Back to results

Potential FileFix Command via Windows Explorer Address Bar

Identifies suspicious commands written to the Windows Explorer address bar history (TypedPaths). Adversaries socially engineer users to paste a command into the address bar of File Explorer or of a browser's file…

Description

Identifies suspicious commands written to the Windows Explorer address bar history (TypedPaths). Adversaries socially engineer users to paste a command into the address bar of File Explorer or of a browser's file upload dialog, a pattern known as FileFix; the writing process is therefore explorer.exe or the browser hosting the dialog. Stored commands that invoke PowerShell, cmd, mshta, msiexec, rundll32, or another living-off-the-land binary are unusual for this key, which normally contains file and folder paths. Investigate the process tree for a child of the writing process that matches the stored command.

Detection logic

Its licence does not clear it for publishing here

Sunturai publishes a detection's own text where the licence it arrived under has been reviewed and permits it, and Elastic License 2.0 has not. The query as its source wrote it, its canonical form and the hash that pins this revision are in the workspace record.

Detection requirements

Platform
ContainersESXiIaaSIdentity ProviderLinuxmacOSNetwork DevicesOffice SuiteSaaSWindows

The rule states no platform. This is derived from the 5 ATT&CK techniques it maps to.

Detections can measure how the public catalogue is used — which detections people look for, and which pages bring them here. It sets a cookie that recognises this browser for 180 days. It is never linked to an account and never follows you to other sites. Privacy notice