clear or delete Linux log file contents, including
truncating to zero size, overwriting with /dev/null, and other methods. These techniques
are commonly used by attackers and ransomware to destroy forensic evidence before or after
malicious activity.
19.08.2026
Logging Daemon Force Killed via CommandLine
Detects use of kill, killall, pkill, or other command line methods to forcefully terminate
common Linux logging and auditing services. Threat actors or malware may use this technique
to silence audit trails before encryption or exfiltration.
19.08.2026
Logging Service Stopped via Service Command
Detects use of the legacy service command to stop common Linux logging and auditing services. The service
command wraps SysV init scripts and remains functional on systemd-based distributions via compatibility shims.
Attackers use this to stop logging with a command that blends into older administration patterns.
19.08.2026
SSH Known Hosts File Removed or Cleared
Detects removal or clearing of SSH known_hosts files via common CLI utilities.
Attackers delete known_hosts to erase evidence of lateral movement destinations and to
suppress SSH host key mismatch warnings when reconnecting to a host whose key has been changed.
19.08.2026
Logging Service Stopped or Disabled via Systemctl
Detects use of systemctl to stop, kill, mask, or disable common Linux logging and auditing services (rsyslog, syslog-ng, auditd, systemd-journald).
Attackers and ransomware use this to silence audit trails before encryption or exfiltration.
Masking a service additionally prevents it from being restarted by other processes.
19.08.2026
PowerShell AppLocker Policy Discovery Via Get-AppLockerPolicy
Detects AppLocker policy enumeration attempts via PowerShell using the Get-AppLockerPolicy cmdlet and an policy scope of either Effective, LDAP, or Local.
19.08.2026
New User Account Creation Attempt Via ADSI
Detects an attempt to create a new user account via ADSI (Active Directory Service Interfaces)
using either the WinNT or LDAP provider. This is an uncommon method to create user accounts
and may indicate an attempt to evade detection by avoiding more commonly monitored commands
such as "net user", "New-LocalUser" or "New-ADUser".
13.08.2026
New User Account Creation Attempt Via ADSI in CommandLine
Detects PowerShell command line arguments containing ADSI (Active Directory Service Interfaces) patterns
trying to create a new user account via the WinNT or LDAP provider. This is an uncommon method to create
user accounts and may indicate an attempt to evade detection by avoiding more commonly monitored commands
such as "net user", "New-LocalUser" or "New-ADUser".
13.08.2026
PowerShell Live Kernel Dump
Detects PowerShell scripts or commands that create live kernel dumps.
While live kernel dumps are a legitimate diagnostic mechanism, they are increasingly
abused by threat actors to read sensitive process memory such as LSASS without opening
a direct process handle, bypassing traditional process-access based detections.
10.08.2026
Live Kernel Dump via CommandLine
Detects live kernel dumps initiated via the command line.
While kernel dumps are not inherently malicious, these dumps can be accessed
to read sensitive process memory such as LSASS without opening a direct process
handle, bypassing traditional process-access based detections.
10.08.2026
Potential Crontab Persistence via CLI
Detects command lines attempting to install a crontab persistence via cli by echoing a cron schedule and piping it to 'crontab -' via stdin.
Attackers may use this technique to establish persistence on a compromised system by scheduling malicious tasks to run at regular intervals.
07.08.2026
Container Overlay Filesystem Enumeration via Mount - Linux
Detects processes enumerating overlay filesystems by piping mount output through grep for "overlay".
This technique is used by attackers to detect if they are running inside a container (e.g., Docker, Podman),
which is a common precursor to container escape attempts or environment-aware malware behaviour.
07.08.2026
Sensitive File Discovery via Find Command
Detects aggressive filesystem searches for credential, certificate, and wallet files using the 'find' command.
This behavior may indicate an adversary attempting to locate sensitive files such as environment variable files, private keys, certificates, or wallet files that could be used for credential access or further compromise.
07.08.2026
Suspicious Grep of Sensitive Contents for Credential Access
Detects the use of grep to search for sensitive credentials and cryptocurrency wallet mnemonics.
This behaviour may indicate an adversary trying to to locate sensitive credentials contained in environment variable files, private keys, certificates, wallet files, or other files that may contain secrets which could be used for credential access or further compromise.
07.08.2026
PostgreSQL Connection String Enumeration via Grep
Detects the use of grep to search for PostgreSQL connection strings and database URLs, which may indicate credential harvesting from application directories as a precursor to lateral movement or data exfiltration.
Attackers may use this technique to find hardcoded database credentials in source code, configuration files, or environment variable definitions.
07.08.2026
Node.Js Inline Script Network Connection - Linux
Detects inline Node.js scripts that establish network connections, which may indicate malicious activity such as data exfiltration or command-and-control communication.
Attackers may use inline Node.js scripts to quickly execute code that interacts with the network without leaving a persistent file on disk.
07.08.2026
Suspicious Node.js Child Process with IP Address - Linux
Detects a Node.js process spawning a shell or network utility with a command line containing an IPv4 address.
This pattern is commonly used by malicious npm postinstall scripts to download second-stage payloads or establish reverse shells, as observed in various malicious Strapi npm campaign.
07.08.2026
Suspicious Node.js Child Process with IPv4 Address
Detects a Node.js child process command line containing an IPv4 address.
This might indicate a malicious npm postinstall script downloading second-stage payloads or establishing reverse shells, as observed in various malicious npm campaigns or supply chain attacks.
07.08.2026
Node.Js Inline Script Network Connection
Detects inline Node.js scripts that establish network connections, which may indicate malicious activity such as data exfiltration or command-and-control communication.
Attackers may use inline Node.js scripts to quickly execute code that interacts with the network without leaving a persistent file on disk.
07.08.2026
ADCS - Certighost Ghost Machine Account Creation
Detects the creation of a machine account whose name starts with 'GHOST', which is the
naming convention used by the CVE-2026-54121 (Certighost) exploit tooling.
The public proof-of-concept for Certighost creates a temporary machine account with a
name of the form GHOST<random>$ before enrolling for a DC certificate via the cdc chase
path. The attacker-controlled machine account is used as the requester identity in the
certificate request; the cdc attribute then redirects the CA to a rogue host that returns
a forged Domain Controller identity. The resulting certificate carries the DC's SID and
DNS name, enabling full PKINIT authentication as the targeted DC followed by DCSync.
A machine account creation event (4741) where TargetUserName starts with 'GHOST' and
ends with '$' is a high-fidelity indicator of this attack tool's execution. Legitimate
environments very rarely provision machine accounts with this prefix.
30.07.2026
ADCS - Certighost CDC Chase Certificate Request (CVE-2026-54121)
Detects Active Directory Certificate Services (ADCS) certificate requests that include the
'cdc' (Client DC) request attribute pointing to a domain or IP that is not a known Domain Controller.
'cdc' is an optional MS-WCCE enrollment attribute designed for cross-domain/cross-forest
scenarios where a client in a child domain tells the CA which DC to contact for identity
lookups when the CA cannot reach that domain directly. Legitimate values are DC hostnames
or IPs that resolve to a real Domain Controller computer object in AD with the
SERVER_TRUST_ACCOUNT (0x2000) userAccountControl bit set.
In an attack, the attacker sets cdc to a domain or IP they control so the CA connects to their
rogue SMB and LDAP services instead of a real DC. The rogue server returns a forged DC
identity which the pre-patch CA accepts without validation. A malicious event looks like:
Requester: DOMAIN\GHOST<random>$
Attributes: cdc:<attacker_ip>
rmd:<target_dc_fqdn>
SubjectAlternativeName: DNS Name=<target_dc_fqdn>
CVE-2026-54121 (Certighost) is the known exploit for this path. The July 2026 patch added
_ValidateChaseTargetIsDC which rejects cdc values that do not resolve to a legitimate
DC object in Active Directory before following the chase.
27.07.2026
ADCS - Certighost Certificate Issued via CDC Chase (CVE-2026-54121)
Detects successful issuance of an ADCS certificate where the request attributes include
'cdc' (Client DC) or 'rmd' (Remote Domain) pointing to a non-DC domain or IP, confirming the
CA's chase fallback path was taken against an attacker-controlled target.
'cdc' directs the CA to an address for identity lookup; 'rmd' specifies the principal to
look up there. In an attack (CVE-2026-54121, Certighost), cdc points to a rogue host that
returns a forged DC identity. A successfully issued certificate at this stage means the
attacker has obtained a cert carrying a Domain Controller's SID and DNS identity, enabling
PKINIT authentication as that DC followed by DCSync replication.
27.07.2026
Registry Hive File Staged Outside Standard User Profile Path
Detects the creation of a registry hive file (UsrClass.dat or NTUSER.DAT) outside of the standard user profile path.
These files generally contain various user-specific registry settings and are typically located in the user's profile directory.
Staging these files outside of the standard path can be indicative of an attacker attempting to manipulate user registry settings
for persistence, privilege escalation, or dump user registry hives for credential harvesting.
23.07.2026
Suspicious Cross-User Process Spawn
Detects suspicious spawning of a process under a different user context than the parent process.
Processes such as notepad.exe, calculator etc. are generally spawned under the same user context and
also they are often targeted as sacrificial process or decoy process to check successful privilege escalation.
23.07.2026
YARA/SIGMA Rule Count
Rule Type
Community Feed
Nextron Private Feed
Yara
1298
23262
Sigma
3617
1097
Sigma Rules Per Category (Community)
Type
Count
windows / process_creation
1359
windows / registry_set
219
windows / file_event
211
windows / ps_script
167
windows / security
164
linux / process_creation
142
windows / image_load
115
webserver
86
windows / system
74
macos / process_creation
69
aws / cloudtrail
57
proxy
55
linux / auditd
54
windows / network_connection
53
azure / auditlogs
44
windows / registry_event
40
azure / activitylogs
35
windows / ps_module
33
windows / application
32
windows / dns_query
28
windows / process_access
25
opencanary / application
24
okta / okta
22
azure / riskdetection
19
windows / pipe_created
19
azure / signinlogs
18
rpc_firewall / application
17
windows / windefend
17
linux / file_event
16
gcp / gcp.audit
16
linux
16
github / audit
15
bitbucket / audit
14
windows / file_delete
13
m365 / threat_management
13
cisco / aaa
13
windows / create_remote_thread
12
windows / driver_load
10
windows / registry_delete
10
kubernetes / application / audit
10
windows / codeintegrity-operational
10
dns
10
windows / appxdeployment-server
9
antivirus
9
windows / ps_classic_start
9
windows / create_stream_hash
9
windows / firewall-as
8
windows / msexchange-management
8
windows / file_access
7
azure / pim
7
windows / bits-client
7
zeek / smb_files
7
gcp / google_workspace.admin
7
fortigate / event
7
kubernetes / audit
6
windows / dns-client
6
jvm / application
5
zeek / dns
5
linux / network_connection
5
zeek / http
5
zeek / dce_rpc
4
m365 / audit
4
windows / taskscheduler
4
macos / file_event
4
windows / sysmon
4
windows / iis-configuration
4
windows / registry_add
3
linux / sshd
3
gcp / google_workspace.login
3
windows / wmi_event
3
windows / powershell-classic
3
windows / ntlm
3
windows / security-mitigations
2
linux / syslog
2
spring / application
2
windows / dns-server
2
apache
2
windows / wmi
2
onelogin / onelogin.events
2
windows / applocker
2
firewall
2
windows / openssh
1
fortios / sslvpnd
1
linux / clamav
1
juniper / bgp
1
windows / appxpackaging-om
1
cisco / syslog
1
linux / cron
1
huawei / bgp
1
windows / smbserver-connectivity
1
windows / file_change
1
windows / process_tampering
1
windows / smbclient-connectivity
1
windows / capi2
1
windows / shell-core
1
paloalto / file_event / globalprotect
1
windows / certificateservicesclient-lifecycle-system
1
windows / raw_access_thread
1
nodejs / application
1
paloalto / appliance / globalprotect
1
linux / vsftpd
1
zeek / x509
1
windows / microsoft-servicebus-client
1
python / application
1
windows / diagnosis-scripted
1
windows / smbclient-security
1
windows / file_executable_detected
1
windows / file_rename
1
windows / sysmon_status
1
zeek / rdp
1
windows / sysmon_error
1
m365 / exchange
1
zeek / kerberos
1
windows / driver-framework
1
windows / terminalservices-localsessionmanager
1
ruby_on_rails / application
1
m365 / threat_detection
1
windows
1
velocity / application
1
linux / sudo
1
sql / application
1
cisco / duo
1
cisco / ldp
1
nginx
1
windows / ldap
1
windows / dns-server-analytic
1
cisco / bgp
1
windows / ps_classic_provider_start
1
windows / printservice-admin
1
database
1
windows / lsa-server
1
windows / printservice-operational
1
django / application
1
linux / auth
1
linux / guacamole
1
windows / appmodel-runtime
1
Sigma Rules Per Category (Nextron Private Feed)
Type
Count
windows / process_creation
542
windows / registry_set
95
windows / ps_script
91
linux / process_creation
71
windows / file_event
52
windows / image_load
48
windows / security
29
windows / wmi
29
proxy
13
windows / system
13
windows / network_connection
9
windows / registry_event
8
windows / kernel-event-tracing
6
windows / ntfs
5
windows / ps_module
5
windows / dns_query
5
windows / sense
4
windows / pipe_created
4
webserver
4
windows / taskscheduler
4
windows / create_remote_thread
4
windows / registry_delete
4
macos / process_creation
3
dns
3
windows / ps_classic_script
3
windows / application-experience
3
windows / vhd
3
windows / hyper-v-worker
3
windows / driver_load
3
windows / kernel-shimengine
2
linux / Linux kernel module / THOR
2
windows / smbclient-security
2
windows / windefend
2
windows / process_access
2
windows / bits-client
2
linux / file_delete
2
windows / file_access
2
windows / codeintegrity-operational
2
windows / file_delete
2
linux / file_event
2
windows / file_rename
1
windows / environment variable / THOR
1
linux / Unix user / THOR
1
windows / posh_ps
1
windows / amsi
1
windows / audit-cve
1
windows / application
1
windows / firewall-as
1
windows / registry-setinformation
1
Tenable Nessus
Requirement: Privileged Scan
- YARA Scanning with Nessus works only when scanning with credentials (privileged scan)
YARA Scanning with Nessus
- You can only upload a single .yar file
- Filesystem scan has to be activated
- You have to define the target locations
- The Nessus plugin ID will be 91990
- Only files with the following extensions can be scanned: .application, .asp, .aspx, .bat, .chm, .class, .cmd, .com, .cp, .csh, .dl, .doc, .docx, .drv, .exe, .gadget, .hta, .inf, .ins, .inx, .isu, .jar, .job, .jpeg, .jpg, .js, .jse, .jse, .jsp, .lnk, .msc, .msi, .msp, .mst, .paf, .pdf, .php, .pif, .ppt, .pptx, .ps1, .ps1xm, .ps2, .ps2xm, .psc1, .psc2, .reg, .rgs, .scf, .scr, .sct, .shb, .shs, .swf, .sys, .u3p, .vb, .vbe, .vbs, .vbscript, .ws, .wsf, .xls, .xls
