New analysis of CrowdStrike Falcon's Windows DirectoryCreate telemetry found the event is generated by the CSAgent.sys kernel minifilter at the IRP_MJ_CREATE layer, making it resistant to many user-mode evasion and path-obfuscation techniques. Testing across roughly 60 directory-creation methods showed the signal is dependable for true folder creation, including SMB-based creation that can produce both client-side and server-side events, but it records the resolved target path for junctions, symlinks, and bind links rather than the originally requested path.
The research also showed that directory renames, same-volume moves, and Recycle Bin restores do not trigger DirectoryCreate because they use rename semantics instead of create semantics, limiting the event's usefulness for some file-operation detections. That behavior aligns with a separate Windows Server 2022 file-share report in which files moved into a share by an automated process did not appear to clients until a manual refresh, suggesting rename-based operations can behave differently from true creates in both endpoint telemetry and SMB visibility; defenders are advised to correlate DirectoryCreate with ProcessRollup2 and parent-process context because the recorded actor may be an intermediary such as WmiPrvSE.exe, services.exe, or explorer.exe.

See real exploitation activity before you spend the cycle.
3 events from the most recent confirmed update back to the earliest known activity.
A Reddit user reported that after migrating a file server from Windows Server 2016 to Windows Server 2022, files moved into a shared folder by MOVEit did not appear in Windows 11 clients' File Explorer until users manually refreshed. The report said the issue occurred specifically for same-volume MOVEit moves that behave like rename operations, while drag-and-drop copies, SFTP uploads, and files created locally on the server appeared immediately.
The same research reported that directory creation through junctions, symlinks, and bind links is logged using the resolved target path rather than the requested path, which can affect detections based on request-path strings. It also found that SMB directory creation can produce both client-side and server-side events, and warned that DirectoryCreate should be correlated with ProcessRollup2 and related context because the recorded actor may reflect intermediary processes rather than the true initiator.
An analysis of CrowdStrike Falcon's Windows DirectoryCreate telemetry concluded that the event is generated by the CSAgent.sys minifilter at the IRP_MJ_CREATE layer, making it resilient to user-mode evasion and path obfuscation. Testing across roughly sixty directory-creation methods found that true creates are generally captured, while renames, moves, and Recycle Bin restores do not generate DirectoryCreate because they use rename rather than create semantics.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
3 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcedetect.fyi
Open sourcereddit.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.