title: Execution in Non-Executable Folder status: experimental description: Detects a suspicious exection from an uncommon folder author: Florian Roth tags: - attack.defense_evasion - attack.t1036 logsource: category: process_creation product: windows detection: selection: Image: - '*\$Recycle.bin' - '*\Users\All Users\\*' - '*\Users\Default\\*' - '*\Users\Public\\*' - 'C:\Perflogs\\*' - '*\config\systemprofile\\*' - '*\Windows\Fonts\\*' - '*\Windows\IME\\*' - '*\Windows\addins\\*' condition: selection fields: - CommandLine - ParentCommandLine falsepositives: - Unknown level: high