Clfs.SYS Loaded By Process Located In a Potential Suspicious Location
Description
Detects Clfs.sys being loaded by a process running from a potentially suspicious location. Clfs.sys is loaded as part of many CVEs exploits that targets Common Log File.
Query · sigma
selection_dll: ImageLoaded|endswith: \clfs.sys selection_folders_1: Image|contains: - :\Perflogs\ - :\Users\Public\ - \Temporary Internet - \Windows\Temp\ selection_folders_2: - Image|contains|all: - :\Users\ - \Favorites\ - Image|contains|all: - :\Users\ - \Favourites\ - Image|contains|all: - :\Users\ - \Contacts\ - Image|contains|all: - :\Users\ - \Pictures\ condition: selection_dll and 1 of selection_folders_*
Known false positives
- Unknown