Suspicious Copy on System32
The following analytic detects potentially suspicious file copy operations targeting the System32 or SysWow64 directories as source, often indicative of malicious activity. It leverages data from Endpoint Detection and Response (EDR) agents, focusing on activity initiated by command-line tools like cmd.exe or PowerShell. This behavior is significant as it may indicate an attempt to evade defenses by copying an existing binary from the system directory and renaming it. If confirmed malicious, this activity could allow an attacker to execute code undetected and potentially leading to system compromise or further lateral movement within the network.
Sign in to view the rule source
Free accounts can view the source for the top-ranked rules. Create one in seconds — no credit card required.
Sign in →