Uncommon FileSystem Load Attempt By Format.com
Description
Detects the execution of format.com with an uncommon filesystem selection that could indicate a defense evasion activity in which "format.com" is used to load malicious DLL files or other programs.
Query · sigma
selection: Image|endswith: \format.com CommandLine|contains: '/fs:' filter_main_known_fs: CommandLine|contains: - /fs:exFAT - /fs:FAT - /fs:NTFS - /fs:ReFS - /fs:UDF condition: selection and not 1 of filter_main_*
Known false positives
- Unknown