Elevated process started from a writable installer staging directory
Matches Sysmon Process Creation where a process running at High or System integrity was started out of one of the directories a self-extracting installer unpacks into — the per-user %TEMP% tree, or C:\Windows\Temp. That is the payoff step of this technique: a binary sitting in a directory whose permissions let any standard user overwrite it is then executed by the installer under the installer's own elevated token. The two path values are MITRE's MonitoredDirectories knob. MITRE names %TEMP% there; the second value, C:\Windows\Temp, is added by this rule because that is where %TEMP% resolves for an installer running as SYSTEM, and the technique text names neither it nor any other absolute path. The knob's third suggested value, C:\ProgramData, is deliberately left out, because the vendor updaters that live there and run as SYSTEM would swamp everything else the rule returns. IntegrityLevel is the only field on this event that separates the interesting case from a user running something ordinary out of their own temp directory, so it carries the whole discriminating weight of the rule. Three limits are structural. Nothing on a process-creation event distinguishes a planted binary from the installer's own legitimate payload, so this is a hunting filter, not an alert. The file-overwrite half of AN0108 arrives as a separate Sysmon File Creation event, and joining it to the execution inside MITRE's TimeWindow knob is a correlation lib/sigma has no way to express. And the DLL variant — where the elevated installer loads a replaced library rather than executing a replaced EXE — is invisible from here and would need the Module Load source instead. Requires Sysmon with Process Creation enabled and IntegrityLevel carried through the field mapping; if that field is dropped in normalisation the selection silently never matches, which reads as quiet when it means blind. UNVERIFIED AS AUTHORED — derived from MITRE ATT&CK DET0038, not hand-written and not tested by its author. Any lab result is on this rule's own page.Full descriptionShow less
The detection
The 4 SIEM queries below are previews produced by Siemphony’s own translator, not pySigma, and none has been executed against a real backend — review before you deploy.
detection.yml
title: Elevated process started from a writable installer staging directoryid: 64f96cc4-1d2f-47fc-8238-e1daf785395cstatus: experimentaldescription: | Matches Sysmon Process Creation where a process running at High or System integrity was started out of one of the directories a self-extracting installer unpacks into — the per-user %TEMP% tree, or C:\Windows\Temp. That is the payoff step of this technique: a binary sitting in a directory whose permissions let any standard user overwrite it is then executed by the installer under the installer's own elevated token. The two path values are MITRE's MonitoredDirectories knob. MITRE names %TEMP% there; the second value, C:\Windows\Temp, is added by this rule because that is where %TEMP% resolves for an installer running as SYSTEM, and the technique text names neither it nor any other absolute path. The knob's third suggested value, C:\ProgramData, is deliberately left out, because the vendor updaters that live there and run as SYSTEM would swamp everything else the rule returns. IntegrityLevel is the only field on this event that separates the interesting case from a user running something ordinary out of their own temp directory, so it carries the whole discriminating weight of the rule. Three limits are structural. Nothing on a process-creation event distinguishes a planted binary from the installer's own legitimate payload, so this is a hunting filter, not an alert. The file-overwrite half of AN0108 arrives as a separate Sysmon File Creation event, and joining it to the execution inside MITRE's TimeWindow knob is a correlation lib/sigma has no way to express. And the DLL variant — where the elevated installer loads a replaced library rather than executing a replaced EXE — is invisible from here and would need the Module Load source instead. Requires Sysmon with Process Creation enabled and IntegrityLevel carried through the field mapping; if that field is dropped in normalisation the selection silently never matches, which reads as quiet when it means blind. UNVERIFIED AS AUTHORED — derived from MITRE ATT&CK DET0038, not hand-written and not tested by its author. Any lab result is on this rule's own page.references: - https://attack.mitre.org/techniques/T1574/005 - https://attack.mitre.org/detectionstrategies/DET0038author: Siemphony pipeline (machine-derived from MITRE ATT&CK v19.2)date: 2026-08-16tags: - attack.defense-evasion - attack.execution - attack.t1574.005logsource: category: process_creation product: windowsdetection: selection: IntegrityLevel: - 'High' - 'System' Image|contains: - '\AppData\Local\Temp\' - ':\Windows\Temp\' condition: selectionfalsepositives: - "Ordinary software installation. Self-extracting installers built with NSIS, Inno Setup, InstallShield or 7-Zip SFX unpack into a randomly named %TEMP% subdirectory and execute the unpacked setup binary through the elevation prompt, which is precisely the shape this rule matches. On any estate where users install their own software this is the highest-volume match by a wide margin, and it is why the level is low rather than medium." - "Software deployment and patching agents running as SYSTEM. ConfigMgr, Intune, WinGet and Chocolatey stage vendor bundles into C:\\Windows\\Temp and launch them there on every deployment, so each patch window produces a burst of System-integrity matches across the whole fleet." - "Windows Installer custom actions. msiexec extracts embedded executables into a temporary directory and runs them inside the elevated install session, so any MSI carrying a custom action matches once per install and once per repair." - "Vendor firmware, driver and diagnostic utilities — Dell Command Update, HP Image Assistant, Lenovo System Update and similar — which unpack their payload into Windows\\Temp and run it as SYSTEM on a scheduled cadence."level: lowSentinel · KQL
Run this as a search.
DeviceProcessEvents| where ((ProcessIntegrityLevel =~ "High" or ProcessIntegrityLevel =~ "System") and (FolderPath contains "\\AppData\\Local\\Temp\\" or FolderPath contains ":\\Windows\\Temp\\"))
Splunk · SPL
Run this as a search.
index=* ((IntegrityLevel="High" OR IntegrityLevel="System") AND (Image="*\\AppData\\Local\\Temp\\*" OR Image="*:\\Windows\\Temp\\*"))Elastic · ES|QL
Run this as a search.
FROM logs-*| WHERE ((TO_LOWER(winlog.event_data.IntegrityLevel) == "high" OR TO_LOWER(winlog.event_data.IntegrityLevel) == "system") AND (TO_LOWER(process.executable) LIKE "*\\\\appdata\\\\local\\\\temp\\\\*" OR TO_LOWER(process.executable) LIKE "*:\\\\windows\\\\temp\\\\*"))
Wazuh · XML rule
Deploy to your manager — this is a rule, not a search.
<group name="sigma,windows,process_creation,"> <!-- Rule ids must be unique on your manager; 100000+ is the user range. --> <rule id="100000" level="5"> <!-- Set <if_sid> to the decoder/base rule for windows so this only evaluates relevant events. --> <field name="IntegrityLevel" type="pcre2">(?i)(^High$|^System$)</field> <field name="Image" type="pcre2">(?i)(\\AppData\\Local\\Temp\\|:\\Windows\\Temp\\)</field> <description>Elevated process started from a writable installer staging directory</description> <mitre> <id>T1574.005</id> </mitre> </rule></group>
Verdicts · reactions · comments
Community
Verdicts from engineers who actually deployed it, and the conversation around it.
Nobody has run this in a real environment and said what happened.
Verdicts from engineers who deployed it
0 castNo verdicts reported yet. The first one is worth more than the tenth — say what you ran it against.
Log in to report a verdict.
Log in to join the discussion.
No comments yet. Someone who deploys this will have something to say about it.