File and Directory Hiding via attrib.exe +h or +s +h Flags
Detects the use of the Windows attrib.exe utility to set the hidden file attribute (+h) on files. Adversaries often use this technique to hide malicious files, scripts, or directories from standard file browsing tools to evade detection. The rule includes an exclusion for processes signed by Microsoft to reduce noise from legitimate system operations.
SentinelOne

