Skip to content

Sqlwriter Executed from Non-Standard Directory #5825

@PMorningstar98

Description

@PMorningstar98

title: Sqlwriter Executed from Non-Standard Directory
id: 3f2d8a66-9f61-4e61-b7d1-4d77d2f47a22
status: experimental
description: >
Detects execution of sqlwriter.exe from non-standard directories.
Legitimate sqlwriter.exe is part of Microsoft SQL Server and is
normally executed from SQL Server installation paths. Execution
from user-writable or temporary directories may indicate abuse,
including DLL side-loading techniques observed in real-world attacks.
references:

Metadata

Metadata

Labels

Create Pull-Requestissues that should be provided as a pull request

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions