Rule Library
Sigma Rules
2 rules found
3,731Total
3,132Detection
457Emerging
139Hunting
Detectionmediumtest
Suspicious Appended Extension
Detects file renames where the target filename uses an uncommon double extension. Could indicate potential ransomware activity renaming files and adding a custom extension to the encrypted files, such as ".jpg.crypted", ".docx.locky", etc.
WindowsFile Rename
François HubautSat Jul 16windows
Threat Huntmediumtest
Non-DLL Extension File Renamed With DLL Extension
Detects rename operations of files with non-DLL extensions to files with a DLL extension. This is often performed by malware in order to avoid initial detections based on extensions.
WindowsFile Rename
François HubautSat Feb 19windows