BIOCs

Browse the Cortex behavioral indicator of compromise (BIOC) detection rules.

Severity
Category

1 BIOC match the current filters. technique: T1105 ✕

Download CSV Show ATT&CK heatmap
  • Suspicious lock screen image file written to disk Low Execution

    Desktopimgdownldr.exe is a built-in Windows tool used to set a lock screen or desktop background image as part of Personalization CSP. Adversaries may use it maliciously to download malware.

    Indicator:

    File action type = create , write , rename AND file path = *personalization\lockscreenimage* Process os parent name = desktopimgdownldr.exe , svchost.exe AND cgo name != omadmprc.exe AND CcmExec.exe AND GoogleUpdate.exe AND ServiceShell.exe AND os parent cmd != *svchost.exe*-k*gpsvc*

    ATT&CK tactics: Command and Control (TA0011)
    ATT&CK techniques: Ingress Tool Transfer (T1105)
    Preventable:
    Yes
    Source:
    Palo Alto Networks
    Updated:
    2026-08-23