BIOCs
Browse the Cortex behavioral indicator of compromise (BIOC) detection rules.
1 BIOC match the current filters. tactic: TA0011 ✕ technique: T1105 ✕
Download CSV Show ATT&CK heatmapSuspicious lock screen image file written to disk Low Execution
Desktopimgdownldr.exe is a built-in Windows tool used to set a lock screen or desktop background image as part of Personalization CSP. Adversaries may use it maliciously to download malware.
Indicator:File action type = create , write , rename AND file path = *personalization\lockscreenimage* Process os parent name = desktopimgdownldr.exe , svchost.exe AND cgo name != omadmprc.exe AND CcmExec.exe AND GoogleUpdate.exe AND ServiceShell.exe AND os parent cmd != *svchost.exe*-k*gpsvc*
ATT&CK tactics: Command and Control (TA0011)ATT&CK techniques: Ingress Tool Transfer (T1105)- Preventable:
- Yes
- Source:
- Palo Alto Networks
- Updated:
- 2026-08-23