
Rule Info
Name
Suspicious File Dropped in Perflogs Directory
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects the creation of suspicious files (like scripts and executables) in the Perflogs directory, which could indicate malicious activity.
The PerfLogs directory is a default Windows folder typically used for storing performance logs and data, making it an unusual location for executable files.
Adversaries may attempt to hide malicious files in this directory to evade detection, as it's rarely monitored and accessed by normal users.
This detection focuses on common file extensions that are often associated with malicious code execution.
Reference
Internal Research
Date
2025-03-24 00:00:00
Modified
None
Id
d5e8cbdf-235d-484b-9cd2-db1fd1a9540a
Tags
attack.execution attack.t1204.002
Type
Nextron Sigma feed only (private)