Windows Symlink Evaluation Change via Fsutil — Detection Rule

This analytic detects the execution of the Windows built-in tool Fsutil.exe with the "behavior", "set" and "SymlinkEvaluation" parameters. Attackers can abuse this to alter symlink evaluation behavior on Windows, potentially enabling remote traversal over SMB shares or evading defenses. Such changes should be uncommon or even rare in enterprise environments and should be investigated.

Read the full analysis on IntelFusions