UC-L3-003
Suspicious Email Attachment Extension
Windows Security / Sysmon Event ID 1
Use case development / Protect Against Ransomware / Prevent Ransomware Delivery
sigma
Detection rule
title: Suspicious Email Attachment Execution
status: experimental
description: Detects execution of files with double extensions commonly used in phishing
logsource:
product: windows
category: process_creation
detection:
selection:
Image|endswith:
- '.pdf.exe'
- '.doc.exe'
- '.xlsx.exe'
- '.docx.exe'
- '.pdf.scr'
condition: selection
falsepositives:
- None expected
level: high
tags:
- attack.initial_access
- attack.t1566Test cases
- Execute file with double extension
- Verify process tree shows email client as parent
False positive guidance
No known false positives for this detection.