Windows Network Access Suspicious desktop.ini Action
Description
Detects unusual processes accessing desktop.ini remotely over network share, which can be leveraged to alter how Explorer displays a folder's content (i.e. renaming files) without changing them on disk.
Query · sigma
selection: EventID: 5145 ObjectType: File RelativeTargetName|endswith: \desktop.ini AccessList|contains: - WriteData - DELETE - WriteDAC - AppendData - AddSubdirectory condition: selection
Known false positives
- Read only access list authority