Scripted recursive copy sweeping multiple document types
Authors a single-event stand-in for AN0531's core signal — "search for and copy information fitting set criteria such as file type" — as a PowerShell Copy-Item invocation that is both recursive and names several unrelated document extensions in one command line, which is what a scripted bulk collection sweep looks like at the point it runs versus an ordinary one-off copy. MITRE's ProcessCountThreshold and ClipboardCheckRate knobs describe a rate over repeated events, which Sigma's lack of aggregation support (no `count() by`) makes impossible to express directly, so this substitutes "several file types requested together" for "many files copied over time" as the single-event proxy for automation. Three limits are structural, and none of them is a false positive. Sysmon EventID 1 records the process command line only, so this fires solely on a sweep typed inline (powershell.exe -Command "Copy-Item -Recurse ... -Include *.doc,*.pdf"); a launch of powershell.exe -File collect.ps1, an -EncodedCommand payload, a pipeline where -Recurse and -Include sit on Get-ChildItem and the trailing Copy-Item carries neither, or plain aliasing (cpi, gci) all put none of the matched tokens on the recorded command line, because the cmdlet text lives inside the script body this event never captures. Inline invocation is one style of scripted collection and not the dominant one for real automation, so treat a silent result as unmeasured rather than clean. Second, 'recurse' is matched as a bare substring, so -Recurse:$false — recursion explicitly turned off, no tree walked — still satisfies that gate. Third, robocopy and xcopy are left out of the selector rather than OR-ed in on a different CommandLine shape, keeping the rule to one condition all four backends render. This is deliberately not the shape already published elsewhere in the corpus: T1005 matches a find/ grep search for credential and SSH-key filenames, and this matches a PowerShell copy of general document types — different tool class, different target, no overlap. UNVERIFIED AS AUTHORED — derived from MITRE ATT&CK DET0186, not hand-written and not tested by its author. Any lab result is on this rule's own page.Full descriptionShow less
The detection
The 4 SIEM queries below are previews produced by Siemphony’s own translator, not pySigma, and none has been executed against a real backend — review before you deploy.
detection.yml
title: Scripted recursive copy sweeping multiple document typesid: aad6ea77-2853-4827-abf9-9c877c56e2abstatus: experimentaldescription: | Authors a single-event stand-in for AN0531's core signal — "search for and copy information fitting set criteria such as file type" — as a PowerShell Copy-Item invocation that is both recursive and names several unrelated document extensions in one command line, which is what a scripted bulk collection sweep looks like at the point it runs versus an ordinary one-off copy. MITRE's ProcessCountThreshold and ClipboardCheckRate knobs describe a rate over repeated events, which Sigma's lack of aggregation support (no `count() by`) makes impossible to express directly, so this substitutes "several file types requested together" for "many files copied over time" as the single-event proxy for automation. Three limits are structural, and none of them is a false positive. Sysmon EventID 1 records the process command line only, so this fires solely on a sweep typed inline (powershell.exe -Command "Copy-Item -Recurse ... -Include *.doc,*.pdf"); a launch of powershell.exe -File collect.ps1, an -EncodedCommand payload, a pipeline where -Recurse and -Include sit on Get-ChildItem and the trailing Copy-Item carries neither, or plain aliasing (cpi, gci) all put none of the matched tokens on the recorded command line, because the cmdlet text lives inside the script body this event never captures. Inline invocation is one style of scripted collection and not the dominant one for real automation, so treat a silent result as unmeasured rather than clean. Second, 'recurse' is matched as a bare substring, so -Recurse:$false — recursion explicitly turned off, no tree walked — still satisfies that gate. Third, robocopy and xcopy are left out of the selector rather than OR-ed in on a different CommandLine shape, keeping the rule to one condition all four backends render. This is deliberately not the shape already published elsewhere in the corpus: T1005 matches a find/ grep search for credential and SSH-key filenames, and this matches a PowerShell copy of general document types — different tool class, different target, no overlap. UNVERIFIED AS AUTHORED — derived from MITRE ATT&CK DET0186, not hand-written and not tested by its author. Any lab result is on this rule's own page.references: - https://attack.mitre.org/techniques/T1119 - https://attack.mitre.org/detectionstrategies/DET0186author: Siemphony pipeline (machine-derived from MITRE ATT&CK v19.2)date: 2026-08-16tags: - attack.collection - attack.t1119logsource: category: process_creation product: windowsdetection: selection_tool: Image|endswith: - '\powershell.exe' - '\pwsh.exe' selection_copy_verb: CommandLine|contains: 'copy-item' selection_recurse_flag: CommandLine|contains: 'recurse' selection_extension: CommandLine|contains: - '.doc' - '.xls' - '.ppt' - '.pdf' - '.csv' - '.txt' condition: selection_tool and selection_copy_verb and selection_recurse_flag and selection_extensionfalsepositives: - "User-profile migration and onboarding/offboarding scripts run by helpdesk tooling, which use Copy-Item -Recurse against a user's Documents folder filtered to common office extensions as their normal operating pattern — in an environment with active migration or provisioning waves this is the largest source of matches." - "Backup, e-discovery or legal-hold agents that periodically sweep user document folders and copy matching file types to a review or backup repository as part of routine, scheduled compliance operations." - "Software packaging and imaging scripts (SCCM/Intune build tasks) that stage a fixed set of document templates into a reference image using the same cmdlet and flag combination."level: mediumSentinel · KQL
Run this as a search.
DeviceProcessEvents| where ((((FolderPath endswith "\\powershell.exe" or FolderPath endswith "\\pwsh.exe") and ProcessCommandLine contains "copy-item") and ProcessCommandLine contains "recurse") and (ProcessCommandLine contains ".doc" or ProcessCommandLine contains ".xls" or ProcessCommandLine contains ".ppt" or ProcessCommandLine contains ".pdf" or ProcessCommandLine contains ".csv" or ProcessCommandLine contains ".txt"))
Splunk · SPL
Run this as a search.
index=* ((((Image="*\\powershell.exe" OR Image="*\\pwsh.exe") AND CommandLine="*copy-item*") AND CommandLine="*recurse*") AND (CommandLine="*.doc*" OR CommandLine="*.xls*" OR CommandLine="*.ppt*" OR CommandLine="*.pdf*" OR CommandLine="*.csv*" OR CommandLine="*.txt*"))Elastic · ES|QL
Run this as a search.
FROM logs-*| WHERE ((((TO_LOWER(process.executable) LIKE "*\\\\powershell.exe" OR TO_LOWER(process.executable) LIKE "*\\\\pwsh.exe") AND TO_LOWER(process.command_line) LIKE "*copy-item*") AND TO_LOWER(process.command_line) LIKE "*recurse*") AND (TO_LOWER(process.command_line) LIKE "*.doc*" OR TO_LOWER(process.command_line) LIKE "*.xls*" OR TO_LOWER(process.command_line) LIKE "*.ppt*" OR TO_LOWER(process.command_line) LIKE "*.pdf*" OR TO_LOWER(process.command_line) LIKE "*.csv*" OR TO_LOWER(process.command_line) LIKE "*.txt*"))
Wazuh · XML rule
Deploy to your manager — this is a rule, not a search.
<group name="sigma,windows,process_creation,"> <!-- Rule ids must be unique on your manager; 100000+ is the user range. --> <rule id="100000" level="7"> <!-- Set <if_sid> to the decoder/base rule for windows so this only evaluates relevant events. --> <field name="Image" type="pcre2">(?i)(\\powershell\.exe$|\\pwsh\.exe$)</field> <field name="CommandLine" type="pcre2">(?i)copy-item</field> <field name="CommandLine" type="pcre2">(?i)recurse</field> <field name="CommandLine" type="pcre2">(?i)(\.doc|\.xls|\.ppt|\.pdf|\.csv|\.txt)</field> <description>Scripted recursive copy sweeping multiple document types</description> <mitre> <id>T1119</id> </mitre> </rule></group>
Verdicts · reactions · comments
Community
Verdicts from engineers who actually deployed it, and the conversation around it.
Nobody has run this in a real environment and said what happened.
Verdicts from engineers who deployed it
0 castNo verdicts reported yet. The first one is worth more than the tenth — say what you ran it against.
Log in to report a verdict.
Log in to join the discussion.
No comments yet. Someone who deploys this will have something to say about it.