Join our Newsletter — 33% off our NHI Course

Saved Search File Format

A Saved Search File Format file preserves a Windows search query so it can be repeated later with the same display behavior. In abuse scenarios, a .search-ms file can point to remote locations and shape what the user sees in Explorer, helping malicious content look like a normal local result.

What a Saved Search File Format does

A saved search file format preserves a Windows search query so it can be replayed later with the same search scope, filters, and display behavior. That makes it more than a shortcut, because the file can encode how Explorer resolves and presents search results, not just the search terms themselves.

In practice, that persistence is useful for repeatable investigation, but it also means the file is a small piece of UI state with security relevance. The saved query can influence where results are pulled from, what path names are shown, and how a user interprets the output.

Why the format matters operationally

The main operational value is consistency. A saved search lets a user or analyst reopen the same search without rebuilding the query, which helps with repeatable triage, evidence collection, and navigation of large file systems. The format is therefore a convenience layer on top of Windows search behavior, but its behavior is still tied to the local shell and search subsystem.

That same convenience can become a trust problem when people assume a saved search file is harmless because it looks like a document. It is better understood as a search instruction object that may trigger shell activity and visual rendering, so the surrounding context matters as much as the filename.

Security implications of deceptive search files

Because the file controls how results are displayed, it can be used to make remote or unexpected content appear more ordinary than it really is. In abuse scenarios, that can support social engineering by aligning the visual presentation with a normal local browsing experience. The risk is not that the file executes arbitrary code by itself, but that it shapes user perception at the moment of interaction.

Saved search files are also relevant in phishing and malware delivery chains when attackers rely on the user to open a file that appears to be a benign search artifact. A deceptive search result view can help hide the true origin of content or steer the user toward a path they would not otherwise trust.

For broader file-based deception, The 52 NHI breaches Report and CVE Program are useful references for understanding how small artifacts and known weaknesses become entry points in real incidents.

How to interpret and handle .search-ms files

Practitioners should treat .search-ms files as active content, not passive text. The key question is not only whether the file is valid, but whether its query target, result source, and presentation behavior are expected in the current context. That is especially important when the file comes from email, chat, downloads, removable media, or a user who is not normally responsible for crafting search artifacts.

For defenders, the useful control perspective is simple: watch for search files arriving from untrusted sources, and be cautious when a search file points outside the local system or changes the apparent origin of results. If the file is part of a suspected lure, the surrounding technique matters more than the extension alone.

Practitioner takeaway: Train users and support teams to recognize that a saved search file can be a presentation trick as well as a convenience feature, and verify its source before opening it.

Risk and Threat Considerations

Saved search files create a lightweight deception channel because they can influence what users think they are seeing in Explorer. The main danger is trust abuse: a file that looks like a normal search artifact can help an attacker present remote content as if it were local, familiar, or already vetted.

Failure mechanism: The file leverages shell behavior and result presentation to blur the boundary between query definition and displayed content, which can mislead a user during review or incident triage.

Impact: Users may open untrusted content, follow attacker-controlled paths, or misjudge the origin and legitimacy of files, increasing exposure to phishing, malware delivery, and investigation error.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK address the attack and risk surface, while CIS Controls v8 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
MITRE ATT&CK T1036 — Masquerading Saved search files can disguise malicious content as ordinary Explorer output.
T1204 — User Execution The abuse depends on persuading a user to open the search file.
Recommendation — Detect misleading file presentation patterns and investigate masquerading where search artifacts alter user trust. Harden user-execution paths by flagging suspicious search files before users open them.
CIS Controls v8 8.6 — Audit Log Management Search-file abuse benefits from visibility into file access and shell activity.
Recommendation — Log and review file execution and shell interaction events involving suspicious search artifacts.