Skip to content

Siemphony is in beta and still being built. How a rule earns its badge.

Siemphony’s repertoire

Executable written into a protected program directory

Matches the binary-modification half of AN0949: a file create or overwrite of an .exe, .dll, .sys or .ocx underneath the system directories or the Program Files trees, by a writer that is not part of the Windows servicing or antimalware update path. The rule is written in the Sysmon-shaped `file_event` vocabulary (`TargetFilename`, `Image`); the brief also lists Security 4688 for the execution half of the same analytic, which is a different feed with a different field set and is not authored here. Path terms use `contains` rather than `startswith` so the rule is not pinned to the C: drive. Three limits worth stating: Sysmon EventID 11 fires on create and overwrite, so patching an existing binary in place — IAT hooking or an entry-point patch — may produce no event at all; the excluded-writer list includes msiexec.exe because it is the loudest legitimate writer, which also removes MSI-delivered tampering from view; and the correlation MITRE describes, a write followed by execution of an anomalously signed image inside the `TimeWindow` knob, needs both a join and a signature attribute that Sigma has neither of. Sysmon file-create logging is scoped entirely by your Sysmon configuration, and the common public configs filter most writes under System32 — confirm .exe and .dll creation in these paths is included before reading silence as clean. UNVERIFIED — derived from MITRE ATT&CK DET0336 and never executed against logs.Full description

The detection

The 4 SIEM queries below are previews produced by Siemphony’s own translator, not pySigma, and none has been executed against a real backend — review before you deploy.

detection.yml

title: Executable written into a protected program directoryid: 393c050a-eab2-4223-909d-257aea69ea24status: experimentaldescription: |  Matches the binary-modification half of AN0949: a file create or overwrite of  an .exe, .dll, .sys or .ocx underneath the system directories or the Program  Files trees, by a writer that is not part of the Windows servicing or  antimalware update path. The rule is written in the Sysmon-shaped `file_event`  vocabulary (`TargetFilename`, `Image`); the brief also lists Security 4688 for  the execution half of the same analytic, which is a different feed with a  different field set and is not authored here. Path terms use `contains` rather  than `startswith` so the rule is not pinned to the C: drive. Three limits  worth stating: Sysmon EventID 11 fires on create and overwrite, so patching an  existing binary in place — IAT hooking or an entry-point patch — may produce  no event at all; the excluded-writer list includes msiexec.exe because it is  the loudest legitimate writer, which also removes MSI-delivered tampering from  view; and the correlation MITRE describes, a write followed by execution of an  anomalously signed image inside the `TimeWindow` knob, needs both a join and a  signature attribute that Sigma has neither of. Sysmon file-create logging is  scoped entirely by your Sysmon configuration, and the common public configs  filter most writes under System32 — confirm .exe and .dll creation in these  paths is included before reading silence as clean.  UNVERIFIED — derived from MITRE ATT&CK DET0336 and never executed against logs.references:  - https://attack.mitre.org/techniques/T1554  - https://attack.mitre.org/detectionstrategies/DET0336author: Siemphony pipeline (machine-derived from MITRE ATT&CK v19.2)date: 2026-08-16tags:  - attack.persistence  - attack.t1554logsource:  category: file_event  product: windowsdetection:  selection:    TargetFilename|contains:      - '\Windows\System32\'      - '\Windows\SysWOW64\'      - '\Program Files\'      - '\Program Files (x86)\'    TargetFilename|endswith:      - '.exe'      - '.dll'      - '.sys'      - '.ocx'  filter_servicing_writers:    Image|endswith:      - '\TiWorker.exe'      - '\TrustedInstaller.exe'      - '\poqexec.exe'      - '\msiexec.exe'      - '\wusa.exe'      - '\MsMpEng.exe'      - '\MpSigStub.exe'  condition: selection and not filter_servicing_writersfalsepositives:  - "Third-party application updaters replacing their own binaries in place — browser, conferencing, PDF reader and language-runtime updaters all write fresh .exe and .dll into their Program Files subdirectory on every release. On a fleet this is a continuous stream and by a wide margin the largest source of matches, which is why MITRE's MonitoredPaths knob is the first thing to tighten: dropping the two Program Files prefixes and keeping only System32 and SysWOW64 raises precision sharply."  - "Windows servicing performed by writers other than the excluded ones, in particular svchost.exe-hosted service components and DISM or setup running during a feature-on-demand, language-pack or in-place upgrade, all of which legitimately create binaries directly in System32."  - "Non-MSI installer bootstrappers — setup.exe stubs, NSIS and Inno Setup packages, and vendor bundle installers — which unpack their payload straight into Program Files without ever invoking msiexec.exe."  - "Endpoint agents that self-update without an installer, such as EDR, backup and monitoring products that download a new build and overwrite their own .exe and .dll under Program Files on a schedule."level: low

Sentinel · KQL

Run this as a search.

DeviceFileEvents| where (((FolderPath contains "\\Windows\\System32\\" or FolderPath contains "\\Windows\\SysWOW64\\" or FolderPath contains "\\Program Files\\" or FolderPath contains "\\Program Files (x86)\\") and (FolderPath endswith ".exe" or FolderPath endswith ".dll" or FolderPath endswith ".sys" or FolderPath endswith ".ocx")) and not ((InitiatingProcessFolderPath endswith "\\TiWorker.exe" or InitiatingProcessFolderPath endswith "\\TrustedInstaller.exe" or InitiatingProcessFolderPath endswith "\\poqexec.exe" or InitiatingProcessFolderPath endswith "\\msiexec.exe" or InitiatingProcessFolderPath endswith "\\wusa.exe" or InitiatingProcessFolderPath endswith "\\MsMpEng.exe" or InitiatingProcessFolderPath endswith "\\MpSigStub.exe")))

Splunk · SPL

Run this as a search.

index=* (((TargetFilename="*\\Windows\\System32\\*" OR TargetFilename="*\\Windows\\SysWOW64\\*" OR TargetFilename="*\\Program Files\\*" OR TargetFilename="*\\Program Files (x86)\\*") AND (TargetFilename="*.exe" OR TargetFilename="*.dll" OR TargetFilename="*.sys" OR TargetFilename="*.ocx")) AND NOT ((Image="*\\TiWorker.exe" OR Image="*\\TrustedInstaller.exe" OR Image="*\\poqexec.exe" OR Image="*\\msiexec.exe" OR Image="*\\wusa.exe" OR Image="*\\MsMpEng.exe" OR Image="*\\MpSigStub.exe")))

Elastic · ES|QL

Run this as a search.

FROM logs-*| WHERE (((TO_LOWER(file.path) LIKE "*\\\\windows\\\\system32\\\\*" OR TO_LOWER(file.path) LIKE "*\\\\windows\\\\syswow64\\\\*" OR TO_LOWER(file.path) LIKE "*\\\\program files\\\\*" OR TO_LOWER(file.path) LIKE "*\\\\program files (x86)\\\\*") AND (TO_LOWER(file.path) LIKE "*.exe" OR TO_LOWER(file.path) LIKE "*.dll" OR TO_LOWER(file.path) LIKE "*.sys" OR TO_LOWER(file.path) LIKE "*.ocx")) AND NOT ((TO_LOWER(process.executable) LIKE "*\\\\tiworker.exe" OR TO_LOWER(process.executable) LIKE "*\\\\trustedinstaller.exe" OR TO_LOWER(process.executable) LIKE "*\\\\poqexec.exe" OR TO_LOWER(process.executable) LIKE "*\\\\msiexec.exe" OR TO_LOWER(process.executable) LIKE "*\\\\wusa.exe" OR TO_LOWER(process.executable) LIKE "*\\\\msmpeng.exe" OR TO_LOWER(process.executable) LIKE "*\\\\mpsigstub.exe")))

Wazuh · XML rule

Deploy to your manager — this is a rule, not a search.

<group name="sigma,windows,file_event,">  <!-- Rule ids must be unique on your manager; 100000+ is the user range. -->  <rule id="100000" level="5">    <!-- Set <if_sid> to the decoder/base rule for windows so this only evaluates relevant events. -->    <field name="TargetFilename" type="pcre2">(?i)(\\Windows\\System32\\|\\Windows\\SysWOW64\\|\\Program Files\\|\\Program Files \(x86\)\\)</field>    <field name="TargetFilename" type="pcre2">(?i)(\.exe$|\.dll$|\.sys$|\.ocx$)</field>    <field name="Image" negate="yes" type="pcre2">(?i)(\\TiWorker\.exe$|\\TrustedInstaller\.exe$|\\poqexec\.exe$|\\msiexec\.exe$|\\wusa\.exe$|\\MsMpEng\.exe$|\\MpSigStub\.exe$)</field>    <description>Executable written into a protected program directory</description>    <mitre>      <id>T1554</id>    </mitre>  </rule></group>

Verdicts · reactions · comments

Community

Verdicts from engineers who actually deployed it, and the conversation around it.

Log in to react
Not yet reported on

Nobody has run this in a real environment and said what happened.

Verdicts from engineers who deployed it

0 cast

No verdicts reported yet. The first one is worth more than the tenth — say what you ran it against.

Log in to report a verdict.

Log in to join the discussion.

No comments yet. Someone who deploys this will have something to say about it.