title: Execution in Non-Executable Folder status: experimental description: Detects a suspicious exection from an uncommon folder author: Florian Roth logsource: product: windows service: sysmon detection: selection: EventID: 1 Image: - 'C:\PerfLogs\*' - 'C:\Users\All Users\*' - 'C:\Users\Public\*' - 'C:\Users\Default\*' - 'C:\Windows\addins\*' - 'C:\Windows\Fonts\*' condition: selection falsepositives: - Unknown level: high