title: Hiding files with attrib.exe status: experimental description: Detects usage of attrib.exe to hide files from users. author: Sami Ruohonen logsource: product: windows service: sysmon detection: selection: EventID: 1 Image: '*\attrib.exe' CommandLine: '* +h *' ini: CommandLine: '*\desktop.ini *' intel: ParentImage: '*\cmd.exe' CommandLine: '+R +H +S +A \*.cui' ParentCommandLine: 'C:\WINDOWS\system32\\*.bat' condition: selection and not (ini or intel) fields: - CommandLine - ParentCommandLine - User tags: - attack.defense_evasion - attack.persistence - attack.t1158 falsepositives: - igfxCUIService.exe hiding *.cui files via .bat script (attrib.exe a child of cmd.exe and igfxCUIService.exe is the parent of the cmd.exe) - msiexec.exe hiding desktop.ini level: low